
Liquid disabled bridge nodes and exchanges paused L-BTC activity. This occurred after nearly 4,000 BTC left its federation reserves through a peg-out linked to an Elements software flaw.
Liquid Network paused new transaction activity on Sept. 6 after nearly 4,000 BTC left the federation wallet in an incident that initially raised concerns over a compromise of the Bitcoin sidechain’s peg mechanism. The network said the funds were withdrawn through the SideSwap Peg-out Authorization Key (PAK). However, the key itself and other federation keys had not been compromised.
The latest explanation points to a different failure. SideSwap said the L-BTC used in the transaction had been created through a vulnerability in Elements, the open-source software underlying Liquid. This happened rather than through a compromise of SideSwap’s systems or PAK. That explanation has not yet been accompanied by a detailed public technical post-mortem identifying the exact bug.
Liquid’s official account described the actors behind the withdrawal as “purported white-hat hackers” and said Blockstream was attempting to contact them through a signed on-chain message. The designation has not been independently established.
What Happened in The Liquid Network Security Incident
On the Liquid sidechain, a peg-out transaction requested the release of 3,996.01834922 L-BTC. Blockchain records subsequently showed the corresponding Bitcoin payment on the Bitcoin mainnet.
The transaction was confirmed in Bitcoin block 965,783 at 14:28:56 UTC on Sept. 6, according to on-chain analysis. The Bitcoin transaction identified by researchers is 8db751a650ae2f12006b7e8c69a75e4df360e8afd6b9e05ae0b9fa6458a7b140, with the principal peg-out output sending 3,996.01834922 BTC to bc1qgslsydz56d0ed6827hdemfmk5w2f6ldyc6wt7p.
A subsequent transaction consolidated most of the transferred bitcoin into another address and included an OP_RETURN message claiming: “we are whitehats. contact us on chain.” That message establishes what the transaction author claimed. However, it does not establish the identity or intentions of the party behind it.
Liquid said its federation wallet held roughly 4,200 BTC before the incident. The reported withdrawal therefore represented approximately 95% of the Bitcoin backing associated with the network at the time. Reuters independently reported the approximately $320 million withdrawal and the resulting halt of new Liquid transactions.
The PAK Was Used, But The Key Was Not Reported Compromised
The distinction between a stolen authorization key and a software-level failure is central to understanding the incident.
Liquid’s architecture uses a federation to manage the Bitcoin backing L-BTC.
Meanwhile, Bitcoin held by the federation is protected through an 11-of-15 multisignature structure.
Under the normal process, L-BTC is burned on Liquid and the federation releases an equivalent amount of BTC to an authorized destination. Blockstream’s documentation says the PAK system is intended to prevent even compromised functionaries from redirecting Bitcoin directly to an attacker-controlled address.
Liquid’s incident statement therefore creates an important technical distinction. The SideSwap PAK was apparently accepted by the system. However, Liquid said the key itself was not compromised. SideSwap separately said its peg-out service processed a customer request normally and that its own authorization keys and systems were not breached.
This means the available evidence does not support describing the event simply as an 11-of-15 multisig key theft.
SideSwap Points to An Elements Software Flaw
SideSwap’s account of the incident changes the likely failure point.
According to reporting on SideSwap’s official statement, a customer submitted approximately 4,000 L-BTC to its peg-out service at about 14:05 UTC. SideSwap processed the request through its ordinary mechanism. After that, the Liquid Federation released approximately 3,996 BTC on the Bitcoin blockchain. SideSwap said Blockstream subsequently determined that the L-BTC had been created through a bug in Elements.
That explanation remains an important but developing finding. Neither the available Liquid statement nor Blockstream’s public documentation reviewed for this article provides a detailed description of the Elements vulnerability. This includes the precise validation failure, when it was introduced, how it was triggered or whether other affected transactions exist.
A preliminary theory circulating from industry participants has focused on Liquid’s transaction-validation or confidential-transaction implementation. However, that has not been established as the root cause and should not be treated as confirmed.
Why the Incident Matters Beyond Liquid
The incident exposes a different risk from a conventional custody breach.
Liquid is designed as a Bitcoin sidechain for faster settlement and confidential asset issuance. Users move BTC into the system and receive L-BTC on a one-to-one basis. The federation is responsible for releasing BTC when L-BTC is pegged out.
If SideSwap’s explanation is correct, the immediate problem was not that an attacker obtained the federation’s private keys. Instead, the system appears to have accepted L-BTC that should not have existed and then processed a legitimate-looking redemption.
That distinction matters because fixing a compromised key and fixing an issuance or consensus flaw are fundamentally different security tasks. A key compromise can require replacing credentials and moving reserves. In contrast, a protocol-level flaw can require identifying every affected transaction, determining whether additional unbacked L-BTC exists and establishing how the peg can be reconciled safely.
The incident also explains why Liquid halted the network rather than allowing normal activity to continue. Liquid said bridge nodes were temporarily disabled and that exchanges had been notified to pause L-BTC deposits and withdrawals.
What Users and Exchanges Should Monitor Next
The immediate issue is no longer simply whether the approximately 4,000 BTC moved. The key questions are how the L-BTC was created, whether additional malformed issuance occurred, what happens to the transferred BTC, and how Liquid restores full confidence in the peg.
The network has not publicly provided a final root-cause analysis in the sources reviewed for this article. The fate of the transferred BTC is also unresolved. The “white-hat” message is evidence of a claim made by the party controlling the relevant transaction, not proof that the funds will be returned.
For exchanges and market participants, the clearest operational signal will be the restoration of L-BTC deposits and withdrawals. A restart without a published explanation of the Elements issue would leave important questions about the integrity of the peg unanswered.
The incident also warrants monitoring of the Liquid federation’s reserve balance and related Bitcoin transactions. On-chain evidence provides a direct way to distinguish recovered funds, moved funds and remaining federation reserves without relying solely on social-media claims.
The underlying Bitcoin network was not itself compromised. The confirmed transactions occurred on Bitcoin’s normal consensus layer. The unresolved failure concerns Liquid’s sidechain, its issuance rules and the process by which L-BTC was redeemed for Bitcoin.

















































































































































