Security

The Liquid Network attack: about 4,000 bitcoin and the risk of bridges

A flaw in the Elements software let the attacker create about 4,000 unbacked L-BTC and withdraw them as real bitcoin. See the timeline, who is exposed and the lessons about bridges.

Digital blocks and connections representing a bridge between blockchain networks and federated custody risk
Digital blocks and connections representing a bridge between blockchain networks and federated custody risk

The short answer

On 6 September 2026, about 4,000 bitcoin — roughly US$320 million at the time, or around 95% of reserves — left the federation wallet that backs the Liquid Network, a Bitcoin sidechain built by Blockstream. The cause was not a stolen key or a weak password: a flaw in Elements, the software that runs Liquid, let the attacker create about 4,000 unbacked L-BTC and convert them into real bitcoin through the normal exit process, the peg-out. The federation's automated checks treated the invalid L-BTC as legitimate.

The party behind it calls the operation white hat and has been negotiating a return through signed messages written on-chain. Blockstream says it has patched and updated the bridge nodes. This piece explains what is known so far, why the flaw happened, who is exposed and the lessons that apply to any bridge or parallel network, not only Liquid.

What the Liquid Network is

Liquid is a Bitcoin sidechain: a separate, faster network with privacy features, linked to Bitcoin by a bridge. To enter, you lock BTC on the main chain and receive the same amount in L-BTC on Liquid (the peg-in); to leave, you return the L-BTC and get BTC back (the peg-out). In between, the bitcoin sits with a federation — a group of companies (exchanges and Bitcoin businesses) that run the functionaries, the servers that hold the keys and sign exits. The implicit contract is that every L-BTC is always backed 1:1 by a real BTC held by the federation. Liquid is used mainly by trading desks and exchanges to move value between platforms quickly and confidentially, and to issue other assets such as stablecoin versions and tokens.

What is known so far

  • 6 September 2026: about 4,000 BTC leave the federation wallet in a sequence of withdrawals, leaving only a few hundred bitcoin in reserves. On-chain analysts and press outlets estimate the value at around US$320 million.
  • Network paused: Liquid halts bridge activity; the nodes that handle peg-outs are disabled and exchanges suspend L-BTC deposits and withdrawals.
  • Attacker contact: messages are posted on the Bitcoin blockchain using OP_RETURN (a field for short text in a transaction) and PGP-encrypted text. In one, recorded around block 965,875, the author tells Blockstream to "fix the bug first" and make sure every affected node is patched before any return.
  • Burning the excess: the unbacked L-BTC is destroyed, and the discussion shifts to returning roughly 3,996 BTC.
  • 7 September 2026: Blockstream, led by Adam Back, posts a PGP-signed on-chain message saying the bridge nodes are patched and it is "safe to return the funds". The signature verifies against the security key published on the company's site.
  • At the time of writing: the roughly 4,000 BTC remain in addresses controlled by the attacker. There are reports that the group intends to keep part of the value — in the tens of millions of dollars — as a "bounty".

Why the flaw happened

The problem was in Elements, the codebase that runs Liquid. The flaw allowed a valid peg-out to be sent using invalid L-BTC: vulnerable nodes could not tell a legitimate L-BTC apart from one created by the exploit. In practice the attacker fabricated about 4,000 L-BTC "from nothing", pushed them through the standard exit flow — via the SideSwap service — and the federation released the real bitcoin to an address they controlled.

One key point: no key was compromised. The Peg-out Authorization Keys (PAKs), including SideSwap's, stayed intact. The attack did not "break into the vault" — it exploited a gap in how a legitimate withdrawal is checked. It is the difference between stealing the key and fooling the doorman.

Who is exposed

Anyone holding L-BTC. With reserves depleted and peg-outs suspended, L-BTC may trade below 1:1 with bitcoin (a peg discount) until reserves are rebuilt — which depends on the promised return.

Anyone using assets issued on Liquid. Stablecoins, tokens and other assets on the network depend on the bridge returning to normal and on confidence in the backing.

Exchanges and desks that route through Liquid. Transfers between platforms over this path are stalled while activity is suspended.

Who was NOT affected: main-chain bitcoin for anyone who does not use Liquid. If you hold BTC in self-custody on the main chain, with your own keys, this incident does not change your balance or require any action on your wallet.

What to do now

Do not move L-BTC in a panic. With peg-out suspended and the price possibly detached, dumping into a thin market can be worse than waiting. Assess your real exposure first. Follow official channels: Blockstream, Liquid and your exchange for when L-BTC deposits, withdrawals and peg-outs resume. Distrust "support", "refund" forms and links sent by message — scammers target exactly this moment. If you do not use Liquid, there is nothing to do — but it is worth understanding the case, because the same logic repeats in other bridges and backed networks.

What the case teaches

A sidechain is not Bitcoin. L-BTC is an asset on another network, with other software and another trust model. It promises to equal a BTC, but that promise depends on correct code and an honest, available federation. Every bridge adds two risks: software (a validation bug, as here) and third-party custody (whoever holds the backing can fail, be hacked or freeze withdrawals). "1:1 backing" is a claim to verify, not a guaranteed fact. Ask who custodies, how many signatures are needed, who audits and what happens if one party goes offline. The line between white hat and theft is thin. Draining funds without authorization and making the return conditional — especially while keeping a cut — is not the same as responsible disclosure. The label the attacker chooses does not define the act. On-chain transparency cuts both ways: the whole negotiation is public in signed messages, which helps verify who said what — and also shows how much the outcome depends on the attacker's goodwill.

Checklist

Know where your bitcoin is: main chain in self-custody, L-BTC on Liquid, or a balance on an exchange are three different risk situations. Do not sell in a panic; confirm there is a market and a fair price before exiting. Use only official sources — Blockstream, Liquid and your exchange; ignore "refunds" by link. Reassess bridges: for meaningful amounts, prefer keeping BTC on the main chain unless you truly need the sidechain's features. Keep records of dates, amounts and announcements for support and tax purposes.

FAQ

Is the Liquid Network Bitcoin?

No. It is a parallel network linked to Bitcoin by a federated bridge. Its asset, L-BTC, is meant to be backed 1:1 by BTC but runs on other software and under a different trust model.

Was my bitcoin in a self-custody wallet on the main chain affected?

No, as long as you do not use Liquid. The incident happened in the sidechain's federation wallet, not on the Bitcoin main chain.

What is peg-out and why is it suspended?

Peg-out is the exit from Liquid: you return L-BTC and receive BTC. It was paused to contain the flaw and prevent further improper withdrawals while nodes are patched.

Will I get my L-BTC back?

It depends on the return promised by the attacker and on reserves being rebuilt. Until then L-BTC may trade below the value of a BTC. There is no guarantee of full recovery.

Can the federation just undo the transaction?

No. The bitcoin moved to addresses controlled by the attacker on the main chain, where no one reverses transactions. The federation can only fix the bug, rebuild reserves and negotiate.

Conclusion

The Liquid attack did not break Bitcoin or prove that sidechains "do not work", but it showed at a high cost what depending on a bridge means: a validation bug plus custody concentrated in a federation was enough to remove almost all reserves in a day. For the everyday user the practical lesson is simple: understand which network your money is on, treat "1:1 backing" as something to verify, and keep on the main chain, in self-custody, whatever does not need a parallel network's features.

Informational and educational content. It is not investment advice.

Sources: CoinDesk — US$320 million Liquid Network exploit; The Block — attacker says they will return most of 4,000 BTC; Crypto Briefing — Blockstream confirms bridge nodes patched; The Register — hackers drain US$320M from Liquid Network; Blockstream — official statements. Consulted 7 Sep 2026.

Read more

A sound market reading combines data, context and clear risk limits.