A hacker just told a Bitcoin sidechain to fix its own bug before he'll give the money back
Sometime after 2 PM UTC on September 6, 2026, someone quietly pulled 3,996 BTC out of Blockstream's Liquid Network federation wallet. At the time, that was roughly $320 million. The wallet held about 4,200 BTC before the transaction. Afterward, it held around 207. Ninety-five percent of the reserve backing Liquid's L-BTC token was simply gone, in one transfer, and nobody at Blockstream had seen it coming.
Liquid confirmed the incident on X within hours: Blockstream said it was aware of a security incident and was working to contact the parties on-chain with a signed message, describing the withdrawal as the work of "purported white-hat hackers." The network halted new transactions, disabled its bridge nodes, and asked exchanges to freeze L-BTC deposits and withdrawals while it worked out what had happened. "Liquid wallets will be impacted, and we're sorry for any inconvenience," the post read, which is a strange thing to type after losing nine figures in Bitcoin over a weekend.
What makes this one unusual isn't the size of the loss, though $320 million puts it near the top of this year's hack list. It's what didn't happen. No private keys were stolen. No federation member got phished. Liquid said plainly that the SideSwap Peg-out Authorization Key used to move the funds "was not compromised, nor were any others." SideSwap backed that up, saying the transaction came through as a normal customer order, fully signed, fully authorized, and there was no way for its systems to tell that the L-BTC behind it shouldn't have existed.
That's the actual bug. Someone found a flaw in Elements, the open-source software underneath Liquid, that let them mint L-BTC that no real Bitcoin backed. On-chain analyst mononaut estimated that after the drain, each LBTC in circulation was backed by only about 4.7% of an actual bitcoin. Bitcoin Core contributor Antoine Poinsot, who posts as darosior, noticed something else was off: a Liquid block that Blockstream's own explorer accepted didn't show up on mempool.space at all, a small technical detail that hinted at just how deep into consensus logic the flaw ran. Researchers eventually traced it to how Liquid's confidential transactions validate and cache — an inflation bug, not a stolen-key story.
Then came the part that's turning this into one of the odder standoffs in crypto security history. The person or people holding the funds started sending messages back to Blockstream embedded directly in Bitcoin transactions, some through OP_RETURN, some reportedly PGP-encrypted. One read, more or less: fix the bug first, confirm every node is patched, and only then will the money move back. Blockstream, led by Adam Back, answered in kind. According to reporting from The Block, the company sent its own signed message once the fix was live: "Bridge nodes are patched, safe to return the funds." As of this writing, the Bitcoin was still sitting in the attacker's wallet.

Galaxy Digital's head of research, Alex Thorn, said the hackers had gone a step further and sent Blockstream encrypted technical writeups to help pin down the vulnerability. If that holds up, it's a genuinely strange incentive structure: a $320 million exploit functioning, so far, as an unpaid and fairly aggressive bug bounty. Whether it stays that way is the only question that matters right now, and nobody outside that wallet's owner actually knows the answer. Every large "white-hat" claim in this industry gets tested the moment the deadline to return funds actually arrives.
For everyone else, the immediate damage is more mundane. Liquid's other assets, including USDT, DePix, and various tokenized real-world assets on the network, were reportedly untouched, since the bug was specific to L-BTC's confidential transaction handling rather than the sidechain as a whole. But the federation halted the entire network anyway, and exchanges that route settlement through Liquid have had to pause LBTC activity while patches roll out across the federation's node operators. Liquid has run since 2018 as a federated Bitcoin sidechain overseen by more than 80 exchanges and infrastructure firms, and this is the kind of event that tends to get referenced in every future pitch for or against federated bridge designs.
There's also a broader pattern here that's easy to lose in the specifics of one incident. This exploit alone pushed the week's crypto hack total past $320 million, and other, smaller drains, including a roughly $1.7 million escrow exploit on Notional Finance flagged separately by security monitors, added to that figure. Sidechains and bridges keep being the place where the money leaves, not because the Bitcoin base layer is weak, but because everything built next to it inherits whatever bugs live in its own software.
Blockstream hasn't said when Liquid will fully resume, and it hasn't confirmed the attacker's identity or whether "white hat" is the right label for someone who took nearly the network's entire reserve before agreeing to talk. For now, the story is a bitcoin sidechain waiting on a promise, written in blockchain messages, from the same person who just proved the promise was necessary in the first place.
5% deposit bonus up to 100 gems

a free Gift Case


EGAMERSW - get 11% Deposit Bonus + Bonus Wheel free spin
EXTRA 10% DEPOSIT BONUS + free 2 spins
3 Free Cases + 100% up to 100 Coins on First Deposit
5 Free Cases, Daily FREE & Welcome Bonuses up to 35%

3 free cases and a 5% bonus added to all cash deposits.

+5% to deposit


Comments