Short answer: On September 7, 2026, it became public that attackers had withdrawn about 4,000 BTC, roughly $320 million, from the federation wallet that backs Liquid, Blockstream's Bitcoin sidechain. That was around 95% of its reserve of about 4,200 BTC. No private keys were stolen: a bug in Liquid's Elements software let the attackers create L-BTC with nothing behind it and redeem it for real bitcoin. The group, which called itself white hats, sent back about 3,400 BTC once the bug was patched; about 598 BTC is still missing.
What happened on the Liquid Network?
According to a timeline published by blockchain analytics firm TRM Labs, the attack itself took 36 minutes on Sunday, September 6 (UTC):
- 13:53 UTC — roughly 4,000 L-BTC is created on Liquid without any bitcoin locked to back it.
- 14:06 UTC — a withdrawal (peg-out) request is submitted through SideSwap, a service authorised to process peg-outs.
- 14:28 UTC — the federation pays out about 4,000 BTC on the Bitcoin blockchain; the attacker's address receives around 3,996 BTC.
By September 7 the incident was public. The recipients embedded messages in Bitcoin transactions describing themselves as white hats and asking Blockstream to fix the bug and patch every node before any money would be returned. Liquid halted new transactions, disabled its bridge nodes and asked exchanges to suspend L-BTC deposits and withdrawals, The Register reported. Bitcoin itself was not affected.
After Blockstream deployed patched software, about 3,400 BTC was sent back to the federation on September 7, according to The Hacker News and TRM Labs. The remaining 598.5 BTC, around $47 million, stayed with the attackers. Liquid resumed block production and transactions on September 10 with peg-outs still disabled, The Block reported. When the attackers later demanded a 10% bug bounty, Blockstream refused, called the withholding theft and said it would work with law enforcement.
| Key fact | Figure |
|---|---|
| Liquid reserve before the attack | ~4,200 BTC |
| Withdrawn by the attackers | ~4,000 BTC (~$320M), about 95% of the reserve |
| Time from mint to payout | 36 minutes (September 6, UTC) |
| Returned after the patch | ~3,400 BTC (September 7) |
| Still outstanding | 598.5 BTC (~$47M) |
| Estimated backing of L-BTC afterwards | ~86% (TRM Labs) |
| Federation signing threshold | 11 of 15 |
How did the exploit work?
Liquid supports confidential transactions, which hide amounts behind cryptographic range proofs. To save work, Elements caches the results of verifying those proofs. TRM Labs describes a flaw in that cache: after broadcasting dozens of transactions carrying matching proof data, the attackers got an invalid output treated as already verified. The chain accepted L-BTC that had no bitcoin behind it.
From there the federation behaved exactly as designed. Its members, who sign withdrawals with an 11-of-15 multisig, saw a valid-looking request from an authorised peg-out service and released real BTC. The keys were never compromised. The weak point was the software that tells the signers what is valid.
What are Liquid, L-BTC and a federated peg?
Liquid is a sidechain: a separate blockchain that runs alongside Bitcoin, with faster blocks and confidential amounts, used mainly by exchanges and trading firms to move BTC between venues. CoinDesk notes that more than 80 exchanges, infrastructure firms and asset managers take part in the network.
To use it, you peg in: send BTC to an address controlled by the federation and receive the same amount of L-BTC on Liquid. To leave, you peg out: L-BTC is destroyed and the federation sends BTC back. The promise that one L-BTC equals one BTC therefore rests on the federation's keys and on the correctness of Liquid's code. Native bitcoin depends only on Bitcoin's own consensus rules.
After the partial return, TRM Labs estimated about 3,597 BTC in reserve against roughly 4,200 L-BTC in circulation, around 86% backing. As long as peg-outs are paused, holders cannot convert L-BTC back to BTC through the peg.
Native BTC vs sidechain and wrapped BTC
| Native BTC | Federated sidechain (L-BTC) | Custodial or bridged wrapped BTC | |
|---|---|---|---|
| What backs it | Nothing needed, it is bitcoin | BTC held by a federation multisig | BTC held by a custodian or bridge contract |
| Main failure modes | Losing your own keys | Software bugs, federation key compromise | Custodian failure, bridge hacks, smart contract bugs |
| Can redemption be paused? | No | Yes, as happened here | Yes, by the custodian or bridge |
| Typical use | Savings, cold storage, final settlement | Fast transfers between trading venues | Using BTC in DeFi on other chains |
A practical checklist for people who send, swap or hold BTC
- If you hold L-BTC, wait for official word. Do not send new peg-ins until Blockstream and the Liquid federation confirm that the peg is fully operational. Rely only on their official channels: incidents like this attract fake refund and claim sites.
- Read the network, not just the ticker. An exchanger may list BTC on the Bitcoin network, BTC over Lightning, L-BTC on Liquid and wrapped BTC on other chains. They are different assets with different risks. Pick the one you actually want to receive.
- Treat wrapped BTC as transit, not storage. For long-term holding, move to native bitcoin in a wallet you control. For fast, small payments without leaving Bitcoin's trust model, Lightning is the alternative; see Lightning vs on-chain bitcoin.
- Compare reserves with supply. Liquid's federation reserve is publicly reported, which is how the 95% drain and the roughly 86% backing afterwards could be measured at all. Before holding any wrapped BTC, look for a published reserve figure and compare it with the tokens in circulation. If no such figure exists, you are trusting blindly. Methods that never create an IOU are compared in atomic swaps vs cross-chain bridges.
- Do not assume a 1:1 exit. When redemption is paused, a wrapped token can trade below the asset it represents. Size positions so that a pause does not trap money you need.
- Compare where you swap. Services differ in which BTC networks they support and how quickly they react to incidents. Check the options on the exchangers list before sending.
FAQ
Was Bitcoin itself hacked?
No. The bug was in Elements, the software that runs the Liquid sidechain. Bitcoin's own network and rules were not affected; the attackers used a flaw on Liquid to redeem unbacked L-BTC for real BTC.
How much bitcoin was taken from Liquid, and how much came back?
About 4,000 BTC, roughly $320 million, was withdrawn on September 6, 2026. About 3,400 BTC was returned on September 7 after the bug was patched, leaving 598.5 BTC, around $47 million, outstanding.
Is L-BTC still backed one to one?
Not fully while the remaining coins are missing. TRM Labs estimated about 3,597 BTC in reserve against roughly 4,200 L-BTC, around 86% backing, and peg-outs were still paused when Liquid restarted transactions on September 10.
Is wrapped or sidechain bitcoin unsafe?
It carries extra risks that native BTC does not: software bugs, custodian or federation failure and paused redemptions. It can be useful for moving funds quickly, but native bitcoin in your own wallet is the safer choice for storage.
Sources
- CoinDesk: $320 million bitcoin exploit hits Liquid Network. Hacker makes conditional offer
- The Register: Hackers drain $320M in Bitcoin from Liquid Network, claim they're the good guys
- TRM Labs: 2026's Biggest Hack To Date: Attackers Drained USD 319 Million in Bitcoin From Liquid Network
- The Hacker News: Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug
- The Block: Blockstream refuses ransom demand for remaining 600 BTC from Liquid exploit