A Bitcoin sidechain that banks and exchanges trust to move money quietly in the background just proved how much can go wrong when “quiet” also means “under-audited.” On September 6, 2026, an attacker walked out of Blockstream’s Liquid Network with roughly 4,000 BTC, worth about $320 million at the time, then gave most of it back two days later. The episode leaves behind a reconciliation problem, a $47 million hole, and a fresh argument about whether federated sidechains are still fit for purpose in 2026.
Liquid Network is a Bitcoin-based settlement layer launched by Blockstream in 2018, built so exchanges and institutions could move BTC and other assets faster and more privately than on the base Bitcoin chain. Its L-BTC token is supposed to be backed one-for-one by real Bitcoin sitting in a federation-controlled reserve. That reserve held close to 4,200 BTC before the attacker’s transaction landed. Afterward, it held closer to 200.
What Happened at Liquid Network on September 6
Liquid Network confirmed the incident on Sunday, September 6, posting that “purported white-hat hackers” had withdrawn roughly 4,000 BTC from the federation wallet backing L-BTC, worth about $320 million at the time, according to CoinDesk’s reporting on the exploit. Bitcoin Magazine put the precise transaction size at 4,019.4 BTC, pulled from a single peg-out. Other outlets landed closer to 3,996 BTC, a gap that traces back to which specific transactions each report counted rather than a second, separate theft.
Liquid Network’s own account, posted publicly, read: “We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet.” The project halted new network activity within hours and warned users that Liquid wallets would be affected while the federation investigated.
Crucially, this wasn’t a stolen-private-key story. Liquid stated plainly that the withdrawal route, not the federation’s signing keys, was the problem: “What we know so far is that the funds were withdrawn via SideSwap, a settlement platform permitted to handle withdrawals from the network, though the key used in the process was not compromised.” That distinction shaped almost everything that happened over the following week.
Timeline: From Peg-Out to Partial Refund
- September 6: Attacker executes a peg-out of roughly 4,000 BTC (reported between 3,996 and 4,019.4 BTC across outlets) from the Liquid Federation reserve using SideSwap’s Peg-out Authorization Key route.
- September 6: Liquid Network halts new transactions and publicly discloses the withdrawal, describing the actors as “purported white-hat hackers.”
- September 6-7: Blockstream engineers trace the exploit to a software defect in the Elements codebase that Liquid runs, rather than to any compromised federation key.
- September 7: The attacker posts an on-chain message demanding a fix before returning funds.
- September 7-8: Blockstream patches the affected bridge nodes.
- September 8: The attacker returns 3,400 BTC, about 85% of the withdrawn total, and keeps 598.5 BTC.
- September 8-12: Reports describe a standoff over the remaining coins, including a rejected demand for roughly $50 million to release them.
- September 26: Liquid’s peg operations remain restricted in some reporting, the 598.5 BTC is still unreturned, and no reimbursement or insurance settlement has been announced.
That last point matters for anyone tracking this story today. Three weeks on, Liquid Network has not published a full technical postmortem, and the attacker’s identity, whitehat claim included, remains unverified by any independent party.
How Much Was Actually Stolen? Reconciling the Numbers
Coverage of the Liquid Network hack scattered across several dollar figures in its first 48 hours, largely because BTC’s price moved between the withdrawal and the partial return, and because different outlets rounded the underlying BTC count differently. Here is how the reporting lines up.
| Reported Figure | BTC Amount | USD Value (approx.) | Status |
|---|---|---|---|
| Initial withdrawal (Bitcoin Magazine) | 4,019.4 BTC | ~$320 million | Confirmed by Liquid Network |
| Alternate withdrawal count | ~3,996 BTC | ~$316 million | Reported by Crypto News, Tech Times |
| Amount returned | 3,400 BTC | ~$262.6 million | Confirmed via Blockstream status updates |
| Amount retained by attacker | 598.5 BTC | ~$47 million | Unresolved as of September 26 |
| Federation reserve before hack | ~4,200 BTC | ~$336 million | Per Liquid Network’s own statement |
Adding the returned and retained figures (3,400 plus 598.5) gets to 3,998.5 BTC, close to but not exactly matching either the 3,996 or 4,019.4 BTC withdrawal counts reported elsewhere. That gap is small in relative terms, but it underlines a real problem: nobody outside Blockstream has published a transaction-by-transaction reconciliation of the incident, so the public is working from press statements rather than an audited ledger.
Inside the Bug: How Unbacked L-BTC Slipped Past the Federation
Liquid’s entire design rests on a simple promise: every unit of L-BTC in circulation is backed by a real bitcoin sitting in the federation’s reserve. Peg-ins lock BTC and mint L-BTC. Peg-outs burn L-BTC and release BTC. The reported failure sat in the second half of that loop.
According to crypto.news’ technical breakdown, the exploit traced back to a cache-key collision bug in the confidential-transaction verification logic inside Blockstream’s Elements software, the codebase Liquid runs on. That flaw let the attacker generate or validate L-BTC that had never actually been backed by a genuine BTC deposit. Once that unbacked L-BTC existed, the federation’s own peg-out machinery treated it as legitimate and released real bitcoin against it. No signature was forged and no private key left federation custody. The system simply accounted for money that was never really there.
Tech Times, citing its own review of the incident, put the drained share of Liquid’s reserve at roughly 95%, framing the bug as an accounting failure at the bridge layer rather than conventional key theft, a distinction the outlet said had been confirmed by Blockstream directly.
SideSwap and the Peg-Out Authorization Key, Explained
SideSwap is a Liquid-based trading and settlement platform, one of a small number of services the federation has authorized to submit peg-out requests on behalf of users through a Peg-out Authorization Key, or PAK. In practice, the PAK is a permission slip: it tells the federation that a given redemption request came through an approved channel, so the federation doesn’t need every individual user to interact directly with federation infrastructure.
Liquid was explicit that the PAK itself was not stolen or forged. SideSwap functioned as the route the attacker used, not the source of the vulnerability. The invalid L-BTC entered the system upstream of SideSwap, and SideSwap’s authorized peg-out channel simply carried the redemption through to the federation reserve, exactly as it was designed to for legitimate withdrawals. That is arguably the most uncomfortable part of the story for anyone running bridge-adjacent infrastructure: the parts everyone assumes are the attack surface, keys and permissions, held up fine. The part nobody was watching closely enough, token-accounting logic buried in a shared codebase, did not.
“We Are Whitehats”: The Attacker’s On-Chain Message
Rather than disappearing, the attacker left a message on-chain in the days after the withdrawal, reported by The Register, that framed the theft as a security disclosure rather than a robbery:
"Please fix the bug first. The chain is under risk at latest commit right now.
Make sure every node is patched. Then we will transfer the money back
safely after confirming the fix."
The message was signed by an unidentified attacker and posted through Bitcoin’s OP_RETURN field, a standard way to embed short text in a transaction, according to The Register’s reporting. Whether the framing is genuine or a public-relations move by someone who simply wanted leverage over Blockstream is impossible to verify from the outside. “White hat” is a self-description here, not an independently confirmed legal status, and no named security firm has publicly vouched for the attacker’s motives.
Blockstream’s Patch and the Rejected $50 Million Bounty Demand
Blockstream moved fast on the technical fix, patching the affected bridge nodes within roughly 24 to 36 hours of disclosure. Samson Mow, former chief strategy officer at Blockstream, confirmed the outcome publicly: “3,400 BTC of the roughly 4,000 BTC withdrawn on September 6 has been returned to the Liquid Federation wallet,” he said, according to TechRadar Pro’s reporting. Mow added that “the return followed confirmation from Blockstream that the affected bridge nodes have been patched,” tying the refund directly to the fix rather than to any negotiated payment.
That left 598.5 BTC, worth about $47 million, unaccounted for. CryptoSlate reported that the attacker subsequently floated a demand for roughly $50 million in exchange for the rest of the funds, and that Blockstream turned it down, effectively betting the company would rather absorb the loss than negotiate with someone who had just drained 95% of its reserve. As of publication, that standoff has not produced a public resolution.
Why 598.5 BTC Is Still Unaccounted For
Three weeks after the incident, roughly $47 million sits in an attacker-controlled wallet with no confirmed path back to Liquid’s reserve. No named law enforcement agency or financial regulator has publicly attached itself to the case, based on available reporting as of September 26. There is no confirmed insurance payout, no disclosed reimbursement plan for anyone holding L-BTC that may have been affected, and no independent forensic report from a named security firm walking through the exploit chain end to end.
That silence is notable given how forthcoming Liquid and Blockstream were in the first 48 hours. It suggests the company may be treating the remaining 598.5 BTC as a closed chapter, an acceptable cost of getting the other 85% back quickly and quietly, rather than a case to keep pursuing publicly.
Liquid Network vs Bitget vs the Rest of September’s Hacks
The Liquid incident didn’t happen in isolation. September 2026 turned into one of the year’s roughest months for crypto infrastructure, with at least three distinct categories of failure showing up inside three weeks: a sidechain accounting bug, a centralized-exchange wallet compromise, and a run of smaller DeFi contract exploits.
| Incident | Date | Amount | Root Cause | Recovery |
|---|---|---|---|---|
| Liquid Network | Sept 6, 2026 | ~$320M (4,000 BTC) | Software bug created unbacked L-BTC, redeemed via peg-out | ~85% returned voluntarily |
| Bitget | Sept 24, 2026 | ~$351.6M | Suspected backend wallet compromise, hot/warm wallets drained | Backstopped by a $464M user protection fund |
| rsETH / Kelp DAO Safe wallet | Sept 15, 2026 | Part of a ~$20M weekly total | Compromised Gnosis Safe wallet holding restaking tokens | Unresolved at time of reporting |
| FlamingoFinance | Sept 16, 2026 | $345,900 | Flash-loan price manipulation on older contracts | Flagged by Blockaid, not reversed |
Liquid and Bitget landed within similar dollar ranges, roughly $320 million and $351.6 million, but the mechanisms could not be more different. Bitget’s exposure came from operational security around hot wallets, the kind of failure a protection fund and better key hygiene can address. Liquid’s came from a bug in shared bridge software that had apparently sat in the codebase long enough to be exploitable at scale. The smaller incidents, tracked by outlets including Crypto Times’ weekly roundup and its coverage of the FlamingoFinance exploit, show the same pattern playing out at smaller dollar amounts across DeFi protocols nearly every week this month.
Historical Context: Bitcoin’s Sidechain and Federation Trust Model
Liquid Network has operated since 2018 as one of Bitcoin’s oldest federated sidechains, built specifically so exchanges could settle large BTC transfers faster and more privately than the base chain allows. That federation model has always carried a known trade-off: instead of trusting Bitcoin’s own proof-of-work security directly, users trust a smaller group of federation members to manage the peg honestly and competently.
For most of Liquid’s history, that trade-off looked academic. The September 6 incident made it concrete. Losing 95% of a federation reserve to a software bug, rather than to a coordinated attack on federation members themselves, shows the risk was never really about whether the federation could be bribed or coerced. It was about whether the code connecting Bitcoin’s base layer to a faster settlement layer had been audited as tightly as the trust placed in it demanded.
Market Impact: Did Bitcoin Price or Exchange Confidence Move?
The immediate operational fallout was contained to Liquid itself. Liquid halted new network activity and paused peg operations, but this was a sidechain-level suspension, not a Bitcoin-wide event. Available reporting does not point to a sustained move in BTC’s spot price directly tied to the incident, and no named centralized exchange publicly confirmed halting Bitcoin withdrawals because of it.
The more durable damage is reputational rather than a price chart. Liquid Network markets itself to exchanges and institutions as a faster, more private settlement rail specifically because it is supposed to be safer to use in size than juggling large BTC transfers on the base chain during busy periods. A near-total drain of its reserve, even one mostly reversed, undercuts that pitch regardless of what BTC did in the following 24 hours.
What This Means for Exchanges and Institutions Running on Liquid
Liquid Network has spent years courting exchanges and financial institutions as users of its settlement rails, and the platform’s core sales pitch has always been operational efficiency layered on top of Bitcoin’s underlying security guarantees. That pitch depends on the bridge code being at least as trustworthy as the base chain it sits on top of.
Institutions that route BTC through Liquid for settlement now have a concrete data point showing what happens when that bridge code fails: a near-total reserve drain, a multi-day service suspension, and a lingering unresolved loss that nobody has agreed to cover. Any counterparty doing due diligence on Liquid going forward will reasonably ask for a public post-incident audit, a clearer disclosure of the federation’s current signer configuration, and evidence that the Elements codebase has been independently reviewed since the patch, none of which Blockstream has published as of September 26.
Predictions: Where Bitcoin Sidechain Security Goes From Here
- Expect Blockstream to eventually publish a technical postmortem of the Elements bug, likely alongside a formal bug-bounty adjustment, once the standoff over the remaining 598.5 BTC is resolved one way or another.
- Other federated sidechains and wrapped-BTC projects will face renewed pressure to commission independent audits of their peg-in and peg-out accounting logic, not just their key-management setups.
- Institutions and exchanges that route large BTC volumes through Liquid are likely to diversify settlement rails rather than concentrate exposure in a single federation, at least in the near term.
- The self-described “whitehat” framing will keep showing up in future bridge incidents as attackers learn that returning most of the funds after a public negotiation draws less legal heat than keeping everything.
- Regulatory attention on Bitcoin-adjacent sidechains will likely increase gradually rather than sharply, since no agency has publicly opened an investigation into this specific incident as of late September.
Frequently Asked Questions
What is Liquid Network?
Liquid Network is a Bitcoin sidechain launched by Blockstream in 2018 that lets exchanges and institutions settle BTC transfers faster and with more privacy than the base Bitcoin chain, using a token called L-BTC that is meant to be backed one-for-one by real Bitcoin held in a federation-controlled reserve.
How much was stolen in the Liquid Network hack?
Reports place the initial withdrawal at roughly 4,000 BTC, worth about $320 million at the time, with slight variation between outlets (3,996 to 4,019.4 BTC) depending on which transactions were counted.
Was the money returned?
Most of it. The attacker returned 3,400 BTC, about 85% of the withdrawn total, after Blockstream patched the bug behind the exploit. The remaining 598.5 BTC, worth about $47 million, has not been returned as of September 26, 2026.
Were any private keys stolen?
No. Liquid Network stated that the federation’s signing keys, including SideSwap’s Peg-out Authorization Key, were not compromised. The exploit instead involved a software bug that let the attacker create L-BTC that was not actually backed by real Bitcoin.
What is SideSwap and did it cause the hack?
SideSwap is a Liquid-based settlement platform authorized to process peg-out withdrawals on the network. It was the channel the attacker used to redeem the unbacked L-BTC, but Liquid confirmed the underlying vulnerability sat in the Elements codebase, not in SideSwap’s own systems or authorization key.
Is this related to the Bitget hack?
No. They are separate incidents that happened weeks apart. The Liquid Network hack (September 6) involved a software bug in a Bitcoin sidechain’s bridge accounting. The Bitget hack (September 24) involved a suspected compromise of a centralized exchange’s hot and warm wallets. Both landed in the $320-352 million range, but through entirely different attack paths.
Is L-BTC still safe to hold?
Blockstream has patched the specific bug that enabled this exploit, and Liquid has resumed at least partial operations. Whether L-BTC deserves the same confidence it had before the incident depends on evidence the company has not yet published, including an independent audit of the Elements codebase and a full accounting of the remaining 598.5 BTC.
Has any regulator or law enforcement agency gotten involved?
No named regulator, prosecutor, or law enforcement agency has publicly confirmed an investigation into the Liquid Network incident as of September 26, 2026, based on available reporting.
Related Coverage
- Liquid Network Hack Drains $320M, Sidechain Paused [2026]
- Bitget Confirms $351.6M Hack, 2026's Biggest [2026]
- Bitcoin Quantum Risk: 7M BTC Exposed, BIP-360 Still Just a Proposal [2026]
- 3rd Bitcoin Reorg in a Month: Top 2 Pools Hold 44% [2026]
- Safe Multisig Setup: 12 Steps After the $1.5B Bybit Hack [2026]




