Liquid Network, one of the best-known sidechains built on top of Bitcoin, was forced to disable its bridge nodes and pause new transactions after unidentified actors withdrew roughly 4,000 BTC — worth about $320 million — from the network’s federation wallet. The withdrawal, which took place around Sunday, Sept. 6-7, 2026, drained nearly 95% of the wallet’s total balance and triggered exchanges to halt deposits and withdrawals of L-BTC, the Bitcoin-pegged token that Liquid issues.
The scale of the incident, and the odd manner in which it unfolded, sets it apart from a typical hack. The actors behind the withdrawal have not been identified, but they have communicated through signed onchain messages, describing themselves as white-hat hackers and saying they intend to return most of the funds once a vulnerability in the underlying Elements software is patched across the network. As of the report, no funds had been returned.
What Liquid Is and Why the Federation Wallet Matters
Liquid is a sidechain built on Bitcoin and maintained largely by Blockstream, designed to let users move Bitcoin faster and with more privacy than the base layer allows, while also hosting other assets such as USDT, the Brazilian stablecoin DePix, and various real-world-asset tokens. The system works by locking real BTC in a federation wallet — a multi-signature vault controlled by a group of functionaries — and issuing a corresponding amount of L-BTC on the sidechain. That peg is the backbone of trust in Liquid: every L-BTC in circulation is supposed to be backed one-to-one by actual Bitcoin sitting in that wallet.
According to the facts disclosed so far, the wallet held approximately 4,200 BTC before the incident, and about 3,998.5 BTC remained unmoved by 9:12 p.m. Pacific time, per a timeline published by Samson Mow, the former Blockstream chief strategy officer who now runs Jan3. Mow’s account shows the exchange between the actors and Blockstream beginning around 11:30 a.m. Pacific time, with Blockstream responding roughly an hour later. SideSwap, a platform built on Liquid, said the disputed transaction used its Peg-out Authorization Key through what looked like a legitimate customer order, but denied that its own systems had been compromised — pointing instead to a bug in Elements, the open-source software that underpins the entire Liquid stack.
What This Means for Bitcoin’s Sidechain Ecosystem
Whatever the final resolution, the episode is a blunt reminder that a Bitcoin sidechain is only as trustworthy as the software and governance controlling its bridge. Liquid’s federation model was built to distribute trust among a set of known functionaries rather than a single custodian, yet a software-level vulnerability in Elements was apparently enough to let outside actors move nearly the entire reserve without needing to break the federation’s multisig consensus in the conventional sense. That distinction matters: this was not a private-key theft in the mold of an exchange hack, but a protocol-level exploit that let a valid-looking transaction drain the peg.
The fact that other assets on Liquid — including USDT, DePix, and tokenized real-world assets — were reportedly unaffected suggests the vulnerability was specific to how BTC moves through the peg-out mechanism, not a wholesale compromise of the sidechain’s ledger. Still, for any user holding L-BTC, the pause on deposits and withdrawals is a direct hit to liquidity and a stark illustration of the risks that come with wrapping Bitcoin into a secondary layer. It echoes a broader pattern of custody and infrastructure failures that has shadowed the industry all year, from exchange-side incidents to hardware wallet exploits — including the Coldcard wallet hack that has rattled confidence in Bitcoin self-custody and the case of a solo miner who profited from a related Coldcard exploit. Each incident, regardless of root cause, chips away at the assumption that Bitcoin-adjacent infrastructure is inherently as secure as the base chain itself.
What Comes Next
The immediate question is whether the actors follow through on their stated intention to return most of the withdrawn BTC once the Elements vulnerability is patched. Onchain messages are not binding commitments, and until funds actually move back to the federation wallet, exchanges and users have reason to treat the promise with caution. Readers should watch for:
- An official technical postmortem from Blockstream detailing the exact nature of the Elements bug and the patch timeline.
- Whether exchanges that halted L-BTC deposits and withdrawals resume normal service, and under what conditions.
- Any onchain movement of the withdrawn 4,000 BTC, which would indicate whether the actors’ stated intentions are genuine.
- How the incident affects confidence in other federated or bridge-based Bitcoin layers, a topic closely tied to broader questions about custody discussed in explainers on how exchanges handle order books and custody.
For now, Liquid Network remains in a defensive posture, with bridge nodes disabled and transactions paused as Blockstream and the wider community assess the damage. The episode adds to a year already marked by scrutiny of crypto infrastructure security, and it will likely renew debate over whether federated sidechains can offer the security guarantees users expect from anything claiming to represent Bitcoin one-to-one.
Source: Cointelegraph
This content is for informational purposes only and does not constitute financial or investment advice.




Create a free account to comment and earn rewards.
Create account Log in