cryptocurrency widget, price, heatmap
arrow
Burger icon
cryptocurrency widget, price, heatmap
News/Liquid Network Paused After 4,000 BTC Withdrawal Tied to Elements Bug

Liquid Network Paused After 4,000 BTC Withdrawal Tied to Elements Bug

Van Thanh Le

Van Thanh Le

PublishedSep 7 2026

UpdatedSep 7 2026

1 hour ago4 minutes read
Robot inspects drained vault at Liquid Network facility after exploit

Blockstream tells self-described white-hat attacker bridge nodes are patched and funds can be returned

TL;DR

  • Liquid Network disclosed on Sept. 6, 2026, that purported white-hat hackers withdrew roughly 4,000 BTC worth about $320 million from its federation wallet.
  • SideSwap said the affected L-BTC was created through a bug in Elements software, while its systems and Peg-out Authorization Key were not compromised.
  • The attacker offered to return most of the bitcoin after the vulnerability was fixed, and Blockstream later said the patched bridge nodes made it safe to return the funds.

Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. 

Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!


Liquid Network paused after roughly 4,000 BTC worth about $320 million was withdrawn from its federation wallet, with SideSwap saying the L-BTC used in the withdrawal had been created through a bug in Elements software rather than through a compromised Peg-out Authorization Key. The self-described white-hat attacker later offered to return most of the bitcoin after the vulnerability was fixed, while Blockstream said the affected bridge nodes had been patched.

Liquid disclosed the security incident on Sept. 6, 2026, saying the actors were purported white-hat hackers and that Blockstream was trying to contact them onchain using a signed message. Liquid said: “We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message…”

tweet-2096696272447218108.webp

Liquid is a Bitcoin sidechain that allows users to move BTC onto a separate network for faster transfers while the original bitcoin is held in a shared federation wallet. The federation reserve provides the bitcoin backing for L-BTC circulating on Liquid.

Liquid said the withdrawal passed through the SideSwap Peg-out Authorization Key, or PAK, but stressed that the authorization key itself had not been compromised. “What we know so far is that the funds were withdrawn via the SideSwap PAK (Peg-out Authorization Key), but that key was not compromised, nor were any others,” Liquid said.

SideSwap Says Valid Peg-Out Followed Creation of L-BTC Through Software Bug

SideSwap provided a more detailed account of the transaction flow, saying 4,000 L-BTC was sent to its peg-out service. The service burned those tokens using a valid peg-out authorization, after which the Liquid Federation paid 3,996 BTC to the customer’s Bitcoin address.

SideSwap said Blockstream later established that the L-BTC had been created through a bug in Elements software. SideSwap said neither its systems nor its peg-out authorization key had been compromised, distinguishing the software vulnerability from a theft of authorization credentials.

Other assets on Liquid, including USDT, DePix and RWAs, were unaffected, according to Liquid. Liquid wallets were affected, while Bitcoin transactions continued to function normally on related services as the federation worked to restore operations.

Liquid temporarily disabled bridge nodes, effectively pausing the sidechain. Exchanges were notified and were pausing or had already paused L-BTC deposits and withdrawals. SideSwap separately said swaps, peg-ins and peg-outs would remain paused until the network resumed.

Attacker Conditions Return on Bug Fix

Blockstream first contacted the attacker through a Bitcoin transaction at block 965,822, asking the party to contact its security team. The purported white-hat hacker communicated with Blockstream using Bitcoin OP_RETURN messages and PGP-encrypted text.

At block 965,875, the attacker told Blockstream to “fix the bug first” and ensure “every node is patched” before sending the funds back. An earlier message from the attacker offered to return “most” of the bitcoin to the federation address.

The attacker later said the party would return “the money back safely” once the bug that enabled the withdrawal had been fixed. Blockstream replied, “Yes, thank you.”

Blockstream subsequently sent a PGP-signed onchain message stating, “Bridge nodes are patched, safe to return the funds.” The signature was reported to verify against the security key published by Blockstream.

The bitcoin had not yet been returned at the time of the Sept. 7 reporting snapshot, with the withdrawn funds still held in the attacker-controlled wallet despite the stated return offer.

A separate unsigned onchain message offered a 98 BTC bounty, but its sender could not be authenticated and was reported as potentially being an impersonator. The bounty therefore was not established as an official Blockstream offer.

Blockstream had sent authenticated onchain communications to the attacker, but there had been no official public statement from Blockstream on the broader incident at that stage.

L-BTC Backing Falls Far Below Intended Level

The withdrawal also sharply reduced the bitcoin held against L-BTC, which is intended to be backed one-for-one by bitcoin in the federation reserve.

A Sept. 7 snapshot showed 197 BTC remaining in the federation wallet, leaving L-BTC backed by 4.7% of the bitcoin required to maintain its intended backing. Users continued to hold L-BTC while normal peg-out functionality remained unavailable during the network pause.

That reserve position made the eventual resumption of peg-outs a material unresolved issue. The outstanding question identified at the time was what L-BTC would be worth when withdrawals resumed if sufficient bitcoin had not yet been returned, as well as who would absorb any resulting shortfall.

The attacker’s language also left open the possibility that not all withdrawn bitcoin would be sent back because the earlier message promised to return “most,” rather than explicitly all, of the funds. The separate unsigned bounty message did not establish how much, if anything, the attacker intended to retain.

By Sept. 7, the incident had moved into remediation: the network remained paused, bridge nodes had been disabled and then patched, exchanges had suspended L-BTC movement, and SideSwap had stopped swaps and both directions of peg activity while waiting for Liquid to resume.

FAQ

What caused the Liquid Network incident?

SideSwap said Blockstream traced the affected L-BTC to a bug in Elements software.

Was SideSwap’s Peg-out Authorization Key compromised?

No. Liquid and SideSwap said the key remained uncompromised.

Why was Liquid Network paused?

Bridge nodes were disabled while the vulnerability was addressed and normal operations were suspended.

Did the attacker agree to return the bitcoin?

The attacker offered to return most of it after the bug was fixed.

This article has been refined and enhanced by ChatGPT.

cryptocurrency widget, price, heatmap
v 5.14.18
© 2017 - 2026 COIN360.com. All Rights Reserved.