Liquid Network, the Bitcoin sidechain operated by a federation of members including exchanges and infrastructure providers, has suspended operations after an exploit allowed an attacker to mint fake L-BTC and drain nearly all of the network's bitcoin reserves.
According to the Federation, the vulnerability originated in Elements, the Bitcoin-derived software that Liquid runs on, specifically in how the system validates confidential transactions. A cached cryptographic proof was allegedly reused incorrectly, allowing an invalid transaction to pass node checks undetected.
Exploiting this flaw, the attacker used a single legitimate L-BTC as the basis to generate approximately 4,000 L-BTC out of thin air. L-BTC is designed to represent bitcoin on the Liquid Network on a 1:1 basis, backed by BTC locked with the Federation. The fabricated tokens carried no such backing.
The fake L-BTC were then routed to SideSwap's withdrawal service, a Federation member that facilitates conversion of L-BTC back into BTC. Through that channel, the attacker managed to have 3,996 BTC of real bitcoin released to an external address, extracting value from reserves that were never actually deposited.
Reserves left near empty
The withdrawal amounted to roughly 95% of the Federation's bitcoin reserves, leaving approximately 197 BTC remaining. As a result, L-BTC currently cannot be redeemed for BTC, and holders of the token are unable to exit their positions while the network remains paused.
In response, the Federation disabled bridge nodes temporarily, and exchanges connected to Liquid suspended both deposits and withdrawals involving the network.
The Federation has stated that the Peg-out Authorization Key, which governs authorization for L-BTC exits back to the Bitcoin network, was not compromised in the incident. It has also said that hardware security modules and the multisignature scheme used by Federation members did not fail, pointing instead to the software-level flaw in transaction validation as the root cause.
An unusual on-chain message
In an on-chain message, the attacker described themselves as "hackers de sombrero blanco," the Spanish-language term for white hat hackers, a designation typically used by those who claim to expose vulnerabilities rather than exploit them for personal gain.
The Federation has not disclosed how it intends to address the shortfall in reserves or what recourse, if any, is available to L-BTC holders while the network remains offline. For now, the sidechain remains paused as the investigation into the exact mechanics of the exploit continues.




