Liquid Network has been dealing with the aftermath of one of the largest cryptocurrency security incidents of the year after nearly 4,000 BTC left its federation wallet, prompting the Bitcoin sidechain to halt activity.
The Bitcoin was worth roughly $320 million when it was withdrawn on 6 September. Liquid described those responsible as purported white-hat hackers and said the funds had moved through the SideSwap peg-out process, adding that the relevant authorisation key itself had not been compromised.
Reuters reported on the initial incident, in which Liquid stopped new transactions and warned that wallets would be affected. The story has already taken another turn. Around 3,400 BTC have since been returned, although roughly 598.5 BTC remained with the actors as of 8 September. The scale made the incident striking, but the mechanics behind it may prove more important than the headline value.
Crypto security depends on more than protecting a private key
Liquid said the Peg-out Authorization Key involved in the withdrawal had not been compromised. Subsequent reporting indicated that the problem was linked instead to a bug affecting the Elements software used by the network.
That distinction matters for the wider crypto economy. Users often think of cryptocurrency security mainly in terms of protecting private keys, but digital assets increasingly move through bridges, sidechains, exchanges, settlement systems and application layers, each with its own software and permissions.
The same principle applies wherever bitcoin becomes part of a digital service, whether somebody is moving funds between trading platforms or accessing bitcoin casino games. The security of the underlying asset is only one part of the equation; the infrastructure handling it matters as well.
A perfectly secure Bitcoin key cannot compensate for a vulnerability elsewhere in the transaction path. This is particularly important with sidechains. They extend what can be done with an asset without changing the base Bitcoin network, but that flexibility introduces additional components that users must trust.
Most of the Bitcoin has now been returned
The actors identified themselves as white hats and used messages embedded in Bitcoin transactions to communicate with Blockstream. They indicated that most of the funds would be returned once the vulnerability was fixed.
According to an updated report from The Block, Blockstream later sent a signed on-chain message saying its bridge nodes had been patched. The actors then returned 3,400 BTC to the federation wallet while leaving about 598.5 BTC, worth approximately $47 million at the time, in their address.
There has been no publicly disclosed agreement establishing the remaining amount as an authorised bounty.
The label “white hat” does not make the situation straightforward. Moving hundreds of millions of dollars without prior permission creates legal and operational questions even when most of the funds are later returned.
The negotiation also shows how public blockchains can become communication channels during incidents, with transactions themselves carrying an auditable trail of messages.
Bridges and settlement layers create their own risks
Bridges and sidechains exist because users want more functionality than a base blockchain can always provide efficiently on its own. They can enable faster settlement, different privacy characteristics or new types of applications. The trade-off is that each additional layer introduces another potential failure point.
This is not unique to Bitcoin. Crypto markets have repeatedly seen losses linked to bridges, smart contracts, exchanges and custody systems rather than to failures of the underlying blockchain. For developers, testing therefore has to cover software, permissions and the way separate components interact.
The incident shows why infrastructure layers deserve scrutiny
That difference matters because the crypto market increasingly consists of interconnected layers. Users may see Bitcoin on the screen while the transaction behind that interface depends on additional software, bridges or settlement mechanisms.
The Liquid incident provides a large example of that risk. Roughly 95% of the Bitcoin reported in the federation wallet was moved, yet most of those funds were later returned after the underlying issue was addressed.
The financial outcome could therefore be very different from the initial $320 million headline. The security lesson is less likely to disappear.
As crypto infrastructure becomes more complex, knowing that the base blockchain is secure is no longer enough. Users, platforms and developers also need to understand what happens between the blockchain and the service they actually use.
