Full Breakdown
Liquid Network Hack Drains $320 Million in Bitcoin
9/7/2026, 8:21:41 PM
What Happened on September 6, 2026
On September 6, 2026, roughly 4,000 BTC—about $320 million—were withdrawn from the Liquid Network federation wallet, which held ~4,200 BTC beforehand. The peg-out completed in roughly 23 minutes. Liquid immediately disabled its bridge nodes, paused all new L-BTC deposits and withdrawals, and warned that “Liquid wallets will be impacted.”
Background and Technical Context
Liquid is a Bitcoin sidechain launched in 2018 by Blockstream. It lets exchanges move Bitcoin onto the sidechain, receive L-BTC, and settle transactions faster. The federation’s reserves are secured by an 11-of-15 multisignature arrangement, and peg-outs require a valid Peg-out Authorization Key. SideSwap, a federation member, processes peg-outs under normal conditions.
Data and Statistics
| Metric | Figure |
|---|---|
| BTC in federation wallet before breach | ~4,200 BTC |
| BTC withdrawn | ~4,000 BTC (?3,996 BTC confirmed on-chain) |
| Remaining BTC after withdrawal | ~200 BTC |
| Monetary value of withdrawn BTC | ? $320 million |
| Percentage of reserves drained | ? 95 % |
| Time of peg-out request | 14:05 UTC |
| Block confirming withdrawal | Bitcoin block 965,783 at 14:28:56 UTC |
| SideSwap PAK status | Not compromised (per Liquid) |
Official Statements and Responses
- Liquid Network posted on X that the funds were taken by “purported white-hat hackers,” apologized, and suspended new transactions while members investigate.
- Blockstream shared contact details for its security team and exchanged encrypted, PGP-signed messages with the unknown actors.
- SideSwap confirmed the peg-out used its authorized PAK and said the key itself was not breached.
Criticism and Opposition
- Charles Guillemet, CTO of Ledger, argued that genuine white-hat researchers would not drain a bridge before contacting the project.
- Samson Mow, former CSO of Blockstream, noted a Signal contact request originated from an address different from the one holding the coins, raising doubts about the attackers’ identity.
Verbatim Quote
- “While these events may understandably shake consumer confidence, they highlight where critical infrastructure safeguards need to be strengthened, and why comprehensive security across the full stack is essential for operators.” — Ziqing Ang, head of policy, Asia-Pacific, TRM Labs
Conflicting Reports and Gaps
Analysts differ on the breach’s cause. Some attribute it to a consensus-level bug in the Elements software that allowed unbacked L-BTC to be minted and redeemed; others describe the failure more generally as “an unusual failure.” Liquid continues to label the actors “purported” white-hats, and no independent confirmation of a planned fund return exists.
Why It Matters
Liquid’s 1:1 backing of L-BTC by Bitcoin reserves is central to its model. Draining 95 % of those reserves raises questions about the network’s ability to honor future peg-outs and challenges confidence in federated bridge architectures used by many exchanges.
What’s Next
- Investigation: Federation members are reviewing the Elements codebase and peg-out process.
- Communication: Blockstream is attempting contact with the actors via signed on-chain messages.
- Network status: Bridge nodes remain disabled, and L-BTC deposits and withdrawals are paused. No timeline has been given for resumption.
- Potential remediation: A software fix for the suspected Elements bug has been merged but not yet released; deployment will be required before any fund return.
