Bitcoin BTC $79,625 -0.21% Ethereum ETH $2,497 -0.37% BNB BNB $745 -2.04% Solana SOL $105 -0.33% XRP XRP $1.41 -0.80% Dogecoin DOGE $0.089822 -1.58% Pepe PEPE $0.000004 -1.30% Sui SUI $0.798138 0.18% Fartcoin FARTCOIN $0.173363 -0.67%

Liquid Network Hack: “Whitehats” Pull $320 Million in Bitcoin From Blockstream’s Sidechain

September 7, 2026
Liquid Network Hack: $320 Million in Bitcoin Gone in One Transaction

Bitcoin’s oldest sidechain just watched 95% of its reserves walk out the door in a single transaction. On September 6, someone drained roughly 4,000 BTC, worth about $320 million, from the federation wallet backing Blockstream’s Liquid Network. The wallet held around 4,200 BTC before the withdrawal. It now holds a little over 200.

Here’s the twist: the people holding the coins claim they’re whitehats. They left a message on the Bitcoin blockchain saying exactly that, and they’re now negotiating the return of the funds with Blockstream in public, one OP_RETURN message at a time.

Let’s break down what happened, how the attackers pulled it off, and whether that $320 million is actually coming back.


What Happened to Liquid Network?

Liquid Network is a Bitcoin sidechain run by a federation of exchanges and crypto businesses. Users lock real BTC on the main chain and receive Liquid Bitcoin (L-BTC) on the sidechain, which settles faster and supports confidential transactions. The federation wallet holds the BTC that backs every L-BTC in circulation.

On Sunday, September 6, a peg-out transaction moved roughly 4,000 of the 4,200 BTC out of that wallet. The withdrawal went through SideSwap, a settlement platform authorized to process peg-outs from the network, using the SideSwap Peg-out Authorization Key (PAK). Liquid stressed that the attackers never compromised the key itself and that no other keys were at risk.

The damage control came fast. Liquid disabled its bridge nodes, which means no new transactions can enter the sidechain, and exchanges paused L-BTC deposits and withdrawals. Other assets on the network, including USDT, DePix, and tokenized real-world assets, were untouched. Bitcoin itself was never at risk either; this was a flaw in a system built on top of Bitcoin, not in Bitcoin’s own protocol. BTC barely reacted, holding steady around $80,000.


How the Attackers Did It

Blockstream hasn’t published a full post-mortem yet, but early analysis points to an inflation bug in Elements, the open-source codebase Liquid runs on. The attackers appear to have exploited a consensus flaw to mint over 4,000 L-BTC that never existed, then cashed those tokens out for real on-chain Bitcoin through the federation’s peg-out mechanism.

Because the transaction looked valid under the buggy consensus rules, the federation members’ security servers signed off on the withdrawal like any other. That’s what makes this one sting. Nobody phished a signer, and nobody leaked keys. The peg itself, the exact thing that’s supposed to make L-BTC trustworthy, turned out to be the weak point, and the flaw exposed every L-BTC holder through no fault of their own.

That’s a very different failure mode from user-level compromises. You can protect yourself from phishing by understanding how seed phrases and passphrases work, but no amount of personal opsec saves you when the protocol layer under your assets has a hole in it. We saw a similar dynamic in the KelpDAO exploit, where the vulnerability sat in the infrastructure rather than in any individual wallet.


The Strangest Hack Negotiation of 2026

Right after consolidating the funds, the attackers signed a transaction with a message in the OP_RETURN data field: “we are whitehats. contact us on chain.”

Blockstream played along. The company sent 1,000 satoshis to the attacker’s address with its own OP_RETURN message asking them to email the security team, then followed up with a PGP-signed, encrypted message. The attackers preferred to keep things public, though they did drop a Signal handle at one point.

The back-and-forth, which Galaxy Research head Alex Thorn and JAN3 CEO Samson Mow reconstructed from the transaction data, went roughly like this:

  • The attackers asked whether sending “most” of the funds back to a specified federation address would be acceptable.
  • About an hour later, they added a condition: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”
  • Blockstream replied with a simple “Yes, thank you.”

The attackers also sent encrypted technical details about the vulnerability to Blockstream. As of Monday morning, nearly all of the BTC sits unmoved in the attacker’s address, and the attackers haven’t sent anything back yet.

There’s something almost poetic about a nine-figure negotiation happening in public via Bitcoin transaction data. It’s a reminder that transparency and on-chain privacy are two sides of the same coin: everyone can watch this conversation, yet nobody knows who’s holding the money.


Whitehat or Ransom Note?

Not everyone buys the whitehat framing. Ledger CTO Charles Guillemet pointed out that legitimate security researchers don’t typically drain a bridge for $320 million and then ask to be contacted on-chain. He compared the situation to the Ronin hack, where attackers stole around $625 million after compromising validator keys, and the Euler exploit, where the attacker negotiated a return only after the theft.

The skeptics have a point. A genuine whitehat usually reports the bug privately or takes a small proof-of-concept amount, not 95% of the reserves. The word “most” in the return offer also does a lot of heavy lifting; it leaves the door open for the attackers to keep a self-assigned bounty of unknown size.

On the other hand, the behavior doesn’t fit a typical blackhat either. Criminal groups don’t usually open a dialogue with their victims, hand over technical details of the vulnerability, or leave $320 million sitting untouched in a transparent address. If they wanted to run, mixing services would be the obvious next step, and we’ve covered how crypto mixers like Tornado Cash work well enough to know that laundering 4,000 BTC is hard but not impossible.

Until the coins land back in the federation wallet, this remains a negotiation, not a recovery.


What It Means for Users

If you hold L-BTC, your tokens currently sit on a paused sidechain backed by a wallet that lost 95% of its reserves, pending the return of funds. The federation says wallets will be impacted while the network is halted, and exchanges have suspended L-BTC deposits and withdrawals until further notice.

If you hold regular BTC, nothing changed for you. The market shrugged, and the base layer worked exactly as designed. The lesson here is about layers: every additional layer between you and the base chain, whether a bridge, a federation, or a wrapped token, adds a new way to lose money that has nothing to do with your own mistakes.


Keep This Content Free

We don’t run intrusive ads, and we don’t paywall breaking coverage like this Liquid Network hack breakdown. If you want to support the site, sign up through our OKX or Bybit links. It costs you nothing extra and keeps our research free for everyone.


Final Words

The Liquid Network hack is one of the largest Bitcoin-denominated security incidents ever recorded on a sidechain, and it’s also one of the weirdest. A federation model that ran quietly since 2018 lost $320 million to a consensus bug, and the fate of the funds now rests on the goodwill of anonymous attackers who insist they’re the good guys.

The optimistic read: the bug gets patched, “most” of the BTC comes home, and Liquid survives with a bruised reputation and a stronger codebase. The pessimistic read: the whitehat label was theater, and this becomes the Ronin of Bitcoin sidechains. We should know which version we’re living in within days. Either way, expect every federated bridge and sidechain to get a very uncomfortable security review this month.


Up to 30k in Deposit Rewards on Bybit with their Starter promotion
Check our recent Bybit vs Binance comparison review.

FAQ

How much was stolen in the Liquid Network hack? Roughly 4,000 BTC, worth about $320 million at the time, left the Liquid Federation wallet on September 6, 2026. The wallet held around 4,200 BTC before the incident.

Was Bitcoin itself hacked? No. The exploit never touched Bitcoin’s base layer. The exploit targeted Liquid’s federation-controlled peg-out mechanism, a separate system built on top of Bitcoin, and BTC price held steady around $80,000.

Who hacked Liquid Network? The attackers are anonymous. They claim to be whitehat hackers in on-chain messages and have offered to return most of the funds once Blockstream patches the underlying bug, but nobody has verified that claim.

Will the stolen Bitcoin be returned? Unconfirmed. The attackers pledged to send “most” of the BTC back once Blockstream fixes the vulnerability across all nodes. As of September 7, the funds remain in the attacker’s address.

Is L-BTC still safe to hold? L-BTC is currently frozen in practice. The sidechain’s bridge nodes are disabled and exchanges have paused L-BTC deposits and withdrawals, so holders need to wait for the network to resume and the reserves to be restored.

Morten Christensen
Founder, AirdropAlert
Written by
Morten Christensen

Crypto class of '13, airdrop farmer since 2016. Avid trader and DeFi veteran. His market commentary has been featured by Bloomberg, The Wall Street Journal, The New York Times, Forbes, and CNN.

We publish new crypto airdrops for you every day

Trade your crypto

Support us by using our referral link on these exchanges. Claim their sign up bonus and trade your airdropped coins and other cryptocurrencies.

airdropalert-bybit-logo
Airdropalert okx logo
HyperLiquid Logo DEX AirdropAlert
Airdropalert-Binance-logo
Blofin Exchange logo AirdropAlert
mexc-logo-airdropalert