TLDR
- Purported white-hat hackers withdrew around 4,000 BTC worth $320 million from Liquid Network’s federation wallet
- The exploit came from a software bug in Elements, the open-source software that powers Liquid, not a compromised key
- Funds moved out through SideSwap, a legitimate trading platform, making detection harder
- The hackers are communicating with Blockstream via on-chain Bitcoin messages and say they will return funds once the bug is patched
- Other assets on the network including USDT were not affected
Liquid Network, a Bitcoin sidechain used by exchanges to settle transactions faster, has paused all operations after losing roughly $320 million in Bitcoin to what appear to be white-hat hackers.
We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.
What we know so far is that the funds…
— Liquid Network 🌊 (@Liquid_BTC) September 6, 2026
The incident happened on Sunday, September 7. Actors claiming to be ethical hackers withdrew about 4,000 of the 4,200 Bitcoin held in Liquid’s federation wallet. That is around 95% of the total reserve.
What Is Liquid Network?
Liquid Network was launched in 2018 by Blockstream. It is a sidechain built on top of Bitcoin, designed to help exchanges settle trades faster than the main Bitcoin blockchain allows.
JUST IN: 4,000 Bitcoin worth $320 million withdrawn following Liquid Network hack.
The hacker is now communicating with network maintainers through on-chain Bitcoin transactions & intends to return the $BTC after the vulnerability is fixed. pic.twitter.com/OXpS1X3oqK
— Watcher.Guru (@WatcherGuru) September 7, 2026
The network issues a token called L-BTC, backed one-to-one by real Bitcoin held in a federation wallet. The federation includes more than 80 exchanges, infrastructure companies, and asset managers.
When nearly all of that reserve is drained, it raises questions about the safety of the entire settlement model.
How the Exploit Happened
This incident did not involve a stolen password or compromised private key, which has been the cause of most crypto hacks this year.
Instead, a software bug in Elements, the open-source code that runs Liquid, created some Bitcoin that was not real. The funds then moved out through SideSwap, a normal and approved trading platform on the network.
SideSwap said its Peg-out Authorization Key was not compromised. It said it could not tell which coins came from the bug and which were legitimate, so it processed them all the same.
Security specialists say the flaw sits at the node level in Liquid’s transaction software, not in its hardware or key management systems.
The actors have been sending on-chain Bitcoin messages to Blockstream. One message read: “Please fix the bug first. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”
Galaxy Digital research head Alex Thorn said the hackers also sent encrypted technical details to Blockstream to help them locate and fix the vulnerability.
At the time of writing, the funds had not been returned and the network remained paused. Bridge nodes were disabled, and exchanges had halted or were preparing to halt L-BTC deposits and withdrawals.
Liquid confirmed that other assets on the network, including USDT, DePix, and real-world assets, were not affected.
The incident follows a $6 million drain last week from a lending platform tied to Crypto.com and an earlier breach involving the Coldcard hardware wallet. Liquid has not given a timeline for when the network will reopen.







