The Zhitong Finance App learned that recently, the Bitcoin-linked Liquid Network was attacked by hackers and lost up to 320 million US dollars. The incident has once again damaged the reputation of cryptocurrencies — and the industry is struggling to convince banks and institutional investors that digital assets can be integrated into mainstream financial infrastructure.
However, there is far more to be lost than the stolen bitcoins themselves. Liquid's original purpose was to improve the utility of this largest cryptocurrency in transactions and settlements, and this incident just exposed the risks on the periphery of the blockchain: wallets, escrow arrangements, transaction infrastructure — these are all components that users have to rely on in the end.
Nikhil Raghuveera, CEO of blockchain compliance infrastructure service provider Predicate, said: “The ongoing attacks send a signal to global fintech companies and institutions that decentralized finance is not ready to enter the mainstream stage. Blockchain excels in financial settlement, but DeFi is far from meeting the institutional-level standards that are taken for granted in traditional markets.”
Numerous hacking attacks are exposing decentralization — a characteristic that was once hailed as cryptocurrency's greatest strength — as a vulnerable link. Due to a lack of central authority to undo misoperations, protect assets, and bear losses, the entire system leaves users dependent on fragmented infrastructure, and malicious attackers can always find new vulnerabilities.
Although the total amount of money stolen has declined, the frequency of hacker attacks has increased. According to DeFilLama data, there have been 250 attacks so far in 2026, with stolen funds of about 1.4 billion US dollars; in 2025, there were 146 cases, with losses of about 2.7 billion US dollars.
This year, there were 26 attacks on cross-chain bridges and cross-chain infrastructure, accounting for more than 10%. These tools are used to help users transfer tokens or information between different blockchains. In 2025, DeFilLama recorded only 3 such incidents.
Cross-chain bridges are a key component of DeFi and can automate the transfer and exchange of various types of digital assets. However, with numerous cross-chain projects and limited cybersecurity review capabilities, the risk has increased.

A “white hat hacker” has surfaced
This week's Liquid cyberattack is the latest major security incident targeting decentralized platforms this year, following Kelp DAO and Drift Protocol. The first two attacks collectively caused $588 million in losses.
Liquid said that about 4,000 bitcoins in its main wallet (accounting for about 95% of total holdings) were stolen by so-called “white hat hackers.” This type of hacker exploits security flaws and usually returns the funds after charging a certain fee. According to Alex Thorn, head of research at Galaxy Digital (GLXY.US), a cryptocurrency company, the hacker returned 3,400 bitcoins and confiscated assets worth about 47 million US dollars without permission.
Liquid said the settlement platform authorization key used in the attack was not disclosed. This is another reminder that even if the underlying blockchain itself works properly, the supporting systems built around it may still fail.

Just last week, an attacker stole $6 million from a digital asset lending platform linked to Crypto.com; in August, the attack on Coldcard, a popular offline Bitcoin wallet, also raised questions about the “safest way to store digital assets.”
Even if the industry has a highly secure underlying network, investors may still be exposed to risk through their higher-level applications and intermediaries.
Ziqing Ang, head of policy at TRM Labs Asia Pacific, stated: “These incidents suggest that the vulnerability lies at the operational and infrastructure levels, rather than the underlying consensus mechanism itself.”
This poses a particularly prominent challenge for the traditional financial industry, which is accelerating its entry into the cryptocurrency sector.
For example, a bank considering issuing tokenized deposits or securities must not only evaluate the security of the blockchain itself, but also confirm whether the custodian system, smart contract, settlement mechanism, and entity responsible for asset control are reliable.
Raghuveera said, “A vulnerability in one part of the infrastructure may affect multiple businesses that depend on it. An exchange using an attacked bridging tool, a wallet holding the affected tokens, or a market maker providing liquidity may be instantly exposed to risk, even if their own system is never breached.”
Aneirin Flynn, CEO of cybersecurity technology company FailSafe, believes that although most of the bitcoins stolen in the Liquid hack have been returned, this “hasn't changed the nature of the risk.”
Flynn stated, “It is entirely possible that this attack was carried out by a malicious gang with no intention of returning the funds. Millions of dollars were easily extracted due to code flaws, indicating that software vulnerabilities are a permanent risk faced by cryptocurrency infrastructure for a long time.”
Where the conflict lies
This is the paradox faced by cryptocurrencies as they mature: the industry was born to reduce trust reliance on financial intermediaries; yet the future of institutionalization is increasingly dependent on trust in the infrastructure surrounding blockchain.
The cost of damaged confidence may be reflected in higher security standards, greater demand for insurance and capital buffers, further decentralization of custodian and settlement networks — or simply a slowdown in institutional adoption.
Over the years, the cryptocurrency industry has been proving that blockchain can provide a more efficient financial path. And the Liquid hack once again reminds everyone that the credibility of this track ultimately depends on whether the infrastructure itself that hosts the assets above it is strong.