0x649738a86497…649738ab

ConfirmedSecurity617 vB26 sat/vB3 min decode

$320M Bitcoin Exploit Hits Liquid Network, Hacker Tables Conditional Offer

An attacker exploited the Liquid Network for $320 million in bitcoin and has made a conditional offer, CoinDesk reported, creating a rare negotiation scenario.

$320 million bitcoin exploit hits Liquid Network. Hacker makes conditional offer - coindesk.com
Witness$320 million bitcoin exploit hits Liquid Network. Hacker makes conditional offer - coindesk.comAI-generated

Outputs

  1. An attacker exploited the Liquid Network for $320 million in bitcoin.

  2. The hacker made a conditional offer after the exploit.

  3. Liquid is a federated bitcoin sidechain maintained by Blockstream.

  4. The incident ranks among the largest bitcoin-sidechain exploits on record.

  5. Terms of the attacker's offer have not been publicly specified.

An attacker exploited the Liquid Network for $320 million in bitcoin, according to a CoinDesk report, turning one of the largest-ever bitcoin-sidechain security incidents into an unusual standoff between the exploit's operator and the protocol's operators.

The hacker has since made a conditional offer, the report states — a move that suggests the attacker is open to returning at least part of the stolen funds under terms that have not been publicly specified. Conditional returns are rare in large-scale crypto exploits, and any negotiation would run through the infrastructure's operator, Blockstream, which maintains the Liquid Network as a bitcoin sidechain used primarily for settlement and asset issuance by exchanges and institutional traders.

What happened on Liquid?

The exploit drained $320 million in bitcoin from the network, CoinDesk reported. The Liquid Network is a federated sidechain anchored to the Bitcoin mainchain; it relies on a federation of functionaries rather than proof-of-work miners to sign blocks and manage pegged bitcoin (LBTC) that circulates on the sidechain. That design trades some trust assumptions for faster, confidential settlement between participating institutions.

The scale of the loss places the incident among the largest bitcoin-related exploits on record. Because assets on Liquid are pegged one-to-one to bitcoin held under federation control, a compromise of this size raises direct questions about peg integrity, federation key management and the operational exposure of every institution routing settlement through the sidechain.

What does the hacker's conditional offer mean?

The attacker's conditional offer, as reported by CoinDesk, opens a path that recent exploit cases have occasionally taken: negotiation instead of pure flight. In prior industry incidents, attackers have returned funds in exchange for bug bounties, dropped legal action or public de-escalation. Whether Blockstream treats the offer as credible — and whether law enforcement allows any negotiated settlement at all — remains the central unknown.

Institutional participants now face operational questions. Exchanges and trading desks that hold LBTC or settle through Liquid must assess whether the exploit affected pegged reserves directly or exploited a separate vulnerability, a distinction that determines whether the loss is absorbed by the federation, by individual holders, or by the attacker's ability to cash out.

Why the structure of Liquid matters here

Liquid's federated model concentrates signing authority in a set of functionaries. That concentration is efficient for settlement speed and confidentiality but creates a defined attack surface: the hardware and keys that control block signing and the two-way peg. An exploit of this size will inevitably sharpen scrutiny of how those keys are secured, how the federation rotates members, and what recourse peg participants have when the system is compromised.

For institutional users, the incident is a counterparty-risk event as much as a technical one. Firms that treat sidechain balances as functionally equivalent to bitcoin on the mainchain will reprice that assumption. Operational consequences could include reduced LBTC liquidity, wider discounts on pegged assets during the uncertainty window, and accelerated due-diligence requirements on any federated or custodial settlement layer.

What comes next?

The immediate variables are the attacker's terms, Blockstream's response, and any involvement from law enforcement agencies with jurisdiction over the stolen bitcoin. Each on-chain movement of the funds will be tracked in real time, since bitcoin pegged through Liquid must eventually surface on the Bitcoin mainchain to be spent outside the sidechain — a constraint that limits the attacker's exit options and strengthens the case for negotiation.

The coming weeks will show whether the conditional offer produces a partial return, a standoff, or an enforcement action — and whether the Liquid federation can restore institutional confidence in the peg before settlement volumes migrate elsewhere.

via Google News - Crypto Hack Exploit (Source)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

419 articles