Short answer: On September 6, 2026, an attacker drained about 4,000 BTC, worth roughly $320 million, from the federation wallet that backs Blockstream's Liquid Network, a Bitcoin sidechain. The Liquid Network exploit used a software bug to create L-BTC that was never backed and redeem it for real bitcoin, leaving L-BTC less than 5% covered until the coins come back; bridge operations were paused the same day.
What happened
Liquid is a sidechain launched by Blockstream in 2018. Users lock bitcoin with a group of operators called the federation and receive the same amount of L-BTC, a token that moves faster and more privately than on-chain BTC and can be redeemed one-for-one. Before Sunday the federation wallet held roughly 4,200 BTC.
On the afternoon of Sunday, September 6, the Liquid Network federation signed a withdrawal of about 3,996 BTC to an address it had never interacted with (on-chain trackers counted just over 4,000 BTC leaving the reserve in total). Only around 200 BTC remained behind. Hours later, the recipient embedded a short message in a Bitcoin transaction describing themselves as white hats and asking Blockstream to make contact on-chain. Blockstream replied through the same channel with a message signed by its PGP key.
- Amount taken: about 4,000 BTC, roughly $320 million at the time.
- Reserve before and after: about 4,200 BTC before, about 200 BTC after.
- Route: a normal peg-out processed through SideSwap, a Liquid swap service authorised to request withdrawals.
- Response: bridge nodes disabled, peg-ins and peg-outs paused, exchanges asked to halt L-BTC deposits and withdrawals.
How the Liquid Network exploit worked
This was not a stolen key. Blockstream said that neither SideSwap's peg-out authorization key (PAK) nor any of the federation's signing keys appeared to be compromised. Instead, early analysis points to a bug in Elements, the open-source software (a fork of Bitcoin Core) that Liquid runs on.
- According to on-chain investigators, the attacker tested the system over several days with small peg-ins and dozens of trial transactions.
- The flaw reportedly sat in how Elements caches the cryptographic proofs that hide transaction amounts. By exploiting it, the attacker made nodes accept a transaction that created about 4,000 L-BTC from nothing.
- The fake L-BTC was then sent through SideSwap's regular peg-out flow. Because the transaction looked valid to the network, the federation's hardware security modules signed the payout — Liquid needs 11 of its 15 functionaries to agree, and they did.
In other words, the multisig worked exactly as designed: it signed what the consensus rules said was legitimate. The weak point was the rule-checking software, not the keys.
The exploit in numbers
| Metric | Value |
|---|---|
| Federation reserve before the attack | ~4,200 BTC |
| Bitcoin withdrawn | ~4,000 BTC (~$320M) |
| Reserve left | ~200 BTC |
| L-BTC backing after the drain | under 5% |
| Signatures required to move funds | 11 of 15 |
What was and was not affected
The Bitcoin blockchain itself was untouched; this is a failure inside a sidechain, not in Bitcoin. Liquid said other assets issued on the network — including USDT on Liquid and tokenized real-world assets — were not affected, because they are not redeemed from the BTC reserve. The Liquid chain also kept producing blocks.
The hit falls on L-BTC holders. A token that promises one-for-one redemption is only as good as the reserve behind it, and with about 95% of that reserve gone, L-BTC could not be redeemed at all while the bridge was paused. Whether holders are made whole depends on the attackers returning the coins or on Blockstream and the federation covering the gap.
The self-declared white-hat label deserves caution. Security researchers pointed out that responsible disclosure usually means reporting a bug before moving funds, not after. Taking $320 million first and negotiating second gives the attacker leverage, whatever their stated intentions.
What it means for you
Any wrapped or bridged version of bitcoin — L-BTC, WBTC, tokens on bridges between chains — replaces Bitcoin's own security with the security of whoever holds the reserve and the software they run. Our explainer on cross-chain bridges covers why these reserves are such frequent targets.
- If you hold L-BTC, do not panic-sell it at a discount on thin markets, and do not send BTC to Liquid peg-in addresses until the federation confirms the network is back.
- Watch for fake "recovery" or "claim" sites. High-profile hacks are always followed by phishing that promises compensation in exchange for a wallet connection or seed phrase.
- Prefer native assets for storage. If you only need bitcoin, hold BTC on the Bitcoin network; use wrapped versions only for the time you actually need them.
- When swapping, check the network. BTC, L-BTC and wrapped BTC share a name but not a risk profile — make sure the network you pick is the one you mean.
Key takeaways
- About 4,000 BTC (~$320 million) left the Liquid federation wallet on September 6, 2026, leaving about 200 BTC.
- The attacker appears to have exploited a bug in Elements to mint unbacked L-BTC and redeem it through SideSwap.
- No signing keys were compromised; the federation signed because the transaction looked valid.
- Peg-ins and peg-outs were paused; Bitcoin itself and non-BTC Liquid assets were unaffected.
- The attackers call themselves white hats, but their claim is unverified.
If you want to move between assets without holding a wrapped token in the middle, you can compare direct routes on the exchange pairs page and see the exact payout before creating an order.
Sources: Bitcoin Magazine, Protos, The Register, Bitquery
Frequently asked questions
What is the Liquid Network?
Liquid is a Bitcoin sidechain built by Blockstream and launched in 2018. Users lock BTC with a federation of operators and receive L-BTC, a token meant to be redeemable one-for-one for bitcoin.
How much bitcoin was taken from Liquid Network?
About 4,000 BTC, worth roughly $320 million, was withdrawn from the federation wallet on September 6, 2026. That left around 200 BTC backing roughly 4,200 L-BTC.
Was Bitcoin itself hacked?
No. The Bitcoin network was unaffected. The bug was in Elements, the software behind the Liquid sidechain, which let the attacker create unbacked L-BTC and redeem it for real BTC.