The Liquid Network, a Bitcoin sidechain built by Blockstream, faced a major security crisis after nearly 4,000 BTC, worth about $320 million, was pulled from the Liquid Federation wallet. News of the withdrawal spread fast across the crypto industry since the sum taken was almost 95% of the federation’s total reserves. The people who pulled it off called themselves “white hat” hackers, but the whole thing still raised questions about how well blockchain networks manage their security and handle vulnerabilities.
Blockstream and other market participants said the problem started with a software bug in Elements, the backbone technology behind Liquid. The SideSwap Peg-out Authorization Key (PAK) was not breached, and other assets on Liquid, such as USDT, DePix, and some real world assets (RWAs), stayed safe. In response, bridge nodes were switched off, temporarily putting the entire Liquid sidechain on hold as federation members worked to address the problem.
Nearly 4,000 BTC Withdrawn Following Software Vulnerability
It began on September 6 at 14:05 UTC when someone sent about 4,000 L-BTC into SideSwap peg-out channel. Following protocol, SideSwap burned the L-BTC and started down the usual path of withdrawal authorization. By 14:28 UTC, the Liquid Federation had transferred 3,996 BTC, valued around $320 million, to a specific Bitcoin address.
This one transaction reduced Liquid Federation’s reserves from roughly 4,200 BTC down to just 207 BTC. Blockstream later confirmed the L-BTC involved in this incident has essentially been “conjured out of thin air” because of the vulnerability in Elements, which meant those tokens were never actually backed by real Bitcoin.
Blockstream also clarified there was no breach of SideSwap’s systems or keys. Plus, anyone holding assets in their own self managed, non custodial wallets remained unaffected. And since these transactions were finalized on the Bitcoin blockchain, there was no way to undo them.
As a safety measure, exchanges stopped deposits and withdrawals of LBTC, while SideSwap suspended all exchanges and operations involving peg-ins and peg-outs until the network could safely get back online.
White Hat Claims and On-Chain Communication with Blockstream
Right after the withdrawal, the people behind it left a message in the blockchain via OP_RETURN transactions, saying, “we are white hats. Contact us on chain”. They claimed they stepped in to keep malicious actors from taking advantage of the vulnerability themselves.
A series of on chain and PGP encrypted messages between the group and Blockstream continued. In Block 965,822, a Blockstream address sent 1,000 satoshis with a request for the group to contact their security team via official channels. The hackers replied in Block 965,865 with an encrypted message and a detached PGP signature, verifiable with Blockstream’s public key.
There were more exchanges. In block 965,869, the group sent another 1,000 satoshis to the Liquid Federation wallet with this message: “Can we return most of the funds to the federation address”. By Block 965,875, they added: “Please fix the vulnerability first. As of the latest commit version, there is still risk on chain. Please ensure every node completes the patch update. Once the fix is confirmed, we will securely transfer the funds back”.
According to Galaxy Research’s director, Alex Thorn, most of the 4,000 BTC could be returned once the vulnerability is fixed. Still, not everyone was convinced. Ledger’s Chief Technology Officer and other leaders in the industry argued this was not how responsible disclosure works, they said you are supposed to report bugs before making such huge moves with other people’s funds.
For now, the Liquid Network remains halted, highlighting the need for strong software security and showing just how tough it is to react to vulnerabilities in blockchain systems. Federation members are working to fix the issue, and the crypto industry is watching closely to see if those funds really make their way back as promised.


