Liquid Network, the Bitcoin sidechain operated by Blockstream, restarted block production on September 10 after a four-day shutdown triggered by the largest crypto theft of 2026. Attackers exploited a flaw in the Elements software underpinning the network on September 6, minted roughly 4,000 unbacked L-BTC tokens, and drained about $320 million in bitcoin from the federation wallet that backs the entire sidechain. Most of the funds have been returned, but the episode leaves hard questions about a network whose core promise was institutional-grade security.
How the exploit worked
Liquid is a federated sidechain launched in 2018. Exchanges and infrastructure firms lock real bitcoin into a multisig wallet controlled by a federation of more than 80 members, and the network issues L-BTC tokens one-for-one against those reserves. Users, mostly exchanges seeking faster settlement than the bitcoin mainnet allows, transact in L-BTC and can peg out to real bitcoin at any time.
The exploit did not touch keys, hardware security modules or any member’s signing infrastructure. According to Blockstream and security firms that analyzed the incident, a bug in Elements, the open-source codebase Liquid runs on, allowed the attacker to create synthetic L-BTC without corresponding reserves. On September 6, at Liquid block 4,050,336, the attacker used the minted tokens to withdraw roughly 3,996 BTC through SideSwap, a trading platform authorized to handle transfers from the network.
The numbers tell the story starkly. Before the attack, the federation wallet held more than 4,200 BTC. Afterward it contained roughly 197 BTC. That is a 95 percent drawdown in a single transaction sequence on a network that markets itself on its conservative security model. SideSwap said it could not distinguish minted tokens from legitimate ones, because on the ledger itself they looked identical, so the fraudulent coins passed through a normal, approved platform rather than some shadowy mixer.
“Liquid wallets will be impacted, and we’re sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity.” – Liquid Network, in its September 6 statement on X
The white-hat negotiation
Within a day, the picture grew stranger. Entities claiming to be white-hat hackers opened an on-chain negotiation with Blockstream. After the company deployed emergency node updates and patched the underlying bug, the attackers returned approximately 3,400 BTC on September 7, keeping about 598.5 BTC, worth roughly $47 million at the time, as what they described as a bounty.
TRM Labs, the blockchain analytics firm that published the most detailed public accounting of the incident, confirmed the transfer pattern but noted the obvious: the white-hat claim is unverified. An attacker who got caught, or feared getting caught, has every incentive to rebrand as an ethical hacker and negotiate a softer exit. Whether these were security researchers performing a dramatic proof-of-vulnerability or ordinary thieves who chose the most profitable way out, nobody outside the group knows.
The bounty economics are worth sitting with. Keeping $47 million from a $319 million haul is a 15 percent fee for returning money you should never have had. No bug bounty program on earth pays like that, which is precisely why skeptics read the incident as a shakedown with better public relations.
Where the network stands now
| Metric | Before exploit (Sept 6) | After exploit |
|---|---|---|
| Federation wallet balance | ~4,200 BTC | ~197 BTC (before returns) |
| Amount drained | – | ~3,996 BTC (~$319M) |
| Returned by attackers | – | ~3,400 BTC (~$272M) |
| Still missing | – | ~598.5 BTC (~$47M) |
| Block production | Normal | Resumed Sept 10, no transactions |
| Peg operations | Open | Suspended during recovery |
Blockstream confirmed on September 10 that updates to the network’s functionary and bridge nodes were complete and that functionary nodes were signing and validating blocks again. But the recovery is deliberately slow. Blocks are being produced without transactions as a precaution while the team watches for full stabilization, and peg operations, the mechanism that lets users move bitcoin in and out of the sidechain, remain on hold. There is no published date for reopening.
That holding pattern matters for exchanges. Bitfinex, BTSE and other Liquid users rely on the sidechain for settlement between venues, and every day of suspended pegs is a day those flows route around Liquid or wait. Some of that volume may not come back.
What the bug says about federated design
The deeper damage is architectural. Liquid’s security pitch has always rested on two legs: a federation of independent institutions holding keys, and validation software that prevents anyone from creating unbacked tokens. The federation leg held. The validation leg failed completely, and when it did, the failure was silent and total. A bug in the node software let one actor mint 4,000 synthetic tokens, and the network’s own accounting could not tell them apart from the real thing.
Security researchers pointed out that the flaw sat at the node level rather than in key management, which means every deployment of Elements-based software shares at least some exposure until patched. FailSafe, a cybersecurity firm whose CEO commented on the incident, called it a critical weakness in Liquid’s validation and backing model, a fair summary of what happened.
Defenders of the design note that bitcoin’s main chain and protocol were never affected, and that the stolen coins were real bitcoin held in reserve, not created from nothing on the base layer. Both true. But users do not hold bitcoin main chain through Liquid; they hold L-BTC, and for four days the claim behind every L-BTC token in existence was in doubt. The peg model depends on reserves always being there. This week they were not.
A bruising year for crypto security
The Liquid drain caps a run of infrastructure failures that have little in common except timing. A lending platform linked to Crypto.com lost $6 million days earlier. Coinkite’s Coldcard hardware wallets, long considered the gold standard for bitcoin self-custody, were hit in an August attack that drained about $86 million from thousands of devices. BitMEX, itself a Liquid federation member, announced in August that it would shut down in September.
TRM Labs ranks the Liquid incident as 2026’s largest crypto theft to date, ahead of April thefts from KelpDAO and Drift. The pattern across these events is consistent: the attacks are not hitting user negligence or phishing, they are hitting the software and operational layers beneath the products people actually use. That is a harder problem for the industry, because it means even users who did everything right, who chose a reputable sidechain operated by a well-known firm, still had their funds’ backing put at risk by a code bug they could never have evaluated.
The remaining $47 million is the least of it. Recovery teams and blockchain analytics firms will watch for the missing coins moving to exchanges, and on-chain freezes remain possible on networks that support them. The reputational repair will take longer. A federation built by exchanges, for exchanges, just demonstrated that its accounting could be falsified at scale, and every institution that trusted that accounting will now ask harder questions before locking funds in again.
