Liquid Network Halts as 'White Hats' Drain 4,000 BTC in $320M Sidechain Exploit

September 7, 2026

Federation Wallet Loses 95 Percent of Reserves Overnight

Blockstream’s Liquid Network, one of the oldest Bitcoin sidechains, was drained of 3,996 BTC (worth roughly $320 million) on September 6, 2026, according to on-chain records first flagged by Galaxy Research’s Alex Thorn. The federation multisig wallet that backs L-BTC held about 4,200 BTC before the incident. It now holds just 197 BTC, a 95 percent drop in a single day.

The withdrawal cleared at approximately 14:28 UTC through a routine-looking peg-out transaction, the process users normally trigger to convert wrapped L-BTC back into native Bitcoin. Nothing in the transaction signature looked forged. That is exactly what unsettled the security researchers watching the block.

How Attackers Cleared the Federation Multisig

The exploit did not steal private keys. Instead, it manipulated the software that decides whether a peg-out request is valid. SideSwap, the peg-out service through which the transaction was routed, said the attacker created L-BTC out of nothing by exploiting a bug in Elements, the open-source Bitcoin fork that Liquid runs on. The 11-of-15 federation signing quorum then signed a withdrawal for L-BTC that should never have existed.

According to CryptoBriefing’s technical breakdown, 4,000 phantom L-BTC were submitted at 14:05 UTC. Twenty-three minutes later, 3,996 real BTC left the federation reserve. The signatures were valid. The math behind them was not.

What Liquid Actually Is, and Why Wrapped Bitcoin Matters

Liquid is a separate blockchain built on top of Bitcoin’s security. Users lock BTC into a federation-controlled multisig wallet and receive L-BTC on the sidechain at a 1:1 rate, a process called a peg-in. Traders use L-BTC because it settles in about a minute and carries lower fees than Bitcoin’s main chain. To exit, they burn their L-BTC, and the federation releases the equivalent amount of Bitcoin from the reserve, a peg-out.

The design works only if two things stay true: the L-BTC on the sidechain always maps to real BTC in the vault, and the software that authorises peg-outs cannot be tricked into signing anything else. This week, the second half of that assumption broke. For anyone new to holding wrapped assets, the takeaway is simple: a wrapped coin is only as safe as the bridge that mints it, which is why choosing a trusted crypto wallet still matters even when the underlying asset is Bitcoin itself.

Solana Deposits now live on Digitap

The ‘White Hat’ Claim Playing Out On-Chain

Hours after the drain, the receiving address began writing messages into Bitcoin transactions using OP_RETURN, the field that lets senders attach small pieces of data to a transfer. The sender claimed to be a security researcher. “we are whitehats. contact us on chain,” one message read, per on-chain data reconstructed by Galaxy Research and reported by crypto.news.

Blockstream replied through the same channel, publishing a PGP signature so the counterparty could verify the identity of its security team. On September 7, the sender proposed returning “most” of the funds, but only after Blockstream releases a patch and every federation node upgrades. The word “most” was not defined. No deadline was given. No identities were disclosed.

Bridge Frozen, Exchanges Pull L-BTC Support

Liquid’s federation disabled the bridge nodes shortly after the drain, meaning no new BTC can peg in and no L-BTC can peg out. Several exchanges suspended L-BTC deposits and withdrawals within hours, a defensive move that could last as long as the peg imbalance sits on the sidechain. Traders comparing venues on a best crypto exchange shortlist would have noticed L-BTC pairs pulled without warning at multiple platforms.

Other Liquid assets, including Tether’s USDT-L, DePix, and tokenised real-world assets, are unaffected because the exploit was specific to the BTC peg. But L-BTC holders now sit behind a locked bridge, holding a token backed by a wallet with 5 percent of the reserves the market thought were there.

What Happens If the Funds Return, and What Happens If They Don’t

The Liquid federation had already burned the 4,000 L-BTC used in the peg-out before the BTC left the vault, meaning the token supply and reserve balance remain technically consistent on paper. When the bridge reopens, redemption pressure could exceed what 197 BTC can service, and analysts suggest L-BTC could trade at a temporary discount to spot Bitcoin until either the funds return or the federation closes the gap.

Bitcoin itself barely moved. BTC held near $80,000 through the incident, because the exploit affected a system built on Bitcoin rather than the Bitcoin protocol itself. Traders tracking crypto market prices through the event noted spreads widened briefly on L-BTC pairs, then settled once exchanges froze the market.

If the sender returns the funds after a Blockstream patch, this will be the largest known responsible disclosure payout in Bitcoin sidechain history. If they do not, it becomes the largest theft in that same category, and one of the largest Bitcoin-denominated losses on record.

Sidechain Trust Faces Its First Nine-Figure Stress Test

The Liquid incident is not about Bitcoin’s security model. Bitcoin’s own consensus rules held throughout. It is about the layer of trust that sits between users and the assets those layers wrap. Liquid’s 11-of-15 federation was designed to make theft mechanically difficult, and it still is, because the attacker did not defeat the signatures. The signatures approved a state the software should never have allowed to reach them.

For the wider industry, that distinction is the story. Bridges, sidechains, and wrapped assets carry a software surface that scales faster than the audit budget behind it. Liquid ran for years without incident, then surrendered $320 million to a single logic flaw. Whether the funds come back or not, every federation, custodian, and bridge operator on the market now has to answer a version of the same question Blockstream is answering this week.

Solana Deposits now live on Digitap

Share Article

Madiha Riaz

Madiha Riaz

Madiha is a seasoned researcher in cryptocurrency, blockchain, and emerging Web3 technologies. With a background in organic chemistry and a sharp analytical mindset, she brings scientific depth to decentralized innovation. Since discovering crypto in 2017 and investing in 2018, she’s been uncovering and sharing deep insights into how blockchain is redefining the digital asset landscape.