
Someone walked off with roughly 4,000 bitcoins worth $340 million, and the price of getting them back was a bug fix. That’s the short version of what happened to Liquid Network last weekend, and it tells you a lot about the current state of crypto security.
According to TechCrunch, Liquid Network, a settlement exchange used by multiple cryptocurrency platforms and launched in 2018 by crypto firm Blockstream, confirmed on Sunday that a hacker had drained its wallet. The company posted on X calling the attacker a “white hat” hacker, a term used to describe someone who exposes security flaws rather than purely profiting from them. The network paused operations immediately.
The hacker’s alleged offer was blunt: fix the bug, get the bitcoin back. Blockstream says it did exactly that. Former Blockstream executive Samson Mow posted on X Monday that the company patched the vulnerability and that around 3,400 of the stolen coins had been returned. Still, about 600 bitcoins, roughly $47 million, remain under the hacker’s control. That’s not a small afterthought. That’s a lot of money sitting in someone else’s wallet while Blockstream calls the situation resolved.
This matters beyond the headline number. Liquid Network is not some obscure experiment. It’s infrastructure that multiple cryptocurrency exchanges depend on for settlement, meaning a failure here has the potential to ripple across platforms and affect users who never heard of Liquid Network at all. When shared financial infrastructure breaks, the people who feel it are rarely the ones who chose to take the risk.
The theft ranks among the largest known crypto heists this year, according to the Rekt leaderboard, which tracks these incidents. And there have been a lot of them. Crypto platforms have lost billions of dollars to exploits over the past few years, often through the same categories of vulnerability: smart contract bugs, access control failures, and flawed withdrawal logic. The fact that an attacker was able to withdraw funds of this scale before anyone noticed points to gaps in monitoring and circuit-breaker systems, not just a single code error.
The “white hat” framing is worth questioning too. Returning stolen funds in exchange for a fix is not the same as responsible disclosure. Real security researchers report vulnerabilities before exploiting them. Taking $340 million first and negotiating second is a different thing entirely, whatever label gets applied afterward.
Mow says operations will stay paused until further security improvements are in place. That’s the right call. But users of any platform built on Liquid Network should be asking what due diligence those platforms did on the infrastructure they chose to trust.