The Liquid Network disclosed the incident after approximately 4,000 BTC, then valued at about $320 million, left a wallet controlled by its federation.
Liquid said the withdrawal used SideSwap’s Peg-Out Authorization Key, or PAK, but maintained that neither this key nor its other authorization keys had been compromised. It described the recipients as purported white-hat hackers and said Blockstream was attempting to contact them through signed messages recorded on Bitcoin.
The network disabled its bridge nodes, preventing new transactions from being submitted. Exchanges were also asked to suspend L-BTC deposits and withdrawals while federation members investigated the incident.
A subsequent statement from SideSwap described how its peg-out service received the L-BTC and released the corresponding Bitcoin.
Preliminary incident sequence
| 14:05 UTC | A customer submits 4,000 L-BTC to SideSwap’s peg-out service. |
| Authorization | SideSwap says the request carries valid peg-out authorization. |
| Redemption | The submitted L-BTC is burned as part of the peg-out process. |
| 14:28 UTC | The Liquid Federation releases approximately 3,996 BTC. |
| Preliminary explanation | SideSwap says Blockstream traced the deposited L-BTC to an Elements software bug. |
Blockstream has not yet published a complete technical postmortem identifying the vulnerability and confirming every stage of this account. SideSwap’s explanation should therefore be treated as preliminary.
Liquid’s design separates the validity of an asset from the authorization of its destination. Under Blockstream’s documentation for L-BTC, each unit should be backed by an equivalent amount of Bitcoin held by the federation. A normal peg-out burns the L-BTC before releasing the corresponding BTC.
A PAK performs a narrower job. It authorizes the Bitcoin address that may receive a peg-out; it is not the mechanism that determines whether the redeemed L-BTC was properly issued.
The federation’s multisignature arrangement requires 11 of 15 functionaries to authorize spending from the Bitcoin wallet. If SideSwap’s account is confirmed, those signatures could have been cryptographically valid even though an earlier validation failure allowed improperly created L-BTC to reach the peg-out process.
A secure PAK would therefore not prevent a withdrawal if the network had already accepted the disputed L-BTC as valid. The authorization could approve the intended destination while the asset-validation process failed to identify L-BTC that should not have existed.
What each security control checks
| Elements validation | Whether the L-BTC and its transaction comply with the sidechain’s rules. |
| SideSwap PAK | Whether the proposed Bitcoin destination is authorized for the peg-out. |
| Federation signatures | Whether the required functionary threshold approves the Bitcoin payment. |
If SideSwap’s account is confirmed, the supply controls failed to reject L-BTC created without a corresponding Bitcoin deposit. That would explain how secure authorization keys and valid federation signatures could still produce a loss of real reserves.
The incident concerns Liquid, a federated sidechain built with Elements. It does not indicate that Bitcoin’s consensus rules were broken or that an attacker bypassed the security of the Bitcoin network.
Bitcoin processed a transaction carrying the signatures needed to spend from the federation wallet. The apparent failure occurred earlier, within the system responsible for issuing, validating and redeeming L-BTC.
Calling the event a “Bitcoin hack” would therefore obscure where the problem occurred. The transferred BTC was real, but SideSwap’s preliminary explanation points to Liquid’s sidechain software and peg controls.
Galaxy Digital research head Alex Thorn traced the conversation between Blockstream and the holders of the withdrawn Bitcoin through OP_RETURN messages and PGP-encrypted communications.
💧 LIQUID WHITE HATS SAY THEY’LL RETURN ‘MOST’ OF 4000 BTC ONCE LIQUID NETWORK BUG IS PATCHED
the hackers have been conversing with blockstream via OP_RETURN messages and PGP encrypted text
– block 965,822 blockstream address sent 1,000 sat with “Please contact security at… pic.twitter.com/VP8IkOvftl
— Alex Thorn (@intangiblecoins) September 7, 2026
Thorn reported that Blockstream sent 1,000 satoshis at Bitcoin block 965,822 with a message asking the recipients to contact its security team. At block 965,865, Blockstream sent an encrypted message carrying a signature that could be checked against its published PGP key.
The recipients replied at block 965,869, asking whether they could send most of the Bitcoin to the federation’s address. A later message at block 965,875 said the vulnerability should be fixed and every affected node patched before the money was returned. Technical information was reportedly encrypted for Blockstream, meaning its contents are not publicly available.
Readers can follow transactions involving the stated return address on Mempool.
The exchange provides stronger evidence that Blockstream is communicating with the recipients, but it does not confirm their identities or establish that they are legitimate security researchers. It also narrows the proposed recovery: the messages refer to returning “most” of the funds, without specifying how much may be retained.
No completed return has been publicly confirmed as of time of writing. The white-hat description should therefore remain qualified until the Bitcoin is received and Liquid or Blockstream verifies the outcome.
Liquid said other issued assets, including USDT, DePix and tokenized real-world assets, were unaffected by the security incident. In this context, “unaffected” means that Liquid had not identified those assets as having been improperly created or withdrawn.
The operational disruption was broader. Disabling the bridge nodes effectively paused the sidechain, while exchanges suspended or prepared to suspend L-BTC transfers. An asset can remain intact on the ledger while its owner temporarily loses the ability to move or redeem it.
This distinction matters for users assessing the effect of the incident: asset integrity and asset availability are separate risks.

The event follows a separate Bitcoin security incident involving affected Coldcard devices. The cases are unrelated, but they illustrate failures at different layers. Coldcard’s problem concerned wallet transaction handling, while Liquid’s preliminary account concerns the validation and redemption of a Bitcoin-backed sidechain asset.
Restoring transaction processing would not resolve every question raised by the withdrawal. Before users can independently assess a restart, Liquid should provide enough information to verify the following points:
A software patch would address the vulnerability, but it would not alone prove that Liquid’s accounting had been restored. Users also need evidence that the remaining Bitcoin reserves cover all legitimate L-BTC still in circulation.
The remaining question is why the disputed L-BTC passed the checks that preceded the federation’s signatures. Until Blockstream identifies the vulnerability, reconciles legitimate outstanding L-BTC with the remaining reserves and confirms whether the approximately 3,996 BTC was returned, the incident’s technical and financial outcome cannot be independently assessed.
This article is for informational purposes and does not constitute financial, legal or investment advice.
The post Liquid Says No Keys Were Stolen – How Did 4,000 BTC Leave? appeared first on Coindoo.