Liquid Network's federation loses 4,000 BTC
An inflation bug let hackers mint fake L-BTC and cash out 4,019 BTC ($320M) from Blockstream's Liquid federation reserve.

Liquid Network's federation wallet lost about 4,019 BTC, worth roughly $320 million, in a peg-out transaction on Sunday. The sidechain is now paused and bridge nodes are disabled.
The federation's design
Liquid is a federated Bitcoin sidechain built by Blockstream. It issues L-BTC backed 1:1 by BTC held in a 15-member multisig, requiring 11 signatures to move funds.
That threshold exists to stop any single actor from draining the reserve. It didn't stop this.
What the numbers show
The attackers appear to have exploited an inflation bug to mint L-BTC that never should have existed, then redeemed it for real bitcoin.
- Treasury held over 4,200 BTC before the withdrawal, per Blockstream's proof of reserves.
- 207 BTC remained after the transaction, per the same page.
- 4,019.4 BTC moved out using the SideSwap Peg-out Authorization Key.
- 11 of 15 federation signatures are required to approve any treasury transaction, per Liquid's federation design.
- The attacker's HSM-signed withdrawal passed as valid because the consensus bug made the mint look legitimate.
The federation model's failure
Most coverage will frame this as a hack story: attackers found a bug, stole coins, left a note. The multisig threshold is the real failure point.
Eleven of fifteen signers approved a transaction because their security hardware saw a valid-looking mint. The safeguard designed to prevent unilateral theft did nothing, because the exploit worked upstream of the signing step.
The federation's HSMs verified signatures correctly. They just signed off on a lie.
That's a harder problem than a stolen key. A compromised key gets rotated.
A consensus bug that fools every honest signer into approving a fraudulent transaction means the trust model itself, not any single custodian, is the point of failure. Liquid's entire pitch was that federation beats single-custodian risk.
This event shows federation can fail the same way, just with more signatures on the receipt.
What happens to L-BTC holders
The attackers left onchain messages calling themselves white hats and asking to be contacted. Other issued assets on Liquid, including USDT, DePix and RWAs, were reportedly unaffected.
L-BTC holders are stuck. The underlying BTC backing their tokens is currently unredeemable, and bridge nodes are down across wallets that route through Liquid, including Aqua.
JAN3's Samson Mow said Liquid features in Aqua were affected while native onchain bitcoin held up. That split, Liquid frozen, base-layer Bitcoin fine, is the whole story in miniature.
Given the size of the haul, a full walkaway looks difficult, though not impossible. A negotiated return with a finder's fee is the more likely outcome if the "white hat" framing holds.
Either way, the federation's day-one job, keeping the treasury solvent under its own signature scheme, has already failed once.
Signals to track
- Whether the attacker's onchain contact messages lead to a negotiated return of funds, and on what timeline.
- Whether Blockstream discloses the specific consensus bug and confirms it's patched before restoring bridge nodes.
- Whether L-BTC's peg holds once trading resumes, or whether exchanges require partial writedowns.
