Network Operations Halted
The Liquid Network, a Bitcoin sidechain used by exchanges and infrastructure firms for faster settlement, has suspended all new transactions following a security exploit that resulted in the loss of approximately $320 million in Bitcoin. According to CoinDesk, the incident involved the withdrawal of roughly 4,000 of the 4,200 Bitcoin held within the network’s federation wallet.
Blockstream, the organization that launched the network in 2018, confirmed that the breach was not caused by compromised private keys or passwords. Instead, the exploit originated from a software bug within the ‘Elements’ system. The stolen funds were moved through the SideSwap trading platform, which reportedly could not distinguish between legitimate assets and those created by the software bug, leading it to process the transactions as normal.
The ‘White Hat’ Claim
The individuals behind the exploit have characterized themselves as “white-hat” hackers, claiming they intend to return the funds once the underlying vulnerability is patched. The attackers have been communicating with network maintainers through on-chain Bitcoin transactions. In one message cited by CoinDesk, the hackers instructed developers to patch every node and fix the bug, promising to return the money safely once the fix is confirmed.
Liquid Network, which is overseen by a federation of over 80 member organizations, issued a statement on X (formerly Twitter) confirming the disruption. The team stated that federation members are currently working to resolve the issue and restore normal network activity, though no specific timeline for the reopening of the network has been provided.
Broader Security Concerns
This incident is the latest in a series of security breaches affecting the digital asset ecosystem in 2026. PYMNTS reports that earlier last week, a lending platform linked to Crypto.com suffered a $6 million drain, while an August breach involving Coldcard hardware wallets resulted in estimated losses between $115 million and $130 million.
Industry experts emphasize that these recurring events highlight the need for more robust, full-stack security measures. Ziqing Ang, head of policy in Asia-Pacific at TRM Labs, noted that while such events may impact consumer confidence, they serve as a critical reminder of where infrastructure safeguards must be strengthened to protect against sophisticated exploits.

