What happened
A group identifying itself as white-hat hackers moved roughly $320 million worth of bitcoin out of Blockstream's Liquid sidechain, Decrypt reported Monday morning. The unusual part isn't only the size. It's the communication channel.
Blockstream and the attackers are exchanging PGP-signed messages embedded in Bitcoin transactions, using the chain itself as a public negotiation log. That format lets both sides prove authorship without going through Twitter, email, or a mediator, and it leaves a permanent record every observer can audit. The incident hit Liquid's federated peg, the multisig arrangement that holds the BTC backing every L-BTC in circulation.
As of Monday, the funds sit inside Liquid-linked addresses rather than on a mixer or a centralized exchange. Blockstream has not published a full incident post-mortem at the time of writing.
Why it matters
Liquid isn't a rollup or a trust-minimized L2. It's a federated sidechain, meaning a set of functionaries hold the peg keys and sign off on withdrawals back to the Bitcoin base layer. That design has always been the tradeoff Blockstream asked users to accept in exchange for faster settlement and confidential transactions.
A $320 million withdrawal by an outside party, even one waving a white-hat flag, is exactly the failure mode critics have flagged for years. The optics look bullish only in the narrow sense that the coins haven't been dumped and the attackers are talking. The structural read is harsher.
If a federated peg can be bypassed or coerced by anyone other than its members, the peg's guarantee is worth less than the marketing suggests. Every institution running BTC through Liquid-based products, from OTC desks to prediction markets, is now recalculating counterparty risk on the fly.
