Protecting your investment accounts online
PORTFOLIOTRACKR
Security & Privacy

White-Hat Hackers Took 4,000 BTC From Liquid: What It Means

By James Whitfield · September 7, 2026 · 9 min read

In early September 2026, roughly 4,000 BTC (about $320M) left the Liquid Network at the hands of self-described white-hat hackers who say they will return most of it once a bug is patched. This is a clear window into how custody actually works, why holding your own keys shifts the risk instead of removing it, and how you can track everything with read-only connections that never expose a private key.

What actually happened on the Liquid Network?

Self-described white-hat hackers withdrew roughly 4,000 BTC, worth about $320M, from the Liquid Network and stated publicly that they would return most of it after a bug fix landed on September 7. The Liquid Network is a Bitcoin sidechain operated by a federation of businesses, where BTC is locked on the main chain and represented as L-BTC on the sidechain.

The key detail is who held the coins. On a federated sidechain, a set of functionaries jointly controls the peg that backs L-BTC, so a flaw in that shared machinery can move a lot of value at once. That is a very different risk profile from coins sitting in a wallet whose keys only you control.

What is custody risk, and how is it different from self-custody?

Custody risk is the chance that a third party holding your assets loses, freezes, or mishandles them. When you leave BTC on an exchange, in a wrapped or pegged token, or inside a federated system like Liquid, someone other than you controls the keys, and their security becomes your security.

Self-custody means you hold the private keys yourself, usually in a hardware or software wallet. It removes the third-party failure point, but it does not remove risk. It moves the risk onto you: your backups, your seed phrase, and your operational habits.

Custodial vs self-custody at a glance

FactorCustodial / peggedSelf-custody
Who holds keysThird party or federationYou
Main failure pointTheir breach or bugYour lost seed phrase
Recovery if you slipSupport may helpUsually none
Counterparty exposureHighNone

Neither model is universally safer. The Liquid episode is a reminder that convenience layers add counterparty exposure, while pure self-custody hands you a different job to get right. For a deeper walk through the trade-offs, our guide on crypto wallet security after the Ctrl Wallet exploit breaks down API keys versus seed phrases in plain terms.

What does the Liquid event mechanically mean for holders?

If you never touched Liquid or L-BTC, your BTC-USD holdings elsewhere are mechanically unaffected by this specific event. Price moves on headlines are separate from the pegged assets that were actually withdrawn.

If you did hold L-BTC or used a service built on Liquid, your exposure sits with that platform's response and the promised return. Here is what a holder can check for themselves, without anyone telling them what to do:

Checking your own exposure is not a trading decision. It is just knowing where your money actually is before headlines force the question.

Why read-only tracking beats exposing your keys

Read-only tracking lets you monitor balances and value without ever granting withdrawal power, so a compromised tracker cannot move your coins. The principle is simple: the tool that watches your portfolio should never be able to spend from it.

There are three common ways to connect crypto to a tracker, and they carry very different risk:

  1. Public address / xpub only: the tracker reads on-chain balances and cannot touch funds. Lowest risk.
  2. Read-only API keys: exchange keys created with trading and withdrawal permissions disabled. Low risk if scoped correctly.
  3. Full-permission keys or seed import: never do this for tracking. It hands away control.

PortfolioTrackr is built around the first two. You can add a wallet by its public address, or connect exchanges like Alpaca and Bybit with keys that are scoped to read only. If you want the exact permissions to set, our security checklist for API keys spells out which boxes to leave unchecked.

What read-only cannot do, by design

Read-only access cannot withdraw, trade, or transfer your assets under any circumstances. Even if the connection leaked, the worst case is someone seeing balances, not moving them. That is the whole point of separating monitoring from spending.

How PortfolioTrackr keeps monitoring separate from spending

PortfolioTrackr never asks for your seed phrase and never needs withdrawal permission to show your portfolio. You connect through public addresses or read-only keys, and everything from balances to profit and loss updates without any spending power attached.

Connecting anything is also optional. Manual entry, voice, text, CSV import, and broker screenshots work on every plan, so you can track crypto without linking a single account if that suits your threat model. Many privacy-minded holders enter cold-storage balances by hand and never expose an address at all.

For alerts, every position and every watchlist level is checked once a minute, around the clock, so you hear within a minute of your level being reached. PortfolioTrackr reports status against your own targets, still below target, Target 1 reached, or stop-loss level reached, and leaves the decision entirely to you. Watchlist alerts are a Pro and Lifetime feature.

How to reduce custody risk without giving up tracking

You can lower counterparty exposure while still watching everything in one place by separating where coins live from where you look at them. The habits below are checks and hygiene, not trading instructions.

On that last point, the difference matters more than most people think. Our comparison of SMS versus TOTP two-factor authentication explains why SIM-swap attacks make text-message codes the weaker choice. If you track both stocks and coins together, the workflow in our guide on tracking stocks and crypto in one app shows how read-only connections fit alongside equities.

The bottom line

The Liquid Network withdrawal of roughly 4,000 BTC is a live lesson in custody risk: the security of whoever holds your keys becomes your security. Self-custody removes the third party but hands you the responsibility, and pegged or federated systems add a shared failure point that can move a lot of value fast.

None of that changes the safest way to watch your holdings. Use read-only connections or public addresses, never expose a seed phrase to a tracker, and check your own exposure and target status before headlines make the decision feel urgent. Knowing where your money sits is not a trade. It is the groundwork that lets you make your own calls calmly.

Track your portfolio in real time: free for 3 days

Live P&L across stocks, crypto, and global markets. WhatsApp and Telegram price alerts. AI trade import. Unified dividend tracking. No brokerage connection required.

Start Free Trial
Download on the App Store Get it on Google Play
See the live demo first →

Frequently asked questions

Were my Bitcoin holdings affected by the Liquid Network hack?

Only if you held L-BTC or used a service built on the Liquid Network. Standard BTC held in your own wallet or on other platforms was not touched by this specific event. Check whether any of your positions route through Liquid to know your real exposure.

Is self-custody actually safer than leaving crypto on an exchange?

Self-custody removes third-party failure points but shifts risk onto you, mainly protecting your seed phrase and backups. Custodial or pegged holdings add counterparty exposure, as the Liquid event showed. Neither is universally safer; the right choice depends on your own operational habits and threat model.

How can I track my crypto without exposing my private keys?

Use read-only connections: add a wallet by its public address, or create exchange API keys with trading and withdrawal permissions disabled. PortfolioTrackr never asks for a seed phrase and works with public addresses or read-only keys, so a compromised connection can never move your coins.

What does read-only API access let a portfolio tracker do?

Read-only access lets a tracker see balances and value but never withdraw, trade, or transfer funds. Even if the connection leaked, the worst case is someone viewing balances. You can revoke the key from the exchange side at any time to cut off access instantly.

Can I track cold-storage Bitcoin without connecting anything?

Yes. PortfolioTrackr supports manual entry, voice, text, CSV import, and broker screenshots on every plan, so you can log cold-storage balances by hand without linking an account or exposing an address. Connecting a wallet or exchange is always optional.

James Whitfield
James Whitfield covers broker connections, data security and the mechanics of portfolio tracking at PortfolioTrackr: getting your positions in accurately and keeping them safe.