By CoinAINews Staff
September 7, 2026
Liquid Network has paused activity after nearly 4,000 BTC was withdrawn from its federation wallet in an incident that exposed a serious vulnerability in the Bitcoin sidechain's infrastructure. The Bitcoin involved was worth roughly $320 million at the time of the incident and represented about 95% of the roughly 4,200 BTC held in the federation wallet.
The incident initially appeared to be a major compromise of Liquid's Bitcoin reserves. However, subsequent information from SideSwap and blockchain investigators points to a different mechanism: approximately 4,000 L-BTC appears to have been created through a bug in the Elements software underlying Liquid and then used to trigger a legitimate-looking peg-out through SideSwap.
The unidentified party controlling the withdrawn funds has described itself as a white-hat hacker. Liquid has used the more cautious description “purported white-hat hackers”, meaning the claim has not been independently established. The party has said it intends to return most of the Bitcoin after the vulnerability is fixed.
Liquid Network Incident: Key Facts
| Detail | What We Know |
|---|---|
| Network | Liquid Network |
| Asset involved | L-BTC / BTC |
| Bitcoin withdrawn | Approximately 3,996–4,000 BTC |
| Reported value | About $320 million |
| Share of federation wallet | About 95% |
| Network status | Paused while the incident is investigated |
| Suspected mechanism | Elements software vulnerability |
| Actor's claim | Self-described white-hat hacker |
What Happened to Liquid Network?
Liquid Network is a Bitcoin sidechain developed by Blockstream. It is designed to allow faster and more confidential transactions while maintaining a one-to-one relationship between Liquid Bitcoin, or L-BTC, and Bitcoin held by the Liquid Federation.
On September 6, roughly 4,000 L-BTC was involved in a transaction that ultimately resulted in approximately 3,996 BTC being released from the federation's Bitcoin wallet. The amount represented almost all of the Bitcoin held in that wallet.
Reuters reported that approximately 4,000 BTC out of about 4,200 BTC in the wallet had been withdrawn. Liquid subsequently halted new transactions as a precaution.
The Key Detail: No Federation Key Was Reportedly Compromised
One of the most important details in the incident is that the federation's cryptographic signing key was not reported to have been compromised.
Instead, the withdrawal appears to have passed through the normal peg-out infrastructure. SideSwap said that approximately 4,000 L-BTC was submitted to its peg-out service and that the transaction was processed using a valid peg-out authorization.
According to reporting based on SideSwap's explanation, the problem was that the L-BTC being redeemed had apparently been created through a vulnerability in Elements, the open-source software used by Liquid.
That distinction changes how the incident should be understood. This was not simply a case of someone stealing a private key and signing an unauthorized transaction. The suspected vulnerability appears to have allowed invalid or unbacked L-BTC to enter the system and subsequently be redeemed for real Bitcoin.
How the Elements Bug Could Have Led to the Loss
The exact technical root cause is still being investigated, so it is important not to present every early technical theory as established fact.
What current reporting does establish is the broad sequence:
- Approximately 4,000 L-BTC was created through an Elements-related vulnerability.
- The L-BTC was sent to SideSwap's peg-out service.
- The peg-out process treated the transaction as valid.
- The Liquid Federation released approximately 3,996 BTC to the resulting Bitcoin address.
- Liquid then disabled bridge activity while developers investigated and patched the vulnerability.
SideSwap has said its systems and peg-out authorization key were not compromised. Instead, the affected L-BTC appeared valid to the system processing the redemption.
Why 4,000 BTC Is Such a Big Deal
The size of the withdrawal is what makes the incident particularly significant.
Approximately 4,000 BTC represented around 95% of the Bitcoin held in Liquid's federation wallet. In other words, the incident affected nearly the entire reserve associated with the wallet at the center of the event.
The reported value was approximately $320 million, although the dollar value naturally changes with Bitcoin's market price.
For a Bitcoin sidechain built around a one-to-one BTC/L-BTC relationship, an event involving such a large portion of the backing is a major test of the system's security and recovery procedures.
Why Did Liquid Pause the Network?
Liquid disabled its bridge nodes after the incident, preventing new transactions from being submitted while developers investigated the vulnerability.
Exchanges also moved to suspend or prepare to suspend L-BTC deposits and withdrawals while the situation was being assessed. SideSwap said swaps, peg-ins and peg-outs were paused until the network could safely resume operations.
Pausing the network is a precaution designed to stop the same vulnerability from being exploited again while the affected software and bridge infrastructure are secured.
Are the Attackers Really White Hats?
That remains an open question.
The party controlling the funds has identified itself as a white-hat hacker and communicated with Blockstream through on-chain messages. Liquid has described the actors as “purported white-hat hackers.”
The distinction is important. Calling someone a white-hat hacker is not the same as independently confirming that the activity was an authorized security test or that the actor had permission to remove the funds.
The actor has reportedly said that most of the Bitcoin will be returned after the underlying vulnerability is fixed. That makes the incident unusual, but the promised recovery should not be treated as complete until the funds are actually returned.
Blockstream Says the Bridge Nodes Were Patched
Communication between the party holding the Bitcoin and Blockstream has continued through on-chain messages.
According to The Block, the attacker said the funds would be returned after the underlying bug was fixed and every relevant node was patched. Blockstream later sent a signed on-chain message stating that the bridge nodes had been patched and that the funds could be returned.
At the time of that report, however, the approximately 4,000 BTC was still in the attacker's wallet.
This means there are two separate developments to watch: the technical vulnerability may have been addressed, but the Bitcoin recovery itself still needs to be completed.
Did Someone Hack Bitcoin?
No.
The incident does not indicate that Bitcoin's base blockchain or proof-of-work consensus was compromised.
The affected system was Liquid, a separate Bitcoin sidechain with its own infrastructure, federation and L-BTC peg mechanism.
This distinction matters because a vulnerability in a sidechain does not automatically translate into a vulnerability in Bitcoin itself.
Bitcoin transactions on the main network continue to operate independently of Liquid's infrastructure.
What Is Liquid Bitcoin (L-BTC)?
L-BTC is Liquid Network's Bitcoin-pegged asset. It is designed to represent Bitcoin on the Liquid sidechain and maintain a one-to-one relationship with BTC.
Users can move Bitcoin into Liquid and receive L-BTC, while the reverse process allows L-BTC to be redeemed for Bitcoin through the network's peg mechanism.
That structure makes the security of the peg particularly important. If a software vulnerability creates L-BTC that is not backed by corresponding Bitcoin, the system can potentially face a shortfall between the amount of L-BTC circulating and the amount of BTC available to back it.
Why the Incident Matters Beyond Liquid
The Liquid incident highlights a broader issue for crypto infrastructure: asset backing and software integrity are two different security problems.
A system can protect its private keys while still facing risk from a software vulnerability that creates invalid assets or bypasses an important validation rule.
This is especially relevant for sidechains, bridges, wrapped tokens and other systems that connect blockchain assets across different environments.
For users, the lesson is not that every sidechain or wrapped asset is unsafe. Instead, the incident shows why the technical assumptions behind a peg matter just as much as the custody arrangements protecting the underlying assets.
What Happens to the 4,000 BTC Now?
The next major development will be whether the Bitcoin is actually returned.
The party holding the funds has said it intends to return most of them after the vulnerability is fixed. Blockstream has reportedly confirmed that its bridge nodes have been patched.
But until the Bitcoin is transferred back to the appropriate federation-controlled wallet and the network establishes how the incident will be reconciled, the recovery should be considered promised rather than completed.
The investigation also needs to establish exactly how the vulnerability worked, why the invalid L-BTC was accepted and what changes are required to prevent a similar incident from happening again.
What Users Should Watch Now
- Network status: When Liquid resumes normal operations.
- BTC recovery: Whether most or all of the withdrawn Bitcoin returns.
- Elements patch: Details of the vulnerability and the permanent fix.
- L-BTC deposits: When exchanges restore deposits and withdrawals.
- Post-mortem: Blockstream and Liquid's final technical explanation.
- Peg security: Whether additional safeguards are introduced around L-BTC issuance and redemption.
Frequently Asked Questions
How much Bitcoin was withdrawn from Liquid Network?
Approximately 3,996 to 4,000 BTC was withdrawn from the Liquid Federation wallet, with the value reported at roughly $320 million at the time of the incident.
What percentage of Liquid's Bitcoin was affected?
The withdrawal represented approximately 95% of the roughly 4,200 BTC held in the federation wallet before the incident.
Was Liquid's private key stolen?
There is currently no indication that the federation's cryptographic key was compromised. The withdrawal was reportedly processed using a valid peg-out authorization, while the underlying problem was linked to an Elements software vulnerability.
What caused the Liquid Network incident?
Current reporting points to a vulnerability in Elements software that allowed approximately 4,000 L-BTC to be created and subsequently redeemed through Liquid's peg-out infrastructure. The precise technical root cause remains under investigation.
Are the hackers going to return the Bitcoin?
The party controlling the funds has said it intends to return most of the Bitcoin after the vulnerability is fixed. Blockstream has reportedly said its bridge nodes were patched, but the recovery is not complete until the funds are actually returned.
Was Bitcoin itself hacked?
No. The incident affected Liquid's sidechain infrastructure and its L-BTC peg mechanism. There is no indication that Bitcoin's underlying blockchain consensus was compromised.
Is Liquid Network still paused?
Liquid has paused network activity while the security incident is addressed. The status of deposits, withdrawals and normal sidechain operations remains an important development to monitor as the response continues.
Bottom Line
Liquid Network's roughly 4,000 BTC incident is significant not simply because of the dollar value involved, but because it exposes a different class of blockchain security risk.
The latest information points away from a straightforward private-key theft. Instead, approximately 4,000 L-BTC appears to have been created through an Elements software vulnerability and then redeemed for roughly 3,996 BTC through the Liquid peg-out system.
The actors call themselves white hats and have offered to return most of the funds after the bug is fixed. Blockstream has reportedly patched the relevant bridge nodes, but the Bitcoin recovery still needs to be verified on-chain.
For Bitcoin users, the key takeaway is straightforward: Liquid was affected; Bitcoin itself was not hacked. The final technical post-mortem, the return of the withdrawn BTC and the safeguards introduced afterward will determine how the crypto industry ultimately assesses this incident.
Sources
- Reuters — Bitcoin-based Liquid Network says $320 million withdrawn in hack
- The Block — Liquid Network attacker says they will return most of 4,000 BTC after bug fix
- The Block — Liquid Network pauses after purported white-hat hackers withdraw $320 million
- Bitquery — Liquid Network on-chain investigation

0 Comments