Key TakeawaysOn Sunday, September 6, 2026, self described whitehat hackers withdrew about 4,000 Bitcoin (BTC), worth roughly $320 million, from the federation wallet backing Blockstream's Liquid NetwoKey TakeawaysOn Sunday, September 6, 2026, self described whitehat hackers withdrew about 4,000 Bitcoin (BTC), worth roughly $320 million, from the federation wallet backing Blockstream's Liquid Netwo

Liquid Network Hack Explained: $320 Million in Bitcoin Drained, 85% Returned, and the $47 Million Question

Key Takeaways
On Sunday, September 6, 2026, self described whitehat hackers withdrew about 4,000 Bitcoin (BTC), worth roughly $320 million, from the federation wallet backing Blockstream's Liquid Network, about 95% of the sidechain's reserves of around 4,200 BTC.
The attackers exploited a bug in Elements, the open source software underlying Liquid, to create L-BTC that was not backed by real Bitcoin, then pegged it out through SideSwap's peg out authorization path. Blockstream says the key itself was not compromised and no other Liquid assets were affected.
The negotiation happened entirely on the Bitcoin blockchain: the group wrote "we are whitehats. contact us on chain" into a transaction, demanded every bridge node be patched first, and Blockstream answered with PGP signed messages confirming the fix.
On Monday, September 7, the group returned exactly 3,400 BTC, about $268 million, and kept 598.5 BTC worth roughly $47 million, an apparent self awarded bounty that Blockstream is still negotiating over.
Liquid remains paused with a chain split to unwind, bridge nodes disabled and L-BTC deposits and withdrawals halted at exchanges. Bitcoin held on the main chain is unaffected, and BTC barely reacted, trading near $78,500.
 
 

What Liquid Is and Why the Peg Matters

Liquid Network is a Bitcoin sidechain launched by Blockstream in 2018 and operated by a federation of exchanges and institutions. Users lock BTC on the main chain and receive L-BTC on Liquid, where transactions settle in about a minute with confidential amounts, which is why it became a preferred settlement rail between trading venues and a home for assets such as Tether's USDT. The entire system rests on a promise: every L-BTC in circulation is backed one to one by real Bitcoin held in the federation wallet, and a peg out destroys L-BTC on the sidechain while releasing the matching BTC on the main chain.
That promise is what broke on Sunday. Blockstream's incident notice said hackers claiming to be whitehats took about 4,000 BTC from the federation wallet, roughly 95% of reserves that stood near 4,200 BTC beforehand. The coins left through SideSwap's peg out authorization key, one of the keys that can release funds, though Blockstream stressed that the key was not compromised and neither were any others. The root cause, according to SideSwap and subsequent analysis, was a bug in Elements, the blockchain software powering Liquid, that allowed the creation of L-BTC without backing. In effect, the attackers minted counterfeit sidechain Bitcoin and redeemed it for the real thing.
 
 
 

A Negotiation Written Into the Blockchain

What followed was unlike any security disclosure in the industry's history. Rather than emails or a bug bounty portal, the actors communicated through messages embedded in Bitcoin transactions using OP_RETURN. One of the earliest read "we are whitehats. contact us on chain." At Bitcoin block 965,875 they stated they would return the funds, but only after the vulnerability was fixed and the patch applied to every relevant node, a condition Blockstream acknowledged in a PGP signed message of its own. Blockstream then confirmed all bridge nodes had been patched and the funds were safe to send back.
The return came on Monday, September 7. A transaction confirmed at 15:31 UTC sent the federation address 1,000 satoshis along with a PGP encrypted message whose contents remain private. Thirty eight minutes later, in block 965,950, exactly 3,400 BTC arrived back in the federation wallet, worth about $268 million at prevailing prices. The remaining 598.5 BTC, roughly $47 million and about 15% of the haul, stayed with the actors. Samson Mow, the JAN3 chief executive and former Blockstream strategy chief who has been posting updates on the incident, said Blockstream continues to engage with the group over the balance. Whether that sum is a demanded bounty, a unilateral fee, or something still to be returned has not been made public.
 
 

Whitehats, or Something Else?

The label is contested. Liquid itself has carefully referred to "purported" whitehats, and Ledger's chief technology officer Charles Guillemet questioned the take first and negotiate later approach, before allowing that the actors could be inexperienced researchers rather than criminals. Genuine whitehat disclosure normally involves reporting a flaw privately and being rewarded after a fix, not draining 95% of a system's reserves and setting terms in public. The counterargument is pragmatic: the group demonstrated the bug, forced a rapid patch, returned the overwhelming majority of the funds, and never attempted to launder anything. The crypto industry has seen this ambiguous middle ground before, and the $47 million now sitting outside Blockstream's control will decide which reading history settles on.
 
 

What Is Still Broken

The return eased the collateral crisis but did not end it. Liquid remains paused, bridge nodes are disabled, and L-BTC deposits and withdrawals at centralized exchanges are halted. During the pause a chain split emerged that operators must resolve before a coordinated restart, and the federation has to demonstrate that L-BTC is once again fully backed, either by recovering the outstanding coins, funding the shortfall, or documenting a plan for it. Blockstream says updated software has been deployed and federation members are preparing the restart. Until an official statement confirms peg ins and peg outs have resumed, the peg is operating under supervision rather than restored.
Notably, the Bitcoin price barely flinched, holding near $78,500 through the episode. The market appears to have drawn the right distinction: this was a failure in a federated sidechain's software, not in Bitcoin, and main chain BTC was never at risk. It does, however, land in a bruising year for security following the Coldcard firmware exploit and the Trezor and SafePal data leak
 

What It Means for Traders on MEXC

For most holders the practical impact is zero. Bitcoin on the main chain, including balances held on MEXC, is unaffected; only L-BTC on the paused sidechain is frozen, and anyone with funds there simply has to wait for the restart. The incident is a reminder that wrapped and pegged versions of Bitcoin carry their own trust assumptions, from federations to bridge software, that native BTC does not. Traders can follow the market on BTC/USDT as the restart news develops.
 
Disclaimer: This content is for educational and reference purposes only and does not constitute any investment advice. Digital asset investments carry high risk. Please evaluate carefully and assume full responsibility for your own decisions.
Market Opportunity
4 Logo
4 Price(4)
--
----
USD
4 (4) Live Price Chart

The articles shared on this page are sourced from public platforms and are provided for reference only. They do not represent the position or views of MEXC. All rights belong to OoJae. If you believe any content infringes upon the rights of a third party, please contact service@support.mexc.com for prompt removal. MEXC does not guarantee the accuracy, completeness, or timeliness of any content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be interpreted as a recommendation or endorsement by MEXC. For expert insights and in-depth analysis, visit MEXC Learn.