Crimes and Fraud News

$320M Bitcoin Hack: What Really Happened to Liquid Network?

Yevheny Serhiienko
8 September 2026 19 min read

On Sept. 6, Liquid Network disclosed that about 4,000 BTC$62,630.00 — about $320 million at that time — had been withdrawn from Liquid Federation wallet.

$320M Bitcoin Hack: What Really Happened to Liquid Network?
Contents

What Happened to Liquid Network?

$320 Million in Bitcoin Was Withdrawn From Liquid’s Federation Wallet

Liquid Network $320 million hack affected the L-BTC issued against Bitcoin sidechain, but not Bitcoin blockchain, because funds are separate.

Liquid initially stated that the withdrawal was made via SideSwap’s Peg-out Authorization Key (PAK) and that the PAK was not compromised. Later reports showed that SideSwap did send 4,000 L-BTC via SideSwap’s Peg-out service and burned it with valid authorization. Liquid Federation subsequently released 3,996 BTC.

Read More: Bitcoin Miner Called $5.68 Cost for 50 BTC a Loss — 16 Years Later, That Reward Is Worth Millions

Nearly 4,000 BTC Were Taken From Around 4,200 BTC in Reserves

Liquid held approximately 4,200 BTC in reserves before the incident. The withdrawal therefore represented about 95% of those reserves, making the Liquid Network 4000 BTC hack particularly significant for a system built around a 1:1 peg between BTC and L-BTC.

These funds were found to be in Liquid’s federation-controlled reserves, which were not dependent upon Bitcoin base-layer consensus and network.

Liquid Network Halted Transactions After the Incident

Liquid’s sidechain was disabled by removing bridge nodes that posted transactions to the sidechain, asking exchanges to suspend L-BTC deposits and withdrawals, and informing the SideSwap project to suspend swaps, peg-ins and peg-outs.

Liquid has stated that other issued assets, including USDT$0.9991, DePix, and real-world assets, were not compromised in the security incident, although users were affected by the outage. 

Key DetailWhat Happened
Bitcoin withdrawn~4,000 BTC
Value at the time~$320 million
Liquid BTC reserves before incident~4,200 BTC
Share of reserves withdrawn~95%
BTC released after L-BTC burn3,996 BTC
Withdrawal routeSideSwap peg-out service
SideSwap PAK compromised?No, according to Liquid and SideSwap
Bitcoin base layer affected?No
Immediate responseLiquid paused transactions; exchanges suspended L-BTC deposits and withdrawals

Was Bitcoin Actually Hacked?

Why the Incident Did Not Compromise Bitcoin’s Base Layer

There is no evidence Bitcoin blockchain, consensus rules or base-layer protocol were compromised. Liquid Network hack 2026 only affected infrastructure on its side, but Bitcoin continued functioning as normal.

SideSwap stated that the L-BTC involved had been created through a bug in Elements software, rather than a vulnerability in Bitcoin itself, and sent through the Liquid peg-out system.

Liquid Network Is a Bitcoin Sidechain, Not the Bitcoin Blockchain

Liquid is a federated Bitcoin sidechain running on Elements, with its own security model and a two-way peg connecting BTC and L-BTC. This distinction is central to what really happened to Liquid Network: the affected system was Liquid, not Bitcoin blockchain.  

L-BTC, Bitcoin’s representation on Liquid, should be 1:1 backed by BTC in the federation’s custody. The incident did not create a problem with respect to Bitcoin’s consensus but rather with the sidechain.

Where the $320 Million Loss Actually Occurred

The incident centered on Liquid’s federation-controlled Bitcoin reserves, and how Liquid Network lost $320 million in Bitcoin was tied to roughly 4,000 BTC being withdrawn through SideSwap’s peg-out mechanism.

According to SideSwap, 4,000 L-BTC was sent to its peg-out and burned with the necessary approvals. The federation then released 3,996 BTC, with SideSwap saying Blockstream had traced the L-BTC sent to the peg-out to a bug in the Elements software.

How the Liquid Network Attack Worked

The Role of Liquid’s Federation Wallet

Liquid Federation wallet holds the mainchain BTC backing L-BTC. As configured by default, these funds are held as an 11-of-15 multisig wallet, where the 15 functionaries each hold a key in a hardware security module. A peg-out can be authorized by 11 of those keys.

In the incident, roughly 4,000 BTC left this reserve through Liquid Network federation wallet. Liquid said the funds moved via SideSwap’s Peg-out Authorization Key, but neither that key nor other federation keys were compromised.  

How BTC Is Converted Into L-BTC

BTC can be converted into L-BTC by a peg-in process whereby the user sends BTC to an address controlled by Liquid Federation and receives an equivalent amount of L-BTC on Liquid after the transaction receives 102 Bitcoin confirmations. According to Blockstream, the only valid way to issue new L-BTC is through a peg-in.

This means L-BTC is always 1:1 backed by BTC secured within Bitcoin mainchain, and this can be verified by anyone running a Liquid node and observing BTC amount secured by the federation.

Why the Attack Involved the Peg-Out Process

In a peg-out, L-BTC is burned on Liquid, and an equivalent BTC amount is released from the federation wallet to the authorized outgoing Bitcoin address. The functionaries verify that the burn occurred and the outgoing Bitcoin address is correct before signing the transaction.

According to SideSwap, the transaction sent 4,000 for L-BTC to its peg-out service. The federation later issued 3,996 BTC after burning the tokens under a valid authorization. Blockstream later discovered the L-BTC was created by a bug in the Elements software, according to a SideSwap statement.

That sequence is central to how 4000 BTC was stolen from Liquid Network: current evidence points to improperly created L-BTC entering an otherwise authorized peg-out path, rather than attackers stealing the federation’s signing keys.  

What SideSwap Had to Do With the $320M Withdrawal

Liquid also relied on SideSwap, whose service controlled the authorized peg-out path for the transaction. Liquid reportedly identified SideSwap’s PAK as the path through which the funds were withdrawn.

SideSwap stated that its systems and authorization key had not been compromised, and that its services correctly processed the 4,000 L-BTC request, burned the tokens, and instructed the federation to release 3,996 BTC. An internal investigation of the incident concluded that the failure was caused by the Elements software. 

StepWhat Happened
1. BTC backingMainchain BTC was held by the Liquid Federation to back L-BTC
2. Normal peg-inBTC deposited into Liquid is represented by an equivalent amount of L-BTC
3. Abnormal L-BTCSideSwap said the 4,000 L-BTC involved originated from an Elements software bug
4. Peg-out request4,000 L-BTC was submitted through SideSwap’s authorized peg-out service
5. L-BTC burnThe L-BTC was burned with valid authorization
6. BTC releaseThe Liquid Federation released 3,996 BTC to the specified Bitcoin address
7. Key findingSideSwap said its PAK and federation keys were not compromised

The Key Was Not Compromised — So How Did the Attack Happen?

What Liquid Says About the Security Incident

Liquid said that the approximate 4,000 BTC withdrawal used SideSwap’s Peg-out Authorization Key (PAK). Liquid denied that the PAK or other federation keys had been compromised. SideSwap also stated its systems and PAK were secure.

According to SideSwap, Blockstream realized the 4,000 L-BTC used for the peg-out had been minted using a bug in Elements — the software infrastructure behind Liquid — so they burned them with valid authorization, and the federation returned 3,996 BTC.

The Difference Between a Stolen Key and a Protocol Vulnerability

​​While the theft of the key would constitute a breach of cryptographic credentials authorizing operations, the reported Liquid Federation wallet hack was performed by authorizing payment in the form of L-BTC created through a bug in the Elements software. The hackers allegedly did not have access to SideSwap’s PAK.

This distinction explains why Liquid Network was hacked without compromised keys; the vulnerabilities discovered so far appear to stem from software validation issues, not federation knowledge or SideSwap credentials.

Read More: Crypto OTC Trading: 5 Best OTC Platforms for Large Crypto Orders

What Remains Unknown About the Exploit

Some technical aspects are not public. While Liquid and SideSwap have claimed that an Elements bug caused the incident, neither has published a complete technical post-mortem explaining exactly how the ill-fated L-BTC was created.

While independent researchers have released analyzes focusing on the rangeproof verification, none should be considered a root-cause report until Blockstream or Liquid produce their own detailed technical report.

Less certain, but established, is that the L-BTC was triggered by an Elements bug, and that the SideSwap systems and PAK were also not compromised.

Who Took the 4,000 BTC?

Why the Attackers Call Themselves “White Hats”

The individuals or organization who withdrew Liquid Network 4000 BTC have never been identified. It is assumed that the “white hats” sought to show a vulnerability in the network and did not intend to permanently misappropriate the coins.

Their activities somewhat corroborated this, as they contacted Blockstream and demanded that the bug be fixed on all affected nodes before handing back most of BTC. However, the “white hat” label is self-proclaimed.

The On-Chain Message Left by the Attackers

The attackers also sent messages via Bitcoin transactions. One of the earliest BTC onchain message said: “we are whitehats. contact us onchain”. Messages to Blockstream were sent via OP_RETURN and PGP-encrypted messages.

The actors stated at Bitcoin block 965,875 that they would return the funds, but first the vulnerability must be fixed and patched on all relevant nodes, which was acknowledged by Blockstream in a PGP-signed message. Blockstream confirmed the patch was applied to all bridge nodes.

Hackers Promise to Return Most of the Bitcoin

The hackers said they would return most of the stolen funds when the exploit was fixed. Blockstream said the bridge nodes have been patched and it is safe to return the funds. 3,400 BTC was returned to the federation at Block 965950.

That leaves 598.5 BTC, or 47.3 million USD at the time of writing, to be returned to the users. This provides the clearest current answer to Liquid Network hack: where did the 4000 BTC go? About 85% went back to the federation, while only about 15% remain.

White-Hat Rescue or $320M Exploit?

Calling the incident a white-hat rescue remains contentious. The actors disclosed the flaw, waited for a patch, and returned 3,400 BTC, but they initially withdrew almost $320 million without authorization and retained nearly 600 BTC.  

While the identity and motive of the perpetrators have not been independently established, Liquid Network hack explained: 4000 BTC and $320M is best described as an exploit carried out by actors who claim to be white hats, rather than a confirmed authorized security operation.

How Much Bitcoin Has Liquid Recovered?

3,400 BTC Returned to the Liquid Network

Liquid has been able to recover about 3,400 BTC, or 85% of the approx. 4,000 BTC that were withdrawn, after Blockstream told the self-described white hats that the bridge nodes had been patched and that it was safe to send Bitcoin back to Liquid.

The return was included in Bitcoin block 965,950 on 7 September and reduced, but did not completely restore, the amount of Liquid Network stolen Bitcoin from the withdrawal.

Around 598 BTC Remains Outstanding

Following the return of the 3,400 BTC, approximately 598.5 BTC remained in the actors’ wallet. When the report was prepared, this Bitcoin was worth approximately $47 M and represented approximately 15% of the funds.

It has been speculated that the remaining sum they did not ask for could have been a bug bounty. There is no public evidence that Liquid or Blockstream let the actors keep the rest of BTC.

Why the Remaining $47 Million Still Matters

Recovering the majority of the stolen Bitcoin greatly reduced the damage, but as of the time of writing, nearly $47 million worth of Liquid Network stolen BTC was unrecovered. The stolen amount was around 95% of the 4,200 BTC Liquid has in reserves; thus, the status of unrecovered coins matters for the L-BTC backing.

The remaining balance also did not address whether additional BTC would be returned to users and under what conditions, while Liquid network remained suspended for security assessment and coordinated restart.

What Happened to L-BTC After the Hack?

Why Liquid’s Bitcoin Reserves Matter for L-BTC

L-BTC is intended to be 1:1 validated by BTC on Bitcoin’s mainchain controlled by Liquid Federation. New L-BTC is normally minted on peg-in at the cost of converting the relative BTC, while redeeming BTC on peg-out destroys an amount of L-BTC and pays the equivalent in BTC from the federation’s multisig.

As a result, the withdrawal of part of this reserve was especially urgent: around 4,000 BTC left a wallet with a balance of around 4,200 BTC. The $70 million hack returned 3,400 BTC, and as such, 598.5 BTC remains outstanding as of press time.

Could L-BTC Lose Its 1:1 Bitcoin Backing?

Liquid, however, has an L-BTC supply pegged 1:1 to BTC locked on-chain, verifiable by running a Liquid node.

Nevertheless, according to SideSwap, Blockstream itself has determined that the L-BTC used in the exploit came from an Elements software bug: instead of appearing on-chain as part of a peg-in, it appeared on-chain out of nowhere, and was burned via an otherwise valid peg-out.

Crypto Exchange API: 5 Best Crypto Exchange APIs in 2026

What the Incident Means for Liquid Users and Exchanges

Liquid, after the accident, disabled the bridge nodes from accepting new transactions, requested exchanges to pause L-BTC deposits and withdrawals, and SideSwap to pause swaps, peg-ins, and peg-outs until the network resumes.

Users were promptly impacted by freezing withdrawals and transfers, but no reports emerged of individual wallets being attacked. Liquid announced that all wallets were being suspended across the network.

Which Liquid-Based Assets Were Affected?

Although Liquid Network hacked was through an incident affecting its sidechain infrastructure, Liquid said other issued assets, including USDT, DePix, and tokenized real-world assets, were not compromised.

These issued assets differ from L-BTC in that Blockstream claims that L-BTC is backed by mainchain Bitcoin, while the backing and redemption of assets depends on their issuers. 

Key IssueStatus
Intended L-BTC backing1:1 with BTC held on Bitcoin’s mainchain
BTC reserves before withdrawal~4,200 BTC
BTC initially withdrawn~4,000 BTC
BTC later returned3,400 BTC
BTC still outstanding~598.5 BTC
L-BTC involved in exploitReportedly originated from an Elements software bug
L-BTC deposits/withdrawalsSuspended following the incident
SideSwap servicesSwaps, peg-ins and peg-outs paused
Other Liquid-issued assetsUSDT, DePix and tokenized RWAs were reported as not compromised

Why the Liquid Network Security Model Is Under Scrutiny

The Risks of a Federated Bitcoin Sidechain

Unlike Bitcoin, Liquid does not use PoW. Blocks are created and finalized by a group of functionaries — the same ones that secure BTC backing of L-BTC. Blocks are finalized through M-of-N multisig. According to Blockstream’s reporting, there are 15 functionaries, and 11 functionary signatures are required to finalize a block and perform federation multisig.

Liquid Network hack creates questions around security assumptions outside of Bitcoin; Liquid is a finite federation of members and infrastructure, unlike Bitcoin, which is a permissionless network of miners and nodes.

Who Controls the Bitcoin Behind Liquid?

BTC sent to the Liquid sidechain is held in the federation’s 11-of-15 multisig wallet. Each of the federation’s 15 functionaries holds one key in separate hardware security modules. The functionaries must collectively verify the L-BTC burn and an acceptable destination before signing a Bitcoin transaction to initiate a peg-out.

Liquid Federation comprises over 80 businesses focused on Bitcoin, though only some of these businesses actually run functionaries that sign blocks securing the two-way peg.

What Happens When Most of the Reserve Is Suddenly Withdrawn?

Liquid’s bridge nodes were taken offline, and the sidechain paused after 4,200 BTC in reserves were reduced by 4,000 BTC — 95% of its reported reserves — on September 6. Exchanges have also paused L-BTC deposits and withdrawals.

The actors were paid back a total of 3,400 BTC once Blockstream announced the bridge nodes had been patched, leaving 598.5 BTC unaccounted for. The attack highlighted the vulnerabilities within the Liquid infrastructure, which could have led to the immediate loss of access to the reserve behind L-BTC.

Liquid’s Security Model vs. Bitcoin’s Decentralized Consensus

Liquid’s consensus model differs from Bitcoin: Liquid relies on a federation of 15 functionaries that take turns proposing the blocks, and a block is considered finalized when 11 out of 15 functionaries have agreed on it. Bitcoin does not strictly depend on it.

This distinction is especially relevant for Liquid Network 320 million Bitcoin hack, which only exposed the sidechain ecosystem and BTC wallet reserves, not the decentralized base-layer consensus.

What Liquid Network Is Doing After the $320M Hack

Why the Network Was Paused

Liquid disabled its bridge nodes after around 4,000 BTC was withdrawn from the federation wallet, blocking new transactions from entering the network. Blockstream and federation members asked exchanges to suspend L-BTC deposit and withdrawal operations during the investigation period of Liquid network.

The pause was a preventative measure until the vulnerability could be fixed, and swaps, peg-ins and peg-outs for SideSwap were also suspended until Liquid resumed service.

Security Fixes and the Path to Restarting Liquid

The white hats informed Blockstream that they would return most of Bitcoin after the bug was fixed and the exploited nodes were patched. Blockstream later published a PGP-signed on-chain message stating that its bridge nodes had been patched and that Bitcoin could be safely returned.

Subsequently, the actors again returned 3,400 BTC. Patching the Blockstream-operated bridge nodes was not sufficient either: the network had to be coordinated to restart.

What Federation Members Need to Resolve

Federation members need to coordinate the safe restoration of network operations, following the Elements vulnerability, and verify the continued operability of other relevant infrastructure components. Liquid previously stated that federation members were working to safely restore network operations while the sidechain remained paused.

Additionally, restoring L-BTC deposits and withdrawals, SideSwap services, and the bridge without the vulnerability that allowed the withdrawal to be reintroduced must be resolved in parallel with the resolution of the vulnerability.

When Could Liquid Network Resume Normal Operations?

While no timeline has been provided as of 8 September for the bridge and the L-BTC services to return to normal, Liquid has not specified this according to media reports, while Blockstream confirmed that their bridge nodes were all patched.

Liquid and the federation have yet to announce a coordinated restart, meaning until then this timeline is speculative. SideSwap has clarified that swaps, peg-ins and peg-outs will remain paused until the network restarts.

What the Liquid Network Hack Means for Bitcoin Investors

Why the Attack Does Not Mean Bitcoin Was Compromised

The incident did not cause the ending of Bitcoin blockchain or consensus: Liquid remains an independent Elements-based Bitcoin sidechain. Blockstream claims sidechains are dependent on Bitcoin, while Bitcoin is not dependent on them.

Liquid Network stolen Bitcoin came from BTC held by the federation to back L-BTC. Current reporting attributes the incident to a bug in Elements software, with no reported compromise of Bitcoin’s base-layer security.  

Read More: CLARITY Act or 2030? Senator Lummis Warns US Crypto Regulation Could Face Years of Delay

What It Reveals About Bitcoin-Based Infrastructure

This episode is particularly relevant for investors because applications built on top of Bitcoin impose security assumptions that Bitcoin does not. For example, Liquid relies on federation functionaries to produce blocks, operate its two-way peg and secure BTC in a multisig wallet.

This means that Bitcoin-linked infrastructure may expose Bitcoin holders to software, bridge, and operational risks beyond what they would be exposed to by simply holding BTC on the mainchain. In this case, Liquid network activity was stopped, and exchanges suspended L-BTC deposits and withdrawals.

The Risks of Using Sidechains and Federated Custody

Liquid’s federation uses an 11-of-15 multisig to secure BTC and perform peg operations. L-BTC users do not have BTC in Bitcoin blockchain, relying instead on the peg and federation infrastructure and the software they are using to be functional.

Liquid Network 4000 BTC incident showed the risk that a large insurance pool like this could be drained. 95% of Liquid’s Bitcoin reserves left the federation wallet. 3,400 BTC was returned.

What Crypto Users Should Watch Next

Top priority issues are safe resumption of Liquid operations, reinstatement of L-BTC deposit and withdrawal functionality, and more information about the Elements vulnerability. SideSwap said swaps, peg-ins and peg-outs would continue to be suspended until the network resumes operations.

Users should also note that 598.5 BTC (worth approximately $47 million at the time of this writing) has not been refunded, and a technical post-mortem will be published explaining the vulnerability and the steps that have been taken to reduce future occurrences. 

Investor QuestionKey Takeaway
Was Bitcoin compromised?No reported breach of Bitcoin’s base layer or consensus
Where did the risk originate?Liquid’s sidechain infrastructure and an reported Elements software bug
Is L-BTC the same as holding BTC?No — L-BTC relies on Liquid’s peg, federation and supporting software
How is Liquid’s BTC secured?Through a federation-operated 11-of-15 multisig
What risks did the incident expose?Software, sidechain, bridge and federated-custody risks
How much BTC was returned?3,400 BTC
What remained outstanding?~598.5 BTC, worth about $47 million at the reported valuation
What should users watch?Network restart, L-BTC services and publication of technical findings

Liquid Network Hack: What We Know and What We Don’t

On Sep. 6, approximately 4,000 BTC (around $320 million) was withdrawn from Liquid’s federation wallet via SideSwap’s peg-out service.

Liquid and SideSwap said that their authorization key was not removed, and SideSwap wrote that Blockstream traced the stolen L-BTC from Liquid Network to an Elements software bug. Bitcoin’s base layer was untouched.

Read More: What Is KYB Verification in Crypto? How Businesses Get Verified by Crypto Platforms

The self-described white hats returned 3,400 BTC after Blockstream patched its bridge nodes, leaving a balance of 598.5 BTC. Liquid halted its network and L-BTC deposits and withdrawals while restoring the network.

The identities and motivations of the attacker have not been disclosed, and a post-mortem analysis of the exploit has not been released by Blockstream.

FAQ

Was Bitcoin hacked?

No. Bitcoin’s blockchain and base-layer consensus were not compromised. It affected Liquid, an independent Bitcoin sidechain built on Elements.

How much Bitcoin was stolen from Liquid Network?

Around 4,000 BTC, worth approximately $320 million at the time, was withdrawn from a federation wallet holding roughly 4,200 BTC.  

How did hackers withdraw 4,000 BTC?

Withdrawal through SideSwap’s peg-out service. SideSwap said that its authorization key was not compromised. SideSwap stated that Blockstream traced the L-BTC used in this transaction to a bug in the Elements software.

Has Liquid recovered the stolen Bitcoin?

Most of it. The actors returned 3,400 BTC after Blockstream said that its bridge nodes had been patched. The actors kept 598.5 BTC.

Is L-BTC still backed 1:1 by Bitcoin?

The L-BTC is supposed to be 1:1 backed by BTC held by Liquid Federation, but L-BTC that was supposedly created was reportedly generated by a bug in Elements. Almost 600 BTC remains outstanding.

Is Liquid Network safe to use now?

Liquid suspended operations after the event. Blockstream claimed its bridge nodes were patched following this. Users are advised to stay tuned to network and service-provider communications before resuming such activities.

Who was behind the Liquid Network hack?

No details of the perpetrators have been revealed, but the actors referred to themselves as “white hats”, spoke with Blockstream on-chain, and sent back most of BTC.

Yevheny Serhiienko

Crypto writer living between common sense and volatility. Convinced that Bitcoin survives everything, Ethereum is always “almost ready,” and a bear market is just the market testing your resilience. Seen…