The Liquid Network, a prominent Bitcoin sidechain, experienced a significant security event on September 6, 2026, when an actor identified as a whitehat hacker successfully drained approximately 3,996 BTC from the federation’s reserves. The incident, which involved a sophisticated exploit of the network’s underlying software, has led to a temporary suspension of several core services as developers work to address the vulnerability. The value of the assets involved is estimated at approximately $320 million, marking one of the most substantial security interventions in the history of Bitcoin sidechains.
According to reports from Blockstream and the trading platform SideSwap, the event was triggered by an abnormal peg-out request. A peg-out is a fundamental process within the Liquid Network where users burn Liquid Bitcoin (L-BTC) on the sidechain to trigger the release of an equivalent amount of native Bitcoin from a reserve managed by a federation of functionaries. In this instance, the actor submitted 4,000 L-BTC to SideSwap’s peg-out service, initiating a chain of events that exposed a critical flaw in the system’s architecture.
Key Developments in the Liquid Network Incident
- A whitehat hacker withdrew 3,996 BTC from the Liquid Federation reserve using an abnormal peg-out request.
- The exploit utilized a vulnerability in Elements, the open-source software platform that serves as the foundation for the Liquid Network.
- The transaction was authorized by 11 of the 15 Liquid Federation functionaries, despite the underlying L-BTC lacking proper Bitcoin backing.
- The actor has pledged to return the majority of the funds once the software bug is fixed and all network nodes are patched.
The Mechanics of the Peg-Out Exploit
The security breach centered on the use of SideSwap’s valid Peg-out Authorization Key (PAK). This key is a critical component of the Liquid Network’s security model, designed to ensure that only authorized entities can initiate the withdrawal of Bitcoin from the federation’s multisig wallet. During the incident on September 6, the actor managed to leverage this authorization to facilitate a massive withdrawal that appeared legitimate to the automated systems governing the network.
A particularly notable aspect of the event was the involvement of the Liquid Federation functionaries. The Liquid Network operates on a federated model where a group of geographically dispersed entities, known as functionaries, are responsible for signing transactions and maintaining the integrity of the sidechain. In this case, 11 out of the 15 federation functionaries signed the withdrawal request. This level of consensus typically indicates a valid and verified transaction, yet the underlying assets were later found to be problematic.
Investigations conducted by Blockstream and SideSwap revealed that the root cause was not a failure of the federation members themselves, but rather a flaw within the Elements software. Elements is the core technology that enables the creation of sidechains like Liquid. The vulnerability allowed for the creation of L-BTC without the necessary corresponding Bitcoin backing. Essentially, the system was tricked into recognizing L-BTC that did not represent actual Bitcoin held in reserve, which was then used to “peg-out” and claim real BTC from the federation.
Immediate Response and Service Suspensions
Upon discovery of the abnormal withdrawal, the Liquid Federation and associated service providers took immediate action to contain the situation. Liquid disabled its bridge nodes, effectively halting the movement of assets between the Bitcoin mainnet and the Liquid sidechain. This measure was necessary to prevent further unauthorized withdrawals while the technical team analyzed the extent of the vulnerability.
SideSwap, a primary interface for users interacting with the Liquid Network, also suspended its operations. This included the cessation of swaps, peg-ins, and peg-outs. These suspensions remain in place as the community awaits a comprehensive fix for the Elements software. The coordinated shutdown of these services reflects the severity of the flaw and the priority placed on protecting the remaining assets within the federation’s reserve.
The actor responsible for the drain quickly clarified their intentions through on-chain communication. Using OP_RETURN messages—a method of embedding data within a Bitcoin transaction—the individual identified themselves as a “whitehat” hacker. In the context of cybersecurity, a whitehat is an actor who exploits vulnerabilities to highlight security weaknesses rather than for personal gain. The hacker stated that they intend to return “most” of the funds, but only after specific conditions are met regarding the network’s security.
Contextualizing the Elements Software Vulnerability
The Liquid Network is designed to maintain a strict 1:1 peg between BTC and L-BTC, providing users with faster transactions and enhanced privacy features compared to the Bitcoin mainnet. For this peg to remain credible, every unit of L-BTC in circulation must be backed by a unit of BTC held by the federation. The discovery that the Elements software allowed for the creation of unbacked L-BTC strikes at the core of this trust model.
This incident has drawn attention from various industry experts and entities, including Bitslab and Alex Thorn of Galaxy Digital, as the community evaluates the implications for federated sidechain models. While the use of a federation is intended to provide a layer of human and institutional oversight, the fact that 11 signers approved the transaction suggests that the automated verification processes they rely on were successfully bypassed by the software bug.
The reliance on Elements as an open-source foundation means that any vulnerability discovered within it could potentially affect other projects utilizing the same codebase. However, the immediate focus remains on the Liquid Network and the restoration of its peg-out mechanisms. The incident highlights the ongoing challenges of maintaining secure bridges between different blockchain layers, even when those layers are built on established technology.
What Happens Next
The path to resolution for the Liquid Network involves several critical steps. First, the developers at Blockstream and the broader Elements community must finalize a patch that addresses the flaw allowing for unbacked L-BTC creation. This patch must be thoroughly vetted to ensure it does not introduce new vulnerabilities or unintended side effects.
Once the fix is ready, every node operator within the Liquid Network will need to update their software. The whitehat hacker has explicitly stated that the return of the 3,996 BTC is contingent upon the bug being fixed and the entire network being patched. This requirement places the timeline for the return of funds in the hands of the network’s participants and their ability to coordinate a rapid upgrade.
Following the successful deployment of the patch and the return of the funds, the Liquid Federation will likely conduct a comprehensive post-mortem analysis. This process will be essential for restoring user confidence and ensuring that the PAK and federation signing processes are reinforced against similar exploits in the future. For now, the network remains in a state of partial suspension as the technical recovery continues.
