A Liquid Network hack drained roughly 4,000 BTC worth USD 320 million from Blockstream's Bitcoin sidechain. The alleged attackers now offer to return most of the funds, provided the network patches the exploited flaw first.
Liquid is a sidechain to Bitcoin. Exchanges and trading platforms use it to move BTC between each other quickly and confidentially. Thus they avoid the slower and more expensive mainchain. Anyone using the network first locks Bitcoin in a federation wallet and receives the token L-BTC 1:1 in return. Blockstream Corp originally launched Liquid in 2018. Adam Back co-founded the company. The federation includes more than 80 companies, according to Blockstream. Fifteen functionaries authorize payouts through an 11-of-15 multisig. On 6 September 2026, however, roughly 4,000 of the approximately 4,200 BTC previously held in that reserve left the network. Around 197 BTC remained. The transactions ran through SideSwap, a settlement platform authorized for peg-outs. Its key stayed intact, according to Liquid Network.
A software bug enabled the Liquid Network hack
The attackers did not steal a key. Preliminary technical analyses point instead to a flaw in the Elements node, the software behind the sidechain. Specifically, the affected component is the rangeproof cache, which the network uses for confidential transactions. As a result, attackers could create L-BTC without any locked Bitcoin backing it. During the peg-out, the federation only checked whether the payout address was authorized. It never verified the backing of the submitted L-BTC. Its 15 functionaries hold the keys in dedicated HSM hardware and also validate the blocks of the sidechain.
A patch apparently already existed. On 3 August 2026, a Blockstream developer committed "fix: range proof cache bind to asset and scriptpubkey". The change only reached the release branch after the incident. Therefore release 23.3.3, the version running in production, did not contain it. Block explorers offered an early signal as well. Blockstream's own Liquid explorer accepted the block in question, 4,050,336, while the independent service mempool.space rejected it.
Consequently, SideSwap could not see where the coins came from. The service said it had no way to distinguish these coins from ordinary L-BTC. At the block level, the payout request arrived at 14:06 UTC. A good twenty minutes later, the federation paid out on the Bitcoin mainchain. Notably, the exact sum varies depending on the measurement point. That peg-out covered roughly 3,996 BTC. The federation's payout, including fees, ultimately came to around 4,019 BTC. Custody security does not cover the layer this incident hits. The keys stayed intact. What failed was the code.
Blockstream halts Liquid Network temporarily
The network responded with a stop. Operators disabled the bridge nodes, so no new transactions can enter. Exchanges received instructions at the same time to pause L-BTC deposits and withdrawals. Other assets issued on Liquid, among them Tether and the Brazilian DePix, are said to be unaffected.
"Liquid wallets will be affected, and we apologize for any inconvenience." - Liquid Network, official statement
The reach of the halt follows from the user base. Overall, the federation counts more than 80 exchanges, infrastructure firms and asset managers. Blockstream lists Bitfinex and BTSE as users, as well as BitMEX, which closes in September 2026. Notably, Bitfinex shares its parent company with Tether. These firms use the sidechain for fast settlement, because transfers on the Bitcoin mainchain take longer and cost more. Public statements from the named exchanges are not yet available, however.
Blockstream itself held back. Neither the company nor co-founder Adam Back commented on the outflow on X by press time. Therefore the network account and SideSwap were the main voices in public.
Alleged attackers signal a partial return
Those responsible surfaced on-chain. "we are whitehats. contact us on chain.", read a message they embedded in a transaction. A day later came the offer to return most of the funds once developers fix the flaw. First the developers should patch the bug and update every node. After that, the attackers would transfer the money back safely. Blockstream replied on-chain as well and pointed the other side to security@blockstream.com.
Doubts about that self-description came from the industry. Ledger CTO Charles Guillemet noted publicly that serious security researchers usually report a vulnerability before moving reserves of this size. The objection lands. Anyone who drains 95% of a reserve and paralyzes a network is negotiating from a position of strength. A regular disclosure would never have created it.
The incident joins an expensive year of hacks
The scale also stands out in the annual comparison. According to TRM Labs, hack losses in 2026 added up to roughly USD 1.2 billion before the Liquid outflow. Those losses came from 276 incidents. Until then, the third-largest single case of the year was the attack on Coldcard hardware wallets in late July. That drained roughly USD 116 million in about 1,816 BTC from more than 5,200 addresses. In late August, an exploit also hit the Cronos lending platform Tectonic. The attacker inflated the price of the Tonic token roughly 300-fold within 20 minutes. Because of that, he could borrow more than USD 74 million. In the end, he took around USD 6 million net. The Cronos validators then froze trading.








