On September 6, the Liquid Network—a Bitcoin sidechain where real BTC backs a token called L-BTC—fell victim to an exploit that siphoned nearly 4,000 bitcoin from a federation wallet. The following day, about 3,400 BTC were returned, though around 598.5 remain with the hackers. The stolen funds originally represented roughly 95% of Liquid’s reserves, which totalled about 4,200 BTC before the incident.
What Went Wrong
The breach was tied to Elements, the software that powers Liquid. Attackers used a bug to create L-BTC then ‘peg out’—that is, convert L-BTC back into on-chain BTC—without authorization. Critically, this didn’t involve compromising SideSwap’s peg-out authorization key or any other core keys. SideSwap insists its systems weren’t breached; they attribute the incident solely to the bug in Elements.
Blockstream, the technology provider for Liquid, confirmed that the exploit impacted one of its federation wallets. At the time, the stolen BTC was worth approximately $320 million, with the 3,400 returned BTC valued near $265 million and the leftover 598 BTC around $47 million.
Negotiations, White Hats, and Fallout
The individuals behind the exploit claimed to be white-hat hackers. They inserted messages into blockchain transactions demanding that Liquid patch the flaw and update all nodes before returning funds. Blockstream responded by confirming updates and securing bridge nodes. A tiny transaction, sending just 1,000 satoshis, carried an encrypted message through the blockchain before the bulk of the BTC was sent back.
Even as 3,400 BTC came back, the incident remains unresolved publicly. Blockstream is preparing for a coordinated restart of the Liquid network, but it hasn’t confirmed how much bitcoin currently backs L-BTC. Meanwhile, the remaining ~598 BTC sits unmoved from the hacker’s address. Blockstream has urged users to avoid using deposit (“peg-in”) addresses until full service resumes. Other assets on Liquid—such as USDT and DePix—were not impacted.
There’s debate over whether the hackers truly acted as white hats or if the situation resembled extortion. Some industry leaders question whether there was a negotiated reward hidden within the encrypted messages, suggesting the remaining BTC could be tied to a back-room deal.
Liquid is widely used in crypto trading and institutional applications to provide faster, more confidential settlements compared to on-chain Bitcoin transfers. It operates by using federated servers that guard reserves, and ‘peg-in’ and ‘peg-out’ operations that convert between L-BTC and regular BTC. Any disruption or breach in this architecture can undermine confidence in sidechains and federated custody mechanisms.
Why this matters: the incident underscores the risks embedded in sidechain software—especially bugs that allow token minting or unauthorized conversion. As Liquid prepares to resume operations, it will need to prove both technical soundness and transparent governance. What to watch: whether the full reserves are intact, how Liquid closes the books on the 598 BTC still in limbo, whether any reward was part of an agreement, and how quickly user access returns without new vulnerabilities.