The Incident and Immediate Response
On Sunday, September 6, 2026, the Liquid Network experienced an unauthorized withdrawal of approximately 4,000 BTC, valued at roughly $320 million, from its federation wallet 12. The Liquid Network, a federated Bitcoin sidechain founded by Blockstream, utilizes a 15-member multisig treasury where 11 signatures are required to authorize transactions 1. Following the incident, the sidechain was paused, and bridge nodes were disabled, though the network continued to produce blocks 12.
Other assets issued on the network, such as USDT, DePix, and tokenized real-world assets, remained unaffected 12. Exchanges were instructed to halt L-BTC deposits and withdrawals, and wallets utilizing the Liquid Network, including Aqua, experienced disruptions 1.
Exploit Mechanism and the Elements Bug
The withdrawal was executed through a peg-out transaction using the Peg-out Authorization Key of SideSwap, a bridge exchange and federation member 1. SideSwap reported that a customer sent 4,000 L-BTC at 14:05 UTC, which were burned under a valid authorization, resulting in the federation paying out 3,996 BTC 23 minutes later 2. SideSwap and the Liquid Network confirmed that no federation keys were compromised 2.
Instead, the exploit leveraged an inflation bug in Elements, the underlying software for the Liquid Network 2. This bug allowed the attacker to generate more than 4,000 unbacked L-BTC on the sidechain, which were then redeemed for actual on-chain bitcoin 12. Because the transaction appeared valid under the consensus rules, the federation's Hardware Security Modules (HSMs) signed the withdrawal 1. Although Blockstream had added a fix for this bug to the underlying software five weeks prior, it had not been fully deployed 2. Before the exploit, the treasury held over 4,200 BTC, leaving just over 200 BTC after the transaction 12.
On-Chain Negotiations and White-Hat Claims
Following the transfer of funds, the attacker moved the assets to an address ending in '6gyqjlte' and broadcasted an on-chain message via the OP_RETURN field stating, 'we are whitehats. contact us on chain.' 1 Former Blockstream security chief Samson Mow estimated the hacker's address balance at approximately 3,998.5 BTC 2. Blockstream responded roughly an hour later with an on-chain message directing the attacker to an email address 12.
The two parties subsequently exchanged PGP-signed messages embedded in Bitcoin transactions 2. The attackers offered to return the majority of the funds under the condition that Blockstream first patch the vulnerability at its latest commit and update all network nodes 2. Blockstream accepted the offer, replying 'Yes, thank you' in a transaction confirmed in the same block as the attacker's condition 2.
Industry Reaction and Security Debates
The incident has sparked debate regarding the definition of 'white-hat' hacking. Ledger Chief Technology Officer Charles Guillemet criticized the attackers' actions, arguing that legitimate white hats do not drain bridges and then solicit contact 2. Guillemet noted that the practice of taking funds and refusing to return them until a vulnerability is patched represents a shift from traditional white-hat standards, comparing the event to the Ronin and Euler exploits 2.
Meanwhile, L-BTC holders face significant risk as the underlying BTC reserves are currently unredeemable 1. Because of the private nature of the Liquid sidechain, the distribution of L-BTC holdings between retail users and corporate entities remains difficult to analyze 1.
What is not yet established
- The exact technical details and mechanism of the Elements inflation bug exploit
- Whether the attackers will fulfill their promise to return the majority of the 4,000 BTC
- The exact breakdown of L-BTC holdings between retail users and corporate entities
- Whether the secondary Signal contact address provided in a subsequent OP_RETURN message is legitimate or spam
Frequently asked questions
Were any other assets on the Liquid Network affected by this security incident?
No. Other assets issued on the Liquid Network, including USDT, DePix, and tokenized real-world assets, were completely unaffected 12.
How did the attackers manage to bypass the 15-member multisig security of the Liquid Federation?
The attackers did not compromise any private keys 2. Instead, they exploited an inflation bug in the Elements software to mint over 4,000 unbacked L-BTC 12. Because the transaction appeared valid under the consensus rules, the federation's HSM security servers automatically signed the withdrawal 1.
What condition did the attackers set before returning the funds?
The attackers demanded that Blockstream first patch the vulnerability at its latest commit and update every node on the network before they would return the majority of the funds 2.
Sources
- Bitcoin Magazine — Alleged White-Hat Hackers Withdraw 4,000 bitcoin from Blockstream’s Liquid Network Federation Reserves (2026-09-06) https://bitcoinmagazine.com/news/alleged-white-hat-hackers-withdraw-4000-bitcoin-from-blockstreams-liquid-network-federation-reserves
- Decrypt — 'Purported White-Hat Hackers' Withdraw $320M in Bitcoin From Liquid (2026-09-07) https://decrypt.co/377528/purported-white-hat-hackers-withdraw-320m-in-bitcoin-from-liquid
This brief is for information and education. It is not financial advice or a recommendation to buy or sell.