Roughly 4,000 bitcoin worth about $320 million left the wallet backing Blockstream’s Liquid Network on Saturday, and the people who took it are asking how to give it back.
The withdrawal landed in Bitcoin block 965,783 at 14:28:56 UTC on 6 September, sending approximately 3,996 BTC to a single address. Liquid’s federation wallet had held around 4,200 BTC before the transaction. It now holds a little over 200.
That is close to 95% of every bitcoin ever locked into the sidechain, gone in one movement.
Blockstream paused the network within hours and exchanges suspended L-BTC deposits and withdrawals. The coins have not moved since.
The attacker attached a note
What separates this from a conventional theft is what happened next.
The person who took the funds attached a message to a Bitcoin transaction identifying themselves as a white hat and inviting Blockstream to make contact.
Liquid confirmed it was working to contact the parties responsible through an on-chain signed message. In a public exchange relayed on 7 September, the attacker asked whether pushing “most” of the funds to the federation address would be acceptable, conditional on Blockstream patching the underlying vulnerability first.
Blockstream has not confirmed the white-hat characterisation. No agreement has been announced, and the funds remain in the attacker’s address.
The word “most” is doing noticeable work in that offer.
The keys were not compromised
The mechanism matters because it rules out the obvious explanation.
Liquid runs as a federated sidechain, launched by Blockstream in 2018 and overseen by more than 80 exchanges and infrastructure firms. Users lock real bitcoin on the main chain and receive L-BTC on the sidechain, which settles faster and supports confidential transactions. The federation holds the locked bitcoin and controls withdrawals through Peg-out Authorization Keys.
SideSwap, a Liquid-native trading and peg service, holds one of those keys. The 4,000 BTC left through SideSwap’s authorisation pathway.
Both Liquid and SideSwap have stated that the key was not compromised, and that no other keys were either.
Blockstream has attributed the incident to a software bug in Elements, the codebase Liquid runs on. According to reporting on the sequence, a bug-created batch of 4,000 L-BTC passed SideSwap’s authorisation checks, prompting the federation to release the corresponding bitcoin.
In other words, freshly minted and illegitimate L-BTC was converted into real bitcoin through an entirely valid authorisation process.
Liquid has not published the root vulnerability.
The federation model is the exposure
This is the uncomfortable part, and it applies well beyond one sidechain.
Bitcoin’s base layer was not touched. Its proof-of-work consensus was unaffected, and BTC traded around $79,500 through the incident, close to flat.
Liquid does not use proof-of-work. It uses a fixed group of signers who collectively control the reserve, which is what makes it fast enough for exchanges to settle between each other. The trade-off is that the security of every L-BTC depends on that group’s software behaving correctly rather than on mining.
The incident demonstrated that valid keys and multiple signers can approve a withdrawal for which no underlying bitcoin exists. Nothing was stolen in the sense of a break-in. The system authorised the transfer according to its own rules, because the rules had been corrupted upstream by a bug in how L-BTC could be created.
USDT and other assets issued on Liquid were unaffected. Only the bitcoin backing was drained.
Recovery requires more than a refund
Even if the attacker returns everything, the network cannot simply restart.
Three things have to happen. Every affected node needs patching, the funds need to come back, and Blockstream needs to prove that reserves once again match legitimate outstanding L-BTC one for one.
That last step is the hard one. The bug allowed L-BTC to be minted without backing, which means the federation has to establish how much L-BTC in circulation is legitimate before it can claim the reserve is whole. A partial return would leave a permanent shortfall against tokens that users still hold.
No timeline has been given for resuming operations.
What it means for holders
The practical lesson is narrow and worth stating plainly.
Anyone holding L-BTC was relying on a shared reserve secured by code they could not audit. That is true of every wrapped asset, every bridge and every custodial arrangement in crypto. A protocol-level bug in a pooled reserve is a risk no individual holder can inspect their way out of.
Bitcoin held in self-custody was never exposed to any of this.
The incident also lands during a rough stretch for the sector. The Coldcard exploit has drained more than $130 million from hardware wallets whose seeds were generated with predictable randomness, and the attacker moved another $7.7 million over the weekend. Chile’s Orionx shut down last week after an audit found $7 million missing from customer wallets.
For now, roughly $320 million sits in a single address, and Liquid’s return depends on the goodwill of whoever controls it.
FAQ
Was Bitcoin itself hacked?
No. Bitcoin’s base-layer consensus was unaffected. The exploit targeted Liquid’s federation-controlled peg-out mechanism, a separate system built on top of Bitcoin.
How did the funds leave if no keys were stolen?
Blockstream attributes it to a software bug in Elements, Liquid’s codebase, which allowed illegitimate L-BTC to be created. That passed SideSwap’s valid authorisation checks, prompting the federation to release real bitcoin against it.
Will the bitcoin be returned?
Unconfirmed. The attacker has offered to return “most” of the funds once the vulnerability is patched, but no agreement has been announced and the coins remain in their address.
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any investment decisions.


















