The Liquid Network recovered 3,400 BTC on September 7, one day after approximately 4,000 BTC, then valued at $320 million, was drained from the Liquid Federation wallet on the Bitcoin blockchain. The returned amount accounts for about 85% of the transferred Bitcoin, but nearly 598.5 BTC remains at an address controlled by the entity that executed the transaction.
Recovering the majority of the Bitcoin significantly reduces the shortfall in the federation’s reserves, but it does not fully resolve the incident. Liquid has not yet confirmed when operations will resume or released a technical postmortem explaining the root cause, leaving unanswered questions regarding the missing funds and the security controls protecting the Bitcoin backing L-BTC.
We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.
What we know so far is that the funds…
— Liquid Network 🌊 (@Liquid_BTC) September 6, 2026
3,400 BTC Returned, 598.5 Outstanding
The incident began on September 6 when an unknown party drained roughly 4,000 BTC from the Liquid Federation wallet representing nearly 95% of its pre-incident balance of around 4,200 BTC. Liquid valued the transferred assets at approximately $320 million and described the event as a security incident. The actor later claimed to be a white-hat hacker.
A day later, the return transaction was confirmed at Bitcoin block 965,950 at around 16:09 UTC. On-chain data shows that exactly 3,400 BTC was transferred back to the federation address, while approximately 598.4996 BTC returned to an address controlled by the entity behind the withdrawal.
With Bitcoin trading near $79,000 at the time, the returned portion was worth roughly $268 million, representing 85% of the drained BTC. The remaining amount is valued at approximately $47 million. The address disclosed by Liquid currently holds around 3,597.47 BTC, compared to roughly 197 BTC immediately following the incident.
Liquid and Blockstream have not indicated whether the remaining Bitcoin will be returned. Neither party has confirmed whether the unreturned funds represent a bug bounty, an agreed-upon fee, or assets retained unilaterally by the actor.
The SideSwap Peg-Out
Liquid is a sidechain designed to facilitate value transfers between its network and the Bitcoin blockchain. BTC is locked in the federation wallet to mint L-BTC on Liquid at a 1:1 ratio. Conversely, the peg-out process burns L-BTC before the federation releases a corresponding amount of BTC to the recipient.
Direct peg-out transactions require a Peg-out Authorization Key (PAK) to verify that the destination Bitcoin address is authorized. Users without a dedicated PAK can execute withdrawals through third-party service providers such as SideSwap.
In the transaction involved in the incident, 4,000 L-BTC was submitted to SideSwap’s peg-out service at 14:05 UTC. These tokens were burned using a valid authorization. Roughly 23 minutes later, the Liquid Federation transferred 3,996 BTC to the customer’s Bitcoin address.
SideSwap stated that the L-BTC used in the withdrawal stemmed from a bug in the underlying Elements software rather than issues within its own platform. The PAK used to process the transaction was not compromised, and the tokens could not be distinguished from standard L-BTC at the time of execution. Blockstream has not yet published its own technical report fully explaining the vulnerability.
Statement on today’s Liquid incident
Today at 14:05 UTC a customer sent 4,000 L-BTC to the SideSwap peg-out service. Our service processed it like any other order: the L-BTC was burned on Liquid with a valid peg-out authorisation, and at 14:28 UTC the Liquid Federation paid…
— SideSwap (@side_swap) September 6, 2026
Negotiations Move On-Chain
Following the drain, the entity controlling the recipient BTC address embedded the message “we are whitehats. contact us on chain” into the OP_RETURN field of a Bitcoin transaction. Blockstream responded with a 1,000-satoshi transaction containing its security team’s email address, initiating a communication chain publicly recorded on the blockchain.
Subsequent messages utilized digital signatures and PGP encryption to authenticate senders and exchange confidential details. In a message at block 965,875, the actor requested that Blockstream fix the vulnerability and update its nodes prior to the return of the assets.
Blockstream later sent a signed message confirming that the bridge nodes had been patched and that Bitcoin could safely be transferred back. The transaction returning 3,400 BTC to the federation address was confirmed at block 965,950 following this announcement.
Liquid Prepares to Restart
Upon detecting the incident, Liquid disabled its bridge nodes, preventing new transactions from being submitted to the network. Exchanges were instructed to suspend L-BTC deposits and withdrawals. SideSwap also halted swaps, peg-ins, and peg-outs pending Liquid’s operational resumption.
Liquid stated that other issued assets, including USDT, DePix, and tokenized real-world assets, were not directly impacted by the incident. However, the suspension of network processing continues to temporarily disrupt transfer capabilities for these assets. SideSwap noted that funds held in non-custodial wallets remain under user control and that completed peg-outs on the Bitcoin blockchain cannot be reversed.
On September 8, Blockstream, Liquid’s primary technology provider, stated that updated software had been deployed and that federation members were preparing a coordinated network restart.
As of September 9, Liquid has yet to confirm that network activity has fully resumed. Blockstream’s public explorer continues to display the latest Liquid block at height 4,051,232, with a timestamp of 04:49 UTC on September 7. Consequently, L-BTC trading, deposit, and withdrawal services should still be described as suspended until official confirmation is provided.
Liquid Network explorer. Source: Blockstream
No Postmortem Yet
SideSwap noted that Blockstream identified the L-BTC in the peg-out request as having been generated via a bug in Elements, Liquid’s underlying software framework. However, neither Blockstream nor Liquid has released a technical report explaining how the bug was exploited or why the minting of the affected L-BTC was validated as legitimate asset data by the network.
Public information has also not yet identified the specific Elements software version affected, the full scope of the vulnerability, or the validation checks that failed to block the transaction. Blockstream has only confirmed the deployment of updated software without disclosing details of the patch or additional safeguards added to the peg-out pipeline.
As of September 9, no post-incident reconciliation has been published comparing total circulating L-BTC against the BTC held by the federation. This reconciliation is necessary to verify the 1:1 backing status of L-BTC after the return of the majority of the Bitcoin, while a portion remains outside the federation wallet.