Liquid Network exploit: 4,000 BTC drained via Elements bug in the L-BTC peg

On September 6, 2026, attackers used a bug in Blockstream’s Elements software to create invalid L-BTC on Liquid and peg out 3,996 BTC (about $320 million) — roughly 95% of the federation’s bitcoin.

Cracked voxel-style teal diamond with a white ₿ sign, with debris cubes flying off it on a dark background

Bitcoin didn’t get hacked on Sunday. A bitcoin IOU did. Attackers found a bug in the software behind Blockstream’s Liquid Network, conjured L-BTC out of nothing, and swapped it for real bitcoin through the sidechain’s own exit. In 23 minutes, the federation that backs L-BTC paid out almost everything it held.

Bitcoin itself barely noticed, holding a $78,500–$80,500 range and trading near $79,800. Anyone holding L-BTC noticed a lot. This is the clearest lesson of the year on the difference between native BTC and pegged BTC.

Key facts

  • On September 6, 2026, a bug in Elements, the software behind Blockstream’s Liquid sidechain, let attackers create invalid L-BTC out of nothing.
  • 4,000 L-BTC were sent to SideSwap’s peg-out service at 14:05 UTC; at 14:28 UTC the Liquid federation paid out 3,996 BTC, about $320 million.
  • That payout was roughly 95% of the ~4,200 BTC in the federation wallet; Bitcoin Magazine puts the total withdrawn at 4,019.4 BTC.
  • Blockstream said no peg-out authorization keys were compromised; the forged transaction looked valid, so the federation’s hardware security modules signed it automatically.
  • Liquid paused its bridge nodes and exchanges halted L-BTC deposits and withdrawals; USDT on Liquid, DePix and tokenized real-world assets were not affected.
  • The attackers left on-chain messages calling themselves white hats and demanded that every node be patched before any return of funds.

What happened to the Liquid Network on September 6?

On September 6, 2026, attackers exploited a flaw in Elements, the software that runs the Liquid sidechain, to create L-BTC that should never have existed. They sent 4,000 of it to SideSwap’s peg-out service and received 3,996 real BTC from the federation’s reserve — about $320 million — within 23 minutes.

According to Bitcoin.com News, the L-BTC arrived at SideSwap at 14:05 UTC, and the federation paid out at 14:28 UTC. SideSwap processed it as a normal peg-out order: burn the L-BTC on Liquid, release BTC on the main chain. It later said Blockstream had established that the L-BTC in that order was created through the Elements bug.

The flaw sat in how Elements caches range-proof verification — the check that confirms a hidden amount in a confidential transaction is valid. With that check fooled, the network accepted coins that had no backing.

CoinDesk reported that the federation lost roughly 4,000 of about 4,200 BTC. Crypto Times calls it the largest publicly reported crypto incident of 2026 so far.

How did fake L-BTC get past an 11-of-15 federation?

Nobody had to steal a key. Liquid peg-outs need 11 of 15 federation signers, and those signers run hardware security modules that approve withdrawals backed by valid L-BTC. The consensus bug made forged L-BTC look valid, so the modules signed automatically, exactly as designed.

Blockstream stressed that SideSwap’s peg-out authorization key “was not compromised, nor were any others.” SideSwap is a federation member with a peg-out key, and it simply couldn’t tell bug-created L-BTC from real L-BTC. Neither could anyone else.

That’s the uncomfortable part. Multisig protects against a stolen key or a rogue signer. It does nothing when the software that defines “valid” is wrong. Eleven honest signers agreeing on a false premise still produce a valid-looking signature.

Multisig guards the keys. It can’t guard the rules.

Are the Liquid attackers really white hats?

As of Sunday, that’s only their claim. The attackers posted on-chain messages including “we are whitehats. contact us on chain” and said funds would come back only after every node was patched. An on-chain reply attributed to Blockstream asked them to contact its security team. No return had been reported.

A real white hat usually reports a bug before draining a reserve. Taking 95% of the backing first and negotiating afterward is at best an aggressive version of the practice. Until the coins move back, L-BTC holders are in limbo.

Is L-BTC still worth one bitcoin?

For now, L-BTC can’t be redeemed at all. Its value rests on a claim to BTC held by the federation, and after the exploit that wallet held only a small fraction of what it did — about 207 BTC left, per Bitcoin Magazine. How the shortfall gets resolved had not been announced on Sunday.

The pause hit real products. Exchanges halted L-BTC deposits and withdrawals, and Aqua Wallet, which uses Liquid, was affected. Other Liquid assets — USDT on Liquid, DePix and tokenized real-world assets — were not affected, because they aren’t backed by the BTC reserve.

Liquid launched in 2018 and its federation now counts more than 80 members, from exchanges to infrastructure firms and asset managers. The system ran for eight years. One bug was enough to empty it in 23 minutes.

What this means for swap users

Wrapped and federated BTC is an IOU: its value depends on the peg and on the software that verifies it. Native BTC in your own wallet has no peg to break. If you use SwapZilla’s DEX shelf, CEX and DEX quotes sit side by side, and the plain swaps on SwapZilla deliver native coins straight to your address — no bridge, no wrapper to hold.

When a network pauses, swaps into it stop too, which is exactly what should happen. For fast bitcoin payments without a federation, see Lightning vs on-chain BTC. For long-term holdings, the answer is still cold storage — with the caveat from our Coldcard theft story that the wallet has to be secure too.

Final thoughts

The Liquid exploit didn’t break bitcoin. It broke a promise layered on top of bitcoin — that one L-BTC is always redeemable for one BTC. That promise was only as good as the federation, and the federation was only as good as its code.

A peg is a promise. Native BTC isn’t.

If you hold any pegged bitcoin — on a sidechain, a bridge or another chain — know who backs it, what verifies it, and what happens when that check fails. Or hold the thing itself.

FAQ

What happened to the Liquid Network?
On September 6, 2026, attackers exploited a bug in Elements, the software behind Blockstream’s Liquid sidechain, to create invalid L-BTC. They sent 4,000 L-BTC to SideSwap’s peg-out service at 14:05 UTC, and at 14:28 UTC the Liquid federation paid out 3,996 BTC, about $320 million and roughly 95% of the roughly 4,200 BTC it held. Bridge nodes were paused afterward.
Were Liquid federation keys hacked?
According to Blockstream, no. It said SideSwap’s peg-out authorization key was not compromised, nor were any others. The September 6, 2026 exploit used a consensus bug in the Elements software that made forged L-BTC look valid, so the federation’s hardware security modules signed the withdrawal automatically. Liquid peg-outs require 11 of 15 federation signers.
Can I withdraw L-BTC right now?
Not as of September 6, 2026. After the Liquid exploit, the network paused its bridge nodes and exchanges halted L-BTC deposits and withdrawals. Aqua Wallet was also affected. Other Liquid assets such as USDT on Liquid, DePix and tokenized real-world assets were not affected. The federation’s BTC reserve fell from about 4,200 BTC to about 207 BTC, per Bitcoin Magazine.
Are the Liquid Network hackers white hats?
They say so. After withdrawing about 4,000 BTC from the Liquid federation on September 6, 2026, the attackers left on-chain messages reading “we are whitehats. contact us on chain” and demanded that every node be patched before any return of funds. An on-chain reply attributed to Blockstream asked them to get in touch. As of September 6, no return had been reported.
Is wrapped bitcoin safe?
Wrapped or pegged bitcoin, such as Liquid’s L-BTC, is an IOU backed by BTC held by a custodian, federation or bridge. Its value depends on that reserve and on the software that verifies it. The September 6, 2026 Liquid exploit showed a single bug can empty the reserve without any key being stolen. Native BTC in a wallet you control has no peg to break.