0x170d0624170d…170d0627
Liquid Network Hackers Drain $320 Million from Federation Wallet
Hackers drained $320 million from Liquid Network's federation wallet, emptying roughly 95% of sidechain reserves and claiming to be 'good guys' willing to return funds after the vulnerability is patched.
Outputs
$320 million drained from Liquid Network's federation wallet
Approximately 95% of the federation wallet emptied in a single operation
Attackers identified themselves as ethical security researchers in on-chain message
Attackers pledged to return funds after the vulnerability is disclosed and patched
Liquid Network operators suspended sidechain activity pending federation response
Hackers drained $320 million from the Liquid Network federation wallet, emptying approximately 95% of the sidechain's reserves after exploiting a software vulnerability, according to Tom's Hardware.
The attackers subsequently identified themselves in a public message as "good guys" and pledged to return the funds once the underlying vulnerability was disclosed and patched.
The breach represents one of the largest losses tied to a federated Bitcoin sidechain, an architecture that relies on a group of trusted custodians rather than a fully decentralized validator set to manage assets pegged between chains.
What does the federation wallet hold?
The federation wallet secures the assets backing Liquid's pegged tokens, including BTC issued on the sidechain. With roughly 95% of the wallet drained in a single operation, the operational reserves supporting peg-in and peg-out activity effectively evaporated.
Liquid's operators suspended normal sidechain activity to prevent further loss and to assess the attack vector.
Federated sidechains differ from typical proof-of-work or proof-of-stake networks. A designated group of members holds the multi-signature keys governing peg operations, making security dependent on those members' internal controls and software integrity.
What did the attackers actually do?
The hackers exploited a vulnerability in the federation's software stack to extract the funds.
According to Tom's Hardware, the attackers embedded a message within transaction data identifying themselves as ethical security researchers. "We are the good guys," the message stated, with the group offering to return the stolen cryptocurrency contingent on a public fix to the underlying flaw.
This so-called white-hat framing has appeared across several high-profile DeFi and bridge incidents, where attackers communicate intentions after the fact through on-chain memos or direct contact with the affected project. Whether such offers translate into actual fund recovery varies considerably across cases, with no enforceable obligation on the attackers.
What are the operational consequences?
Liquid Network functions as a settlement layer for cryptocurrency exchanges, providing faster Bitcoin transactions and issuance of pegged assets. Federation members, which typically include major exchanges and infrastructure providers, must now coordinate recovery actions including key rotation, software patching, and a decision on the attackers' offer.
Normal sidechain operations, including peg-ins and peg-outs, remain suspended until the vulnerability is closed and the federation re-collateralizes the wallet.
Exchanges relying on Liquid for inter-exchange settlement will likely route transfers through alternative rails during the outage, raising the prospect of increased pressure on the Lightning Network and on centralized transfer mechanisms.
What happens next?
The incident leaves Liquid's operators facing three concrete decisions: disclose and patch the exploited vulnerability, restore reserve balances, and respond to the attackers' public offer.
Any restitution, if accepted, would still require a coordinated multi-signature process across federation members before funds could return to the wallet.
Until those steps complete, the sidechain's utility as a rapid Bitcoin settlement rail remains degraded. The disclosure of the underlying vulnerability will determine both the feasibility of resuming operations and the credibility of the federation's ongoing security posture for institutional users evaluating Liquid as a counterparty.
via Google News - Crypto Hack Exploit (Source)