
The Liquid Network Hack drained nearly 4,000 BTC worth about $320M. Here’s how an Elements bug enabled the exploit and what happens next.
Author: Akshay
7th September 2026 – Purported white-hat hackers drained roughly 4,000 BTC from the Liquid Federation wallet on Sunday, September 6. At current prices, that haul is worth about $320 million.
High Signal Summary For A Quick Glance
Evas
@DasEvas1
@WatcherGuru moving $320M on-chain is not the same as selling it. there’s currently no evidence the funds reached an exchange. the actual market impact depends entirely on what happens next, not on the withdrawal transaction itself. https://t.co/CroC6TTksY
JUST IN: 4,000 Bitcoin worth $320 million withdrawn following Liquid Network hack. The hacker is now communicating with network maintainers through on-chain Bitcoin transactions & intends to return the $BTC after the vulnerability is fixed. https://t.co/OXpS1X3oqK
07:12 AM·Sep 7, 2026
humptydumpty
@h_dumptytrading
@WatcherGuru A hacker promising to return funds after a patch is either a disciplined whitehat or stalling for an exit. Either way: don't price it in until the BTC actually moves back on-chain, not before.
JUST IN: 4,000 Bitcoin worth $320 million withdrawn following Liquid Network hack. The hacker is now communicating with network maintainers through on-chain Bitcoin transactions & intends to return the $BTC after the vulnerability is fixed. https://t.co/OXpS1X3oqK
07:08 AM·Sep 7, 2026
Dumitrescu Octavian Nicolae
@tavitag203
@WatcherGuru The coins are not returned. They are parked with a slogan. About 4,000 of Liquid’s 4,200 BTC left the federation wallet, 95% of the peg, through a SideSwap peg-out. Liquid says the key was not stolen and blames a bug in Elements. The stack sits on one address with an on-chain
JUST IN: 4,000 Bitcoin worth $320 million withdrawn following Liquid Network hack. The hacker is now communicating with network maintainers through on-chain Bitcoin transactions & intends to return the $BTC after the vulnerability is fixed. https://t.co/OXpS1X3oqK
07:02 AM·Sep 7, 2026
High attention and emotional sentiment detected.
The Liquid Network hack pulled about 95% of the sidechain’s Bitcoin reserves. As a result, Blockstream paused the network and told exchanges to halt L-BTC deposits and withdrawals.
The trouble started at about 14:05 UTC. A customer submitted a peg-out order for roughly 4,000 L-BTC through SideSwap.
SideSwap runs a peg-out service that burns L-BTC and releases the matching Bitcoin. So the request looked routine at first.
Then the Liquid Federation signed the withdrawal. At about 14:28 UTC, in Bitcoin block 965,783, its multisig broadcast a peg-out of roughly 3,996 BTC.
Soon after, the funds landed at a single address. That wallet then held about 3,998.5 BTC, according to mempool.space data.
The main peg-out transaction, tagged 8db751a6, confirmed in block 965,783. A later transaction then carried the white-hat message and returned a token amount to the federation.
Timeline: A September 2026 Liquid Network exploit led to an approximately 4,000 BTC peg-out, a network pause, and conditional negotiations over the funds’ return.
Approximately 4,000 L-BTC was submitted to SideSwap, burned on Liquid and processed as a valid peg-out request.
The Liquid Federation signed the peg-out, releasing approximately 3,996 BTC and reducing its wallet balance to about 197 BTC.
The holding address sends 1,000 sats back and posts an on-chain message: “we are whitehats. contact us on chain.”
Blockstream responds on-chain requesting contact through its security channel, followed by encrypted and signed messages.
Liquid publicly acknowledges the incident, disables bridge nodes and pauses the sidechain while L-BTC deposits and withdrawals are halted.
The actors indicate they will return most funds after the vulnerability is fixed and all network nodes are patched.
Liquid remains paused pending a verified network-wide fix; no fund return or complete patch deployment has been confirmed.
Liquid is a Bitcoin sidechain that Blockstream launched in 2018. A federation of functionaries holds the pegged Bitcoin in an 11-of-15 multisig wallet.
To move value in, users lock BTC and mint L-BTC. To move value out, they burn L-BTC and unlock the matching Bitcoin.
Because the system gates withdrawals with Peg-out Authorization Keys, funds normally reach only approved addresses. Therefore the federation trusts a request once the keys and the burn check out.
This was not a stolen key. Liquid and SideSwap say the SideSwap Peg-out Authorization Key stayed secure, and so did every other federation key.
Instead, the root cause sits in Elements, the software that powers Liquid. Reportedly, the flaw let the attackers mint L-BTC that no real Bitcoin backed.
The attackers then burned that inflated L-BTC and asked for the Bitcoin back. Because the burn and the authorization looked valid, the federation’s hardware signed the release.
In effect, the Liquid Network hack turned a normal peg-out into a $320 million withdrawal. Both CoinDesk and Reuters traced the loss to the Elements flaw rather than any key theft.
By 18:30 UTC, the actors sent a message. They moved the funds through a consolidation transaction and attached a note in the OP_RETURN field.
OP_RETURN is a small data field that lets anyone attach text to a Bitcoin transaction. The note read: “we are whitehats. contact us on chain.”
Blockstream answered on-chain within hours. The team returned 1,000 sats and wrote, “Please contact security@blockstream.com,” according to on-chain records.
After that, both sides traded more notes, and some arrived PGP-encrypted. The actors said they would return “most” of the funds once every node runs a patched version.
In one later message, the actors wrote: “Please fix the bug first. Make sure every node is patched. Then we will transfer the money back safely.”
Galaxy Research and independent on-chain analysts amplified the exchange as it happened. So the crypto community got a rare, live view of a hack negotiation.
Despite the scale, the Liquid Network hack barely moved the Bitcoin price. BTC traded between about $79,200 and $80,500 around September 6 and 7.
In other words, the market treated the event as contained. Because the exploit hit L-BTC alone, spot Bitcoin liquidity stayed intact.
Still, the incident dents confidence in Liquid’s design. The sidechain now backs far less Bitcoin than it did a day earlier.
Traders on X reacted with a mix of alarm and dark humor. Some called it a forced bug bounty, while others flagged the risk of federation-based sidechains.
Still, not everyone trusts the white-hat framing. Liquid itself uses the word “purported,” and it has not confirmed the actors’ intent.
Ledger chief technology officer Charles Guillemet questioned the label in public. He compared the drain-then-contact pattern to past bridge hacks such as Ronin.
The word “most” also leaves room for doubt. Analysts note that the actors could keep a slice and still frame the return as a success.
Yet no one disputes the withdrawal itself. On-chain data still shows the roughly 3,998.5 BTC sitting in the attacker address as of Monday.
For now, the Liquid sidechain stays paused. Other Liquid assets, including USDT and DePix, remain unaffected, according to the official statement.
Meanwhile, the federation wallet holds only about 197 BTC after the drain. So a full recovery depends almost entirely on whether the actors keep their word.
Blockstream has not shared a verified patch timeline yet. Until every node upgrades, the network cannot safely restart.
Ultimately, this incident shows how one consensus bug can undo a federation’s careful key security. Readers should treat any recovery estimate as tentative, and this article is not financial advice.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.
Liquid Network Hack Drains $320M in Bitcoin Reserves
Trezor Data Breach Widens to 67,000 More US Customers
Core DAO Finds Bug Behind Excess Validator Rewards
Avici Users Get Full Refunds After Card Exploit
Liquid Network Hack Drains $320M in Bitcoin Reserves
Trezor Data Breach Widens to 67,000 More US Customers
Core DAO Finds Bug Behind Excess Validator Rewards
Avici Users Get Full Refunds After Card Exploit