Summary
- Liquid halted its bridge nodes on Sunday following the withdrawal of approximately 4,000 BTC from its federation wallet supporting L-BTC.
- The withdrawal utilized SideSwap's peg-out key, which Liquid claims was not compromised, attributing the incident instead to a bug in Elements.
- The wallet currently contains about 200 BTC, a mere 5% of its prior balance.
Blockstream's Liquid sidechain was paused on Sunday after roughly 4,000 BTC, valued at around $320 million, was withdrawn from the federation wallet that supports all L-BTC in circulation.
According to SideSwap, a federation member providing peg-out services, a customer sent 4,000 L-BTC at 14:05 UTC, which was subsequently burned under legitimate authorization. Just 23 minutes later, the federation dispensed 3,996 BTC.
We are aware of a security incident involving @Liquid_BTC. Alleged white-hat hackers have withdrawn approximately 4,000 BTC (around $320 million) from the Liquid Federation wallet. The @Blockstream team is attempting to reach out to them on-chain with a signed message.
What we know so far is that the funds…
— Liquid Network 🌊 (@Liquid_BTC) September 6, 2026
Liquid stated that the funds were transferred via SideSwap's Peg-out Authorization Key, asserting that this key and other federation keys remained secure. SideSwap confirmed that its systems were not breached and indicated a bug in the Elements software as the cause.
Blockstream has yet to provide details on the bug, although a fix was integrated into Liquid's foundational software five weeks prior. No funds were forcibly taken from the wallet; it appears someone generated L-BTC without backing Bitcoin and then exchanged it through a seemingly normal peg-out process.
Before the incident, the wallet held about 4,200 BTC, and now it has around 200 BTC remaining.
Engaging with the Alleged White Hats
The alleged hackers left an on-chain message stating, "we are whitehats. contact us on chain." Blockstream responded an hour later with an email address, and the two parties have since exchanged PGP-signed messages within Bitcoin transactions.
The hackers offered to return most of the stolen coins but attached a condition: the bug must be fixed first to mitigate ongoing risks, and every node must be updated. Blockstream's reply, "Yes, thank you," acknowledged the offer and was confirmed in the same block as the condition.
Myriad: Predict Bitcoin's next price movement.Charles Guillemet, chief technology officer at Ledger, initially remarked that "White hats don't drain a bridge and then seek an 'on-chain' contact," comparing it to the Ronin and Euler hacks. He later suggested that the hackers might be individuals who "intensively played with recent LLMs," but later hardened his stance after the condition was presented, stating that white-hat practices have evolved to where they now steal funds and refuse to return them until vulnerabilities are addressed.
Former Blockstream security head Samson Mow, who detailed a timeline of the events, estimates the hackers' address holds approximately 3,998.5 BTC.
Other assets within Liquid, such as USDT, DePix, and tokenized real-world assets, remained unaffected, and Bitcoin's own network was not compromised.
