Connect with us

NEWS

Liquid Pause Follows 4,000 Bitcoin Peg-Out With Keys Intact

About 4,000 bitcoin left Liquid’s peg through a valid burn on September 6. Keys held; a range-proof cache did not, and the sidechain is paused.

Published

on

About 4,000 bitcoin, worth $320 million, left Blockstream’s Liquid Network federation wallet on September 6 through a peg-out that every listed key treated as valid. The sidechain is paused, exchanges have frozen L-BTC, and just over 200 bitcoin remain in the reserve that backs the token.

Bitcoin itself kept trading near $80,000. The break is in the federated IOU that was supposed to move large amounts of bitcoin between exchanges in minutes.

Sunday’s Two Payouts Emptied the Reserve

Liquid Network said purported white-hat hackers withdrew about 4,000 BTC from the federation wallet, about $320 million, and that the coins left through the SideSwap Peg-out Authorization Key. That key was not stolen, the network said, and neither were any others.

On-chain records show two Bitcoin payouts. A 2.5 BTC transfer went first. A second payout of nearly 3,996 BTC followed, and both lots were swept to one address, bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte, which then held about 3,998.5 BTC. Before those spends the wallet had held roughly 4,200 BTC, so roughly 95% of the reserve left in an afternoon.

THE SUNDAY DRAIN

  1. September 6, 2026, 14:05 UTC: A customer sends 4,000 L-BTC to the SideSwap peg-out service, which burns the tokens with a valid peg-out authorisation.
  2. September 6, 2026, 14:28 UTC: The Liquid Federation pays 3,996 BTC to the customer’s Bitcoin address.
  3. September 6, 2026, afternoon: The holding address consolidates the coins and writes “we are whitehats. contact us on chain.” in an OP_RETURN, then pokes 1,000 satoshis back at the emptied wallet.
  4. September 6, 2026, 20:25 UTC: Liquid says bridge nodes are disabled, the sidechain is paused, and federation members are working to restore the network.

SideSwap said it processed the order like any other customer peg-out. Blockstream later told the firm the L-BTC in that order had been created through a bug in Elements, the software Liquid runs on, and that SideSwap could not tell those tokens from any other L-BTC.

The official account put the halt on the record in this post:

https://x.com/Liquid_BTC/status/2096696272447218108

How Liquid’s Peg-Out Is Built to Work

Liquid, launched in 2018, is a Bitcoin sidechain. Users lock bitcoin with the federation and receive L-BTC, which is meant to stay one-for-one with coins in that wallet. Peg-ins need 102 Bitcoin confirmations. Peg-outs burn L-BTC on Liquid and, in a typical window of 11 to 35 minutes (about 17 minutes on a normal round), pay the same amount of bitcoin from the federation wallet.

Those coins sit in the federation’s 11-of-15 multisig wallet, with each of the 15 functionary keys stored on hardware security modules. Functionaries also sign Liquid blocks. A wider group of more than 80 federation members can peg in and, with a registered key, peg out, but they do not hold those 15 keys.

Ordinary users cannot pull bitcoin out on their own. They send L-BTC to a member that holds a Peg-out Authorization Key, and that member burns the tokens and names a Bitcoin address derived from its key. Watchmen will only pay an address that proves it comes from the registered list. Functionaries wait three days to update the PAK list, a delay meant to catch operators who lose a set of machines before those machines can pay a new destination.

The design assumes a peg-out that looks valid on Liquid should be paid on Bitcoin. Sunday’s spend met that test.

Functionary Hardware Signed a Valid-Looking Burn

Peg-out hardware is built to refuse a payment that is not going back to the federation or to a whitelisted address, and to check that matching L-BTC has been burned. Both checks passed. Eleven or more of the 15 modules signed. The SideSwap key was the whitelist proof, and SideSwap says that key never left its control.

The three-day PAK delay never came into play because nobody needed to add a new key. The destination was a customer address on a member peg-out, which is how the bridge is supposed to pay. Stolen-key defence did the job it was written to do.

WHAT EACH CONTROL STOPPED

Control Built to stop What happened Sunday
11-of-15 HSM keys A stolen or rogue functionary set The modules signed the peg-out
PAK whitelist, 3-day changes A payment to an unknown Bitcoin address SideSwap’s key was used and was not stolen
Burn L-BTC first A withdrawal with no matching tokens The burn looked valid to the watchmen
Range-proof checks on confidential amounts Forged or negative L-BTC A cache reused a proof and let bad amounts through

Samson Mow, chief executive of JAN3 and a former Blockstream executive, said the working theory is a node-level flaw in Liquid’s confidential transactions, and that it is not a PAK or HSM issue. Devs had not confirmed the cause when he wrote that.

The Range-Proof Cache Was the Hole

Liquid hides amounts by default. Nodes still have to prove that a hidden amount is not negative, and they do that with range proofs, which are slow enough that Elements caches proofs it has already checked. Orangesurf, who does strategy and research at mempool, wrote that the cache looked at the proof bytes and the value commitment and did not bind the asset type or the output script. A later output that reused those two fields could get a cached pass even when a full check would fail.

That turns a speed shortcut into a consensus split. A node that had already seen a valid proof in one context could accept an invalid proof in another. A node that had not primed the cache would reject the same block. Independent analysis of the raw transactions describes a crafted output whose proof is invalid in its true context, paired with a huge positive L-BTC output whose proof is valid, so the books look balanced while new spendable L-BTC appears.

Proof Bytes Were Enough for a Pass

The cache lives in memory for the life of the process and does not survive a restart, which is why some explorers and some nodes diverged. Mempool’s Liquid instance and Blockstream’s explorer did not show the same tip. The accepting side kept producing blocks. The rejecting side stalled. Functionaries, following the accepting side, paid the peg-outs from the Bitcoin wallet.

Once those L-BTC were burned through SideSwap, watchmen had no second test for whether the tokens had ever been matched by real bitcoin. The federation did what the protocol tells it to do when a member presents a burn and a PAK proof.

Master Carried a Patch the Nodes Did Not

Elements developers had already written a six-line change that binds the range proof cache to each asset and to the output script. The commit is titled “fix: range proof cache bind to asset and scriptpubkey.” It was authored on August 3, 2026, and landed on the master branch on September 1, five days before the drain. Cherry-picks followed on the 23.x lines. At the time of the attack, no release tag contained the fix.

A public patch with no shipped build is an open window. Anyone reading the commit could see what the old cache omitted. SideSwap, which can peg out for customers, was still on code that would accept the bad proofs. There was also no extra human check on a peg-out that moved most of the reserve in one order, a gap that would have been cheap compared with $320 million.

Who Still Holds L-BTC After the Halt?

Holders of remaining L-BTC still have tokens that, on the public peg tally, line up with the bitcoin left in the wallet. They cannot move those tokens across the bridge while nodes are down. Issued assets that are not L-BTC were not part of the burn.

WHO IS TOUCHED AND WHO IS NOT

  • L-BTC on exchanges: Liquid said venues have paused, or will pause, L-BTC deposits and withdrawals until the sidechain is restored.
  • Aqua and other Liquid wallets: Mow said Liquid features in JAN3’s Aqua wallet are hit, while on-chain bitcoin in the same app still sends.
  • SideSwap customers: The firm paused swaps, peg-ins and peg-outs. Finished Bitcoin payouts stand. Unfinished orders were told to email a transaction id.
  • USDT, DePix and RWAs on Liquid: Liquid said those issued assets were unaffected, though wallets still feel the halt because bridge nodes are off.
  • Bitcoin holders on the base chain: No mainnet coins were created or destroyed. Price held near $80,000.

The people who used Liquid as a fast rail between desks now sit on an IOU they cannot redeem until functionaries bring the bridge back, and until the coins at bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte move. That is a custody and software problem for a network that sold speed to exchanges, not a hole in Bitcoin’s own rules.

On-Chain Notes Now Set the Return Terms

Blockstream answered the first OP_RETURN by paying 1,000 satoshis to the holding address with the text “Please contact security@blockstream.com.” A later note asking for Signal at @m671aw.70 was sent to that address, not from it. Mow flagged the mismatch: “The request for Signal did not come from the same address.”

Charles Guillemet, chief technology officer at Ledger, rejected the white-hat label on the first message.

White hats don’t drain a bridge and then solicit an “on-chain” contact. This echoes the Ronin hack, where attackers compromised validator keys to steal ~$625M, and the “let’s talk” framing is the same move Euler’s attacker used to negotiate a return after the fact.

Charles Guillemet, chief technology officer at Ledger

He later allowed that criminal groups rarely write to their victims either, and that the actors might be people who leaned on recent language models and do not know how disclosure is supposed to work. The sequence still reads as leverage. The coins moved first. The good-intent note arrived after the reserve was already empty.

On September 7 the holding address wrote again, asking whether sending most of the bitcoin back to the federation wallet was acceptable, then set a condition: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.” Technical detail went out in PGP aimed at Blockstream’s published key. Galaxy’s Alex Thorn laid out that OP_RETURN thread, including the line “sending most back.” Most is not all, and none of it has moved back yet.

Remaining Coins Still Match What Is Left

Blockstream’s board still lists a Liquid security incident on public bridge nodes. Liquid is marked as a major outage. Other Blockstream products on that board are listed as running.

THE PEG AFTER THE DRAIN

  • Reserve before: Roughly 4,200 BTC in the federation wallet.
  • Paid out: About 4,000 BTC, worth $320 million, through a SideSwap peg-out.
  • Still in the wallet: Just over 200 BTC, about 5% of the prior reserve.
  • Still at the holding address: About 3,998.5 BTC, with return tied to a network-wide patch.

Because the fake L-BTC was burned to pull those coins out, the L-BTC that remains can still match the bitcoin that remains, down to small dust. That is a cold comfort for anyone who needs to peg out. The 1:1 claim now depends on a patch that was already on master, on every node actually running it, and on an address that has promised to send most of the coins back after that work is confirmed.

Until those three things happen, L-BTC is a paused federated note whose largest backing pile sits with a party the network is still trying to identify in public.

Disclaimer: This article is news reporting and analysis of a security incident on a bitcoin sidechain, and it is for information only. It is not investment advice, trading advice, legal advice, or a recommendation to move, hold, or redeem L-BTC, bitcoin, or any other token. Readers who hold funds on Liquid or on an exchange that used this rail should speak with a qualified financial adviser or a crypto-asset professional before changing custody or sending coins. Wallet balances, patch status, and network operations reflect public statements and on-chain records as of the dates named above and can change if coins move or if federation software is updated.

As the founder of Thunder Tiger Europe Media, Dr. Elias Thornwood brings over 25 years of experience in international journalism, having reported from conflict zones in the Middle East, Asia, and Africa for outlets like BBC World and Reuters. With a PhD in International Relations from Oxford University, his expertise lies in geopolitical analysis and global diplomacy. Elias has authored two bestselling books on European foreign policy and received the Pulitzer Prize for International Reporting in 2015, establishing his authoritativeness in the field. Committed to trustworthiness, he enforces rigorous fact-checking protocols at Thunder Tiger, ensuring unbiased, evidence-based coverage of worldwide news to empower informed global audiences.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending