Bitcoin didn’t get hacked on Sunday. A bitcoin IOU did. Attackers found a bug in the software behind Blockstream’s Liquid Network, conjured L-BTC out of nothing, and swapped it for real bitcoin through the sidechain’s own exit. In 23 minutes, the federation that backs L-BTC paid out almost everything it held.
Bitcoin itself barely noticed, holding a $78,500–$80,500 range and trading near $79,800. Anyone holding L-BTC noticed a lot. This is the clearest lesson of the year on the difference between native BTC and pegged BTC.
Key facts
- On September 6, 2026, a bug in Elements, the software behind Blockstream’s Liquid sidechain, let attackers create invalid L-BTC out of nothing.
- 4,000 L-BTC were sent to SideSwap’s peg-out service at 14:05 UTC; at 14:28 UTC the Liquid federation paid out 3,996 BTC, about $320 million.
- That payout was roughly 95% of the ~4,200 BTC in the federation wallet; Bitcoin Magazine puts the total withdrawn at 4,019.4 BTC.
- Blockstream said no peg-out authorization keys were compromised; the forged transaction looked valid, so the federation’s hardware security modules signed it automatically.
- Liquid paused its bridge nodes and exchanges halted L-BTC deposits and withdrawals; USDT on Liquid, DePix and tokenized real-world assets were not affected.
- The attackers left on-chain messages calling themselves white hats and demanded that every node be patched before any return of funds.
What happened to the Liquid Network on September 6?
On September 6, 2026, attackers exploited a flaw in Elements, the software that runs the Liquid sidechain, to create L-BTC that should never have existed. They sent 4,000 of it to SideSwap’s peg-out service and received 3,996 real BTC from the federation’s reserve — about $320 million — within 23 minutes.
According to Bitcoin.com News, the L-BTC arrived at SideSwap at 14:05 UTC, and the federation paid out at 14:28 UTC. SideSwap processed it as a normal peg-out order: burn the L-BTC on Liquid, release BTC on the main chain. It later said Blockstream had established that the L-BTC in that order was created through the Elements bug.
The flaw sat in how Elements caches range-proof verification — the check that confirms a hidden amount in a confidential transaction is valid. With that check fooled, the network accepted coins that had no backing.
CoinDesk reported that the federation lost roughly 4,000 of about 4,200 BTC. Crypto Times calls it the largest publicly reported crypto incident of 2026 so far.
How did fake L-BTC get past an 11-of-15 federation?
Nobody had to steal a key. Liquid peg-outs need 11 of 15 federation signers, and those signers run hardware security modules that approve withdrawals backed by valid L-BTC. The consensus bug made forged L-BTC look valid, so the modules signed automatically, exactly as designed.
Blockstream stressed that SideSwap’s peg-out authorization key “was not compromised, nor were any others.” SideSwap is a federation member with a peg-out key, and it simply couldn’t tell bug-created L-BTC from real L-BTC. Neither could anyone else.
That’s the uncomfortable part. Multisig protects against a stolen key or a rogue signer. It does nothing when the software that defines “valid” is wrong. Eleven honest signers agreeing on a false premise still produce a valid-looking signature.
Multisig guards the keys. It can’t guard the rules.
Are the Liquid attackers really white hats?
As of Sunday, that’s only their claim. The attackers posted on-chain messages including “we are whitehats. contact us on chain” and said funds would come back only after every node was patched. An on-chain reply attributed to Blockstream asked them to contact its security team. No return had been reported.
A real white hat usually reports a bug before draining a reserve. Taking 95% of the backing first and negotiating afterward is at best an aggressive version of the practice. Until the coins move back, L-BTC holders are in limbo.
Is L-BTC still worth one bitcoin?
For now, L-BTC can’t be redeemed at all. Its value rests on a claim to BTC held by the federation, and after the exploit that wallet held only a small fraction of what it did — about 207 BTC left, per Bitcoin Magazine. How the shortfall gets resolved had not been announced on Sunday.
The pause hit real products. Exchanges halted L-BTC deposits and withdrawals, and Aqua Wallet, which uses Liquid, was affected. Other Liquid assets — USDT on Liquid, DePix and tokenized real-world assets — were not affected, because they aren’t backed by the BTC reserve.
Liquid launched in 2018 and its federation now counts more than 80 members, from exchanges to infrastructure firms and asset managers. The system ran for eight years. One bug was enough to empty it in 23 minutes.
What this means for swap users
Wrapped and federated BTC is an IOU: its value depends on the peg and on the software that verifies it. Native BTC in your own wallet has no peg to break. If you use SwapZilla’s DEX shelf, CEX and DEX quotes sit side by side, and the plain swaps on SwapZilla deliver native coins straight to your address — no bridge, no wrapper to hold.
When a network pauses, swaps into it stop too, which is exactly what should happen. For fast bitcoin payments without a federation, see Lightning vs on-chain BTC. For long-term holdings, the answer is still cold storage — with the caveat from our Coldcard theft story that the wallet has to be secure too.
Final thoughts
The Liquid exploit didn’t break bitcoin. It broke a promise layered on top of bitcoin — that one L-BTC is always redeemable for one BTC. That promise was only as good as the federation, and the federation was only as good as its code.
A peg is a promise. Native BTC isn’t.
If you hold any pegged bitcoin — on a sidechain, a bridge or another chain — know who backs it, what verifies it, and what happens when that check fails. Or hold the thing itself.