Liquid Network halts after 4,000 BTC leaves federation wallet through an Elements bug
Global — September 7, 2026
Liquid Network halts after 4,000 BTC leaves the federation wallet through an Elements bug
No key was compromised and no hardware was breached. The federation paid out almost its entire bitcoin reserve because its own software told it the request was valid.
Roughly 4,000 BTC, worth about $320 million at the time, was withdrawn from the Liquid Network’s federation wallet on 6 September, leaving the Bitcoin sidechain paused and exchanges unable to process L-BTC deposits or withdrawals. The parties responsible left a message on the Bitcoin blockchain identifying themselves as white hats and have since agreed to return most of the funds, on the condition that the underlying bug is fixed first.
What makes this incident different from most nine-figure crypto losses is that nothing was stolen in the conventional sense. No private key was compromised and no hardware was breached. According to Blockstream, which builds and maintains the technology behind Liquid, the withdrawal was made possible by a bug in Elements, the open-source software the sidechain runs on. That bug allowed L-BTC to be created without corresponding bitcoin behind it. The federation then honoured what appeared, from its own software’s point of view, to be a legitimate request to redeem that L-BTC for real bitcoin.
The MechanismHow the withdrawal happened
The peg-out request was submitted at 14:05 UTC through SideSwap’s peg-out service, and the federation paid out 3,996 BTC roughly 23 minutes later, according to reporting by Decrypt. The federation wallet held approximately 4,200 BTC before the incident and was left with around 200 BTC afterwards, close to 95% of its bitcoin reserves gone in under half an hour.
Liquid stated that the peg-out authorization key used in the transaction had not been compromised, nor had any others. That distinction matters. A key compromise would point at custody and operational security. A node-level software bug points at the code every federation member runs, which is a different category of problem and one that patching, rather than key rotation, is meant to solve.
Decrypt reported that a fix for the bug had already been implemented five weeks before the incident. If accurate, that detail moves the story from a zero-day to a deployment failure, and it is the part of this incident most worth watching as Blockstream publishes more detail.
The Back-ChannelA negotiation, not a recovery
The parties behind the withdrawal embedded a message in a Bitcoin transaction, and Blockstream responded with an email address. The two sides then exchanged PGP-signed messages written into Bitcoin transactions, an unusually public back-channel for an incident of this size.
We are whitehats. Contact us on chain.
— Message embedded in a Bitcoin transaction by the parties behind the withdrawal
At block 965,875 the attackers told Blockstream to fix the bug first and to ensure that “every node is patched” before any funds would move. Blockstream later sent a PGP-signed on-chain message reading “Bridge nodes are patched, safe to return the funds,” which The Block verified against Blockstream’s published security key. As of 7 September, the bitcoin remained in the attackers’ wallet. The offer is to return “most of” the funds, with no figure given for what they intend to keep.
Liquid Network said on X that “Liquid wallets will be impacted, and we’re sorry for any inconvenience,” adding that federation members were “actively working on resolving this so we can restore normal network activity.”
Blast RadiusWhat was not affected
The Bitcoin main chain was not involved and continued operating normally. Other assets issued on Liquid, including USDT, DePix and tokenized real-world assets, were untouched. The disruption is specific to L-BTC, the wrapped bitcoin that gives the sidechain its purpose, and to the peg mechanism that connects it to Bitcoin.
That containment is worth noting, but it also underlines where the risk in this design sits. Liquid’s value proposition to exchanges and traders is faster, more private bitcoin settlement. The asset that delivers that proposition is exactly the one that turned out to be mintable from a software bug.
| Event | Value |
|---|---|
| Peg-out request submitted via SideSwap | 14:05 UTC |
| Bitcoin paid out by the federation | 3,996 BTC |
| Federation wallet balance before | ~4,200 BTC |
| Federation wallet balance after | ~200 BTC |
| Bug fix reportedly implemented before the incident | 5 weeks |
| On-chain block carrying the attackers’ terms | 965,875 |
The Trade-OffThe uncomfortable question about federated sidechains
Liquid is secured by a federation of functionaries drawn from exchanges and financial firms rather than by proof of work. That is a deliberate trade, accepted in exchange for speed and confidentiality, and it has always meant trusting a defined set of operators rather than trusting math alone.
This incident tests a narrower version of that trust than the one usually debated. The federation behaved correctly. It processed a request that its own software told it was valid. The failure was upstream of the trust model, in the code that defines what “valid” means, and the recovery has depended not on cryptography or on the federation’s authority but on negotiating with the people holding the coins.
A peg is only as sound as the software validating it, and a coordinated node upgrade across independent operators is itself a piece of security infrastructure.
— Crypto Coin Show
For institutions evaluating sidechains, wrapped assets and bridges, the relevant lesson is not that federated designs are unsafe. It is that the surface area of trust is wider than the trust model advertises.
NextWhat to watch
Three things will determine how this is remembered. Whether the funds are returned in full or with a bounty deducted. Whether Blockstream publishes a full post-mortem naming the bug, its origin and the timeline of the fix. And whether exchanges that route settlement through Liquid change how they treat L-BTC in the meantime.
Until peg-ins, peg-outs and swaps resume, L-BTC holders cannot move between Liquid and Bitcoin. A network that markets itself on settlement speed is currently the slowest route between two points it was built to connect.
This story was first reported by The Block, with additional reporting from CoinDesk and Decrypt.
Liquid Network is a Bitcoin sidechain built on the open-source Elements platform and operated by a federation of exchanges, brokers and financial institutions. It is designed for faster, confidential settlement of bitcoin and issued assets between its members, with L-BTC serving as the network’s bitcoin-backed representation. Liquid is developed and maintained by Blockstream.
