HACKERS drained about 4,000 of the 4,200 Bitcoin held in Liquid Network’s federation wallet on 6 September 2026, a sidechain built by Blockstream used by many exchanges to move funds more privately and quickly than on the main Bitcoin chain. The theft effectively emptied most of the collateral backing Liquid’s L-BTC token, with approximately 3,400 BTC later returned to the federation wallet after Patch confirmation for the affected bridge nodes.
Roughly 598 BTC remained outstanding and the network was paused while federation members carried out security work, resolved a chain split caused by the freeze, and worked to restore confidence that L-BTC is fully backed by Bitcoin.
The attackers described themselves as white-hat and engaged in on-chain communication through OP_RETURN messages rather than demanding a traditional ransom. Bitrue’s breakdown of the exploit indicates the funds were moved not by stealing private keys or credentials, but via a bug in Elements, the open-source code powering Liquid Network, which allowed more L-BTC to exist than the Bitcoin reserves would permit.
The unbacked token was then redeemed for real BTC through SideSwap’s authorised peg-out mechanism; the specific access point cited by Liquid was the SideSwap authorization key, which was not compromised. After Blockstream confirmed patches, 3,400 BTC were returned, leaving about 598 BTC still to be accounted for.
The incident raises questions about trust in a federated system promising one-for-one Bitcoin backing, and has sparked debate over whether the attackers’ actions constitute extortion or legitimate vulnerability disclosure.