Liquid Network Hack: 4,000 BTC Drained From the Sidechain, 3,400 Returned
The 6 September attack emptied the Liquid federation wallet of $320 million. The attackers called themselves 'white hats' and returned most of it, but kept around 598 BTC; Blockstream refused to pay.

In brief: On 6 September 2026, unknown attackers drained around 4,000 BTC (roughly $320 million) from the federation wallet of the Liquid Network sidechain — almost the entire backing of the L-BTC token. The cause was not stolen keys but a bug in the Elements code: it allowed L-BTC to be created without real bitcoin backing and exchanged for real coins through the standard withdrawal procedure. On 8 September the attackers, calling themselves "white hats," returned 3,400 BTC, keeping around 598 BTC (~$47 million) as a self-appointed reward. On 11 September, Blockstream said it would not pay a ransom and would hand the case to law enforcement.
Timeline of the incident
| Date and time (UTC) | What happened |
|---|---|
| 6 September, 14:05 | Around 4,000 L-BTC were sent for processing via the SideSwap service — outwardly it looked like an ordinary withdrawal (peg-out) request |
| 6 September, 14:28:56 | The federation released around 3,996 BTC to the attacker's address (block 965,783). The transaction contained 83 inputs, each with 11 valid signatures of the 11-of-15 multisig |
| 6 September, minutes later | On-chain analyst ErgoBTC publicly flagged the outgoing transfer |
| 6 September, during the day | The Liquid federation halted bridge nodes, and exchanges began suspending L-BTC deposits and withdrawals. The unknown party left an on-chain message: "we are white hats, contact us on-chain" |
| 7–8 September | Negotiations via signed on-chain messages; 3,400 BTC returned on 8 September |
| 11 September | Blockstream publicly refused to pay a ransom and announced its intention to involve law enforcement. The attackers retained around 598.5 BTC — roughly 15% of the drained amount |
What went wrong technically
Liquid is a federated bitcoin sidechain: real BTC are locked in a shared wallet controlled by a federation of 15 members under an 11-of-15 multisig scheme, while the sidechain issues the L-BTC token, backed one to one. The reverse exchange of L-BTC for BTC is called a peg-out.
The key detail of this attack: the signatures were genuine. All 83 inputs of the transaction contained exactly 11 valid signatures — meaning the federation itself authorized the withdrawal, because from its point of view the request looked legitimate. Blockstream separately stresses that the peg-out authorization key (PAK) and other signers' keys were not compromised.
The problem lies in software-level validation. Liquid runs on Elements, a fork of Bitcoin Core, and early investigation points to a bug that allowed a dynafed header with a mismatched height to be accepted; a commit dated 1 September addressed precisely this problem. The result: the attacker was able to obtain L-BTC without actually depositing bitcoin and withdraw them through the standard procedure. After the incident, the public Liquid.net dashboard showed the backing of issued L-BTC below 5%.
Casa's head of security Jameson Lopp also weighed in on the incident: he pointed out that the codebase of the functionary — the component serving the federation — had not been updated for about two years, with the last commit dated 19 April 2024.
"White hats" or not
From the outset, the attackers positioned themselves as whitehat researchers and said they were ready to return the funds once the vulnerability was fixed. Formally, they did return the bulk — 3,400 of ~4,000 BTC. But the 598 BTC they kept was set by themselves, without any agreement with the team, and that is exactly what became the subject of dispute.
Blockstream in its statements called the attackers "alleged white hats," without confirming the status, and on 11 September flatly rejected the ransom logic. Some industry specialists — including Ledger's chief technology officer — publicly rejected the whitehat interpretation, drawing a parallel with past attacks on cross-chain bridges, where similar rhetoric was used for bargaining.
The practical difference is substantial: an official bug bounty program fixes the reward amount in advance, whereas a "bounty after the fact" is legally indistinguishable from extortion.
The state of the network and users' money now
- Liquid has suspended acceptance of new transactions and disabled bridge nodes; peg-out is unavailable.
- Exchanges that supported L-BTC have halted deposits and withdrawals of the token. Each platform sets its own timeline for resumption.
- Other assets on the Liquid network — USDT, DePix, tokenized real-world assets — are unaffected, according to the developers.
- Bitcoin's base layer was not harmed: this is a bug in a separate sidechain, not in the BTC protocol.
For L-BTC holders, only one sensible course is available right now — wait for the official technical postmortem and the federation's decision on restoring the backing. Any offers to "urgently swap L-BTC" in chats and direct messages at a time like this are almost certainly scams: attacks on holders of affected assets traditionally come in a wave right after a major incident.
Market reaction
The bitcoin price barely reacted to the news: during the days of the incident BTC held around $79,700–80,000, and by 13 September it had slid to $77,000 for macroeconomic reasons — the market is waiting for the US Federal Reserve (the Fed) meeting on 16 September. Details in the article "Bitcoin stuck near $77,000 ahead of Fed meeting".
Traders treated the situation as a local problem of specific infrastructure rather than a systemic risk to bitcoin — and that is perhaps the main takeaway of the week: the price of the base asset and the reliability of the layers built on top of it live separate lives.
The lessons
- Multisig does not protect against a logic error. The 11-of-15 scheme worked as designed — the vulnerability was one level up, in request validation. Any audit limited to "how many keys are needed" catches nothing in such a scenario.
- Abandoned code is a separate risk category. A component not updated for two years while holding hundreds of millions of dollars in assets is not "stability" but accumulated technical debt.
- Wrapped bitcoin is not bitcoin. L-BTC, WBTC and their equivalents carry issuer and bridge risk. The backing can go to zero in a single transaction, while the BTC in a user's own wallet is entirely unaffected.
Sources
- ForkLog: "Week in review: bitcoin around $77,000 and the theft of ~4,000 BTC from Liquid Network", 13 September 2026
- Protos: How 4,000 BTC walked out of Blockstream's Liquid Network
- Shattered.io: Liquid Network Hack: $320M Bitcoin Sidechain Exploit
- 24/7 Wall St.: Attackers Drained 4,000 Bitcoin From Blockstream's Liquid Network, 8 September 2026
- The Cryptonomist: Liquid Network Hack Drains 4,000 BTC in Major Security Breach, 8 September 2026


