was abnormally withdrawn from the Liquid Network Federation reserve. The attacker exploited an Elements software vulnerability to create L-
without real
backing, then redeemed it for real
through the normal exit process. The attacker claimed to be a "white hat" and returned about 85% of funds after the vulnerability was patched, but approximately 598.5
remains unreturned.

Withdrawn

Returned
598.5
Outstanding
with no real
backing
enters normal transaction / exit flow
flows out of Federation reserve wallet (≈4,000
)Chainalysis notes that the attacker exploited a Liquid transaction validation software vulnerability, not a private key leak. The system validated an asset that was cryptographically valid but economically shouldn't exist.
Attacker exploits vulnerability to create unbacked L-
, withdrawing approximately 4,000
via normal Peg-out, valued at approximately $319 million.
Liquid completes software patch; attacker self-identifies as "white hat" via on-chain message, returns approximately 3,400
(85%).
Peg-in/Peg-out suspended, approximately 598.5
not yet returned, L-
redemption mechanism not restored.
reserve → L-
→ Elements validation → Peg-out
(95% of reserves)
(~$272M)
(~$47M) This incident does not mean the
network itself was compromised. What is truly challenged is the trust model between sidechain asset issuance, validation, and redemption.
The Liquid incident reminds the market that when
enters other systems through sidechains, wrapped assets, or bridges, the risk investors bear is no longer entirely equivalent to directly holding
. The industry needs to re-examine the gap between "code security" and "economic security."
Holder Risk Alert
Peg-out remains suspended, and L-
cannot currently be redeemed for
. The implied backing ratio is approximately 86%, but Liquid has not yet announced a final plan for handling the shortfall. Do not send
to the paused Liquid Network, and beware of secondary scams such as "official refunds" or "seed phrase verification."
Recommended balance check: Blockstream Green, Aqua, SideSwap, exchange accounts.
Most crypto thefts don't happen because blockchain was broken. They happen because your phone was compromised. Here's what you need to know.
Malicious apps can read your clipboard, capture screenshots, log keystrokes, and steal seed phrases stored on your phone.
Hackers can remotely control your device, approve transactions without your knowledge, and drain wallets while you sleep.
Fake wallet apps, malicious browser extensions, and phishing links can trick you into revealing your private keys.
Phones are always connected. They run dozens of apps, receive links, scan QR codes, and store sensitive data. A single malicious app or an unpatched vulnerability is all it takes:
Your private keys stay offline at all times. Malware on your phone or computer cannot reach them.
Transactions are signed inside the secure chip. Your seed phrase is never exposed to your phone or computer.
Hackers cannot remotely control, drain, or access a hardware wallet. You must physically confirm every transaction.
The device screen shows exactly what you're signing. No hidden approvals, no clipboard hijacking, no surprises.
Hardware wallets are designed for cold storage — ideal for holding
and other assets securely for years.
Even if the device is stolen, your funds remain locked behind a PIN and optional passphrase.
Don't let your phone be your weakest link. Take control of your crypto today.
Trade Securely — Get a Led-ger