The Liquid Network is running again, but it is not whole. Sixteen days after self-described white hat hackers drained roughly 4,000 BTC, worth about $320 million at the time, from the Bitcoin sidechain’s federation wallet, block production and internal transfers are live, yet the one function the network exists to provide, converting L-BTC back into bitcoin, remains suspended. About 598.5 BTC, now worth more than $45 million, is still held by the attackers, and Blockstream has refused their demand for a 10% bug bounty to get it back.
The gap is visible on-chain. The protocol shows about 4,234.76 L-BTC in circulation against roughly 3,632.23 BTC actually held in reserve. That is a hole of about 600 coins in a system whose entire premise is a one-to-one match between the token and the bitcoin locked behind it. Blockstream founder Adam Back has said the peg will be covered 1:1, and he has told holders not to sell their L-BTC over the counter at a discount. What he has not done is explain exactly how the missing coins will be funded, or set a date for peg-outs to resume.
How the drain happened
The September 6 incident did not involve a stolen key, which is what makes it unusual among 2026’s crypto breaches. At 14:05 UTC, someone sent 4,000 L-BTC to SideSwap, a federation member that processes peg-outs. SideSwap handled the order like any other. The L-BTC was burned on Liquid with valid authorization, and at 14:28 UTC the federation paid out 3,996 BTC to the customer’s bitcoin address. Eleven of the federation’s fifteen keys signed the transaction because, under the network’s rules, it looked legitimate.
Blockstream later traced the root cause to a bug in Elements, the open-source software Liquid runs on. Early analysis points to a proof-verification cache vulnerability that let the attackers create L-BTC that was never backed by any bitcoin, then redeem it through the normal peg-out path. The federation wallet held about 4,200 BTC before the incident, so a single withdrawal removed roughly 95% of the reserve. Other assets on Liquid, including USDT and DePix, were unaffected.
The attackers embedded a message in a bitcoin transaction: “we are whitehats.” They asked Blockstream to fix the bug first, warning that the chain was at risk at the latest commit, and said they would return the funds once every node was patched. Blockstream responded on-chain with contact details for its security team, and the two sides moved to encrypted channels.
The return, and the bounty demand
Most of the money came back quickly. On September 7 at 16:09 UTC, 3,400 BTC, about 85% of what was taken, arrived at a federation address. The remaining 598.5 BTC was not a separate payment. It is the change from that same transaction, sent back to the address the funds came from, and it has sat there since.
Then the tone shifted. On September 9, the anonymous hacker published a critique of Blockstream’s security budget, claiming the company had allocated only $1.5 million to secure what it describes as $5 billion in assets. “Your dereliction of duty is obvious,” the message read, and it threatened that failure to pay a 10% bug bounty would mean losing the unreturned coins permanently. Blockstream has declined to pay and wants the coins returned unconditionally.
“Do not panic sell OTC,” Adam Back told L-BTC holders, while pledging that the L-BTC peg with bitcoin will be covered in full.
The standoff has left holders in an odd position. They hold a token that is supposed to be fully backed but currently is not, issued by a federation that says it will make them whole but has not said when redemption reopens or from whose pocket the shortfall will come.
A controlled, partial recovery
The recovery has moved in stages. Liquid paused the entire sidechain on September 6 and asked exchanges to suspend L-BTC deposits and withdrawals. An emergency update, Elements v23.3.4, shipped to address the proof-verification cache vulnerability by hardening the cache keys used for range proofs. On September 10, block production resumed without transactions while the team monitored stability.
By September 17, the network was broadly functional internally. Block production and L-BTC transfers were operating normally, exchange-level services were returning, BTSE had re-enabled USDT-Liquid transfers, and SideShift had restored cross-chain swaps for USDT and DePix. What had not returned was the peg. Liquid’s own status update was blunt: peg-outs will resume only after full 1:1 BTC backing for L-BTC has been confirmed and all required software updates, testing and independent security reviews are complete. No date was given.
The full technical post-mortem promised by Blockstream has also not been published. The company says it will come as soon as it is available.
What the incident says about federated sidechains
Liquid launched in 2018 as a settlement layer for exchanges and traders who needed faster finality than the bitcoin base layer could offer. More than 80 exchanges, infrastructure firms and asset managers make up its federation, and each L-BTC is meant to be matched one-for-one with real bitcoin in a shared multisig wallet. The model depends on two assumptions: that the software cannot mint unbacked tokens, and that the federation’s signing process will catch anything that tries.
The September 6 attack broke the first assumption without touching the second. The federation did exactly what it was designed to do, signing what looked like a valid peg-out. The problem was upstream: the tokens being redeemed should never have existed. That is a software assurance failure, not a key management failure, and it is harder to insure against because it sits inside the codebase the network depends on.
| Metric | Before Sept 6 | Current status |
|---|---|---|
| Federation reserve | ~4,200 BTC | ~3,632 BTC |
| L-BTC in circulation | ~4,234.76 | ~4,234.76 (unchanged) |
| Backing ratio | ~100% | ~86% |
| Peg-outs | Operational | Suspended |
| Block production | Operational | Resumed Sept 10 |
It is also the third exploit this year involving a bitcoin-backed project, following incidents at Symbiosis and Nomic. That pattern is drawing scrutiny to the broader category of protocols that issue tokens against locked bitcoin, a design that concentrates a large prize behind a single codebase.
What happens next
Three things remain open. First, the 598.5 BTC: either Blockstream pays, the hacker relents, or the coins are gone and the company covers the shortfall from its own funds, something it has implied but never detailed. Second, the peg-out restart, which depends on the security reviews Liquid has scheduled. Third, the post-mortem, which will determine whether the vulnerability was confined to Liquid or exists in Elements more broadly, since Elements underpins other federated deployments.
For users, the practical advice from Blockstream has not changed since the incident: hold, do not dump. The market has largely taken that view. Bitcoin’s price barely registered the event, trading in a range through the incident window and rallying past $87,000 this week on ETF flows that have nothing to do with the sidechain. Liquid’s problem is a plumbing problem, and so far the market is treating it that way. Whether that calm holds through the peg-out restart, and through the eventual publication of a post-mortem that names the flaw in public detail, is the real test.
