Mon. Sep 7th, 2026

Liquid Network Pauses After $320 Million Bitcoin Drain

ByShane Neagle

September 7, 2026 #Liquid Network
Crypto Hack

Liquid Network has paused activity after nearly 4,000 bitcoin worth about $320 million was withdrawn from the federation wallet backing its L-BTC token, in an extraordinary security incident involving infrastructure used by cryptocurrency exchanges and institutional traders.

The incident unfolded on Sept. 6 when approximately 4,000 L-BTC was sent through SideSwap’s peg-out service. The Liquid Federation subsequently released roughly 3,996 BTC from the Bitcoin wallet backing the sidechain.

The transaction removed around 95% of the approximately 4,200 BTC held in the federation wallet before the incident.

The unidentified party behind the withdrawal later used Bitcoin’s OP_RETURN field to send a message claiming, “we are whitehats” and asking Blockstream to communicate onchain.

That description remains unverified. However, subsequent messages between the two sides indicate that the party controlling the bitcoin has offered to return most of the funds once Blockstream demonstrates that the vulnerability responsible for the incident has been fixed across the network.

Blockstream later responded through a cryptographically signed message saying its bridge nodes had been patched and that it was safe to return the funds.

At the latest check, the bitcoin had not yet been returned.

The incident forced Liquid to disable its bridge nodes, effectively preventing new user transactions from entering the sidechain. Exchanges were instructed to suspend L-BTC deposits and withdrawals while the federation investigates and patches the problem.

Bitcoin itself was not compromised. The incident affected Liquid, a separate Bitcoin sidechain developed by Blockstream that allows users and financial institutions to move BTC through a faster settlement network.

L-BTC is designed to maintain a one-to-one relationship with bitcoin. Users lock BTC in the Liquid Federation’s Bitcoin wallet and receive an equivalent amount of L-BTC on Liquid. When L-BTC is redeemed, the tokens are destroyed and the federation releases the corresponding BTC.

That relationship makes the latest incident particularly serious.

Onchain analysis indicates that the party behind the exploit was able to create approximately 4,000 L-BTC that was not backed by an equivalent amount of bitcoin before sending it to SideSwap for redemption.

SideSwap then processed the tokens through its normal peg-out service, after which the federation released the real BTC.

SideSwap said its Peg-out Authorization Key was not compromised. Liquid similarly said there was no evidence that other federation keys had been breached.

Instead, the incident has been linked to a vulnerability in Elements, the open-source software underlying Liquid.

That distinction is significant because Liquid’s Bitcoin reserves are protected by an 11-of-15 multisignature structure.

Fifteen federation functionaries operate specialized systems holding keys used to manage the Bitcoin peg, and 11 signatures are required to authorize movements from the federation wallet.

The security model is intended to prevent a single compromised operator or key from moving the underlying bitcoin.

In this case, however, the functionaries appear to have signed what they believed was a valid redemption. The problem was not that an attacker obtained enough federation keys. The system apparently accepted L-BTC that should never have existed and then processed the resulting peg-out through an authorized route.

Bitquery reconstructed the main transaction and found that the federation released 3,996.018 BTC in a single peg-out. SideSwap subsequently forwarded almost 3,996 BTC to the recipient.

The federation wallet was left with roughly 200 BTC after further transactions, compared with more than 4,200 BTC before the incident.

The exchange angle is particularly important because Liquid was built partly as a settlement network for trading venues.

Liquid’s current federation ecosystem lists exchanges including Bitfinex, BitMEX, BTSE, Bitbank, BtcTurk, Coincheck and several others.

Bitfinex, for example, has supported L-BTC deposits and withdrawals and provides a conversion mechanism allowing customers to move between BTC and L-BTC.

Liquid’s documentation specifically markets the network to exchanges as a way to achieve faster bitcoin deposits, withdrawals and inter-platform settlement.

There is currently no evidence that customer balances at those exchanges were stolen as part of the incident, and Liquid said assets issued separately on the network, including USDT and tokenized real-world assets, were not directly affected.

However, customers relying on L-BTC deposits, withdrawals or conversions may face disruptions while the bridge remains paused.

The immediate outcome now depends heavily on whether the self-described white hats return the bitcoin.

Until that happens, the incident represents a roughly $320 million shortfall in the Bitcoin reserves that normally underpin L-BTC, even though the actors controlling the funds say the withdrawal was intended to expose and force the repair of a vulnerability.

The Multisig Worked, and That Is What Makes This Worse

The most troubling part of the Liquid incident is that the famous 11-of-15 multisig appears to have done exactly what it was supposed to do.

The keys were apparently not stolen.

Eleven functionaries signed the transaction.

The bitcoin was released through an authorized peg-out mechanism.

And nearly $320 million still left the wallet.

That exposes an uncomfortable weakness in the way bridge security is often discussed.

A large multisig sounds reassuring because an attacker cannot simply steal one private key and empty the reserves. But the keys only protect the final authorization step. They are useless if the software feeding information into that process incorrectly decides that a fraudulent withdrawal is legitimate.

In simple terms, the guards were still standing at the vault door. The system handed them paperwork saying the withdrawal was valid, and they opened the door.

That is arguably more important than another compromised hot wallet.

Liquid is not an obscure DeFi protocol built several months ago. It launched in 2018, is closely associated with Blockstream and has been marketed toward exchanges and institutions precisely because its federation structure was supposed to offer a controlled alternative to less trusted bridges.

The incident therefore becomes a test of the entire L-BTC model.

Every genuine L-BTC is supposed to represent real bitcoin held by the federation. If unbacked L-BTC can be manufactured and redeemed for actual BTC, the fundamental accounting relationship breaks even if every private key remains secure.

The fact that the attacker has apparently kept the bitcoin stationary and opened communication with Blockstream greatly improves the potential outcome.

But “white hat” should remain in quotation marks until the money comes back.

Moving $320 million without permission and then offering to return most of it after conditions are met is not the same as conducting an ordinary responsible security disclosure. The amount that might be retained also matters. Even 1% of $320 million would represent a $3.2 million payment.

The exchange exposure makes the next phase especially important.

Bitfinex and other platforms have integrated Liquid because L-BTC provides faster movement of bitcoin between venues. Those integrations create convenience when the peg works normally, but they also turn a network-level failure into an operational problem for exchanges.

Customers do not necessarily care whether the vulnerability occurred inside SideSwap, Elements, Liquid or the federation infrastructure. If their L-BTC withdrawal is unavailable, they experience it as an exchange problem.

That means trading venues supporting Liquid will want much more than confirmation that one patch has been installed.

They will need confidence that the mechanism allowing unbacked L-BTC to reach an authorized peg-out cannot be repeated through another variation of the same bug.

The good news is that this incident may end without a permanent $320 million loss.

The bad news is that the money does not need to disappear permanently for the security lesson to matter.

Liquid has just demonstrated that a system can possess geographically distributed hardware keys, an 11-of-15 signing threshold and known institutional operators — and still authorize almost its entire Bitcoin reserve to leave because the software convinced those protections that the transaction was legitimate.

That is the vulnerability Blockstream now has to explain.

ByShane Neagle

Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms. He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments. Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

Leave a Reply

Your email address will not be published. Required fields are marked *