On September 6, an incident occurred involving the withdrawal of approximately 4,000 BTC, valued at around $320 million, from the Liquid Network's federation wallet, as reported by the project's team.

We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.

What we know so far is that the funds…

— Liquid Network 🌊 (@Liquid_BTC) September 6, 2026

The recipients of the funds identified themselves as "white hat hackers." In a related transaction, they left a message:

"We are 'white hat hackers.' Please contact us through the blockchain."

Later, the hackers expressed their intention to return "most" of the funds once the vulnerability was fixed. Alex Thorn, head of research at Galaxy, noted their correspondence with Blockstream, the technical provider for Liquid.

💧 LIQUID WHITE HATS SAY THEY’LL RETURN ‘MOST’ OF 4000 BTC ONCE LIQUID NETWORK BUG IS PATCHED

the hackers have been conversing with blockstream via OP_RETURN messages and PGP encrypted text

- block 965,822 blockstream address sent 1,000 sat with "Please contact security at… pic.twitter.com/VP8IkOvftl

— Alex Thorn (@intangiblecoins) September 7, 2026

"After confirming the fix, we will return the money," one of the messages quoted by the expert stated.

The "white hat hackers" provided technical details in a message encrypted with Blockstream's public key, but did not disclose the specific amount they intend to return in the public correspondence.

In response to the incident, developers disabled bridge nodes and halted new transactions, while also notifying exchanges to suspend the deposits and withdrawals of L-BTC. According to the Liquid team, other assets on the network—such as USDT, DePix, and several RWA—were not affected by the breach.

How the Hack Occurred

The unknown parties exploited a flaw in Liquid's software to create L-BTC tokens without the necessary backing of Bitcoin reserves. They subsequently exchanged these tokens for Bitcoin via SideSwap, as indicated by the team's statement.

Typically, transfers on Liquid involve a user locking coins in the main network to receive an equivalent amount of L-BTC in the sidechain. When exchanging back, the tokens are burned, and Bitcoin is returned from a reserve wallet managed by federation members.

During the attack, SideSwap received a request to exchange 4,000 L-BTC. The service processed it like any other order, burning the L-BTC and subsequently transferring 3,996 BTC to the recipient's Bitcoin address.

According to SideSwap, Blockstream experts identified a software error in Elements that allowed the creation of L-BTC without adequate Bitcoin backing.

Statement on today's Liquid incident

Today at 14:05 UTC a customer sent 4,000 L-BTC to the SideSwap peg-out service. Our service processed it like any other order: the L-BTC was burned on Liquid with a valid peg-out authorization, and at 14:28 UTC the Liquid Federation paid…

— SideSwap (@side_swap) September 6, 2026

The service accepted these tokens as valid and processed their exchange for Bitcoin from Liquid's reserves.

SideSwap emphasized that the attackers did not gain access to their systems or compromise their withdrawal authorization keys.

Mempool.space researcher OrangeSurf speculated that the incident could have been caused by an error in how cryptographic checks were preserved.

Brief notes on the liquid hack, followed by 3 open questions.

Brief notes:
Liquid has confidential transactions, which make use of range proofs to check transactions are valid without revealing the amounts being sent.

These are computationally expensive (relative to most other…

— orangesurf (@OrangeSurfBTC) September 7, 2026

Liquid conceals transfer amounts. To verify transaction validity without revealing these amounts, nodes check special cryptographic proofs. About seven years ago, developers added caching to remember successful checks and avoid repeated resource-intensive computations.

However, when accessing the cache, not all necessary data was considered; the asset type and spending conditions were missing, according to OrangeSurf. This oversight allowed a new invalid operation to receive a positive result from a previously validated check, which should have been rejected in a complete verification.

Fix Prepared Before the Attack

A change to address the missing parameters in the caching mechanism was already present in the Elements repository as of August 3, with its inclusion dated September 1.

OrangeSurf noted that by the time of the attack, a separate release containing the fix had not been made. He raised questions about why those with the privilege to withdraw Bitcoin continued to operate with the outdated version, and also remarked that it was unclear whether SideSwap had been warned and how critical the vulnerability was considered before the update was released.

The researcher highlighted the lack of additional control during large withdrawals and the contradictory responses from Liquid observers regarding the problematic transaction.

Interestingly, despite using the unpatched software version, the node liquid.network rejected the transaction.

Additionally, OrangeSurf mentioned that the Fable 5 model from Anthropic in GitHub Copilot identified an error in the source code of the proposed change with a simple query.

It is worth noting that at the end of August, the Cronos network associated with Crypto.com suspended its blockchain operations after discovering an exploit in the Tectonic credit protocol.