The Liquid Network, the Bitcoin sidechain operated by a federation of exchanges and built on Blockstream technology, was halted on September 6 after roughly 4,000 BTC — approximately $320 million — left the federation wallet that backs the network's L-BTC peg. The withdrawal represented about 95% of that wallet's pre-incident balance of roughly 4,200 BTC, according to Cointelegraph.
The Bitcoin network itself was not affected. Liquid's other issued assets, including USDt, DePix, and real-world asset tokens, were reported unaffected.
A Peg-Out That Followed Every Rule
The most consequential detail of the incident is what did not fail. According to SideSwap, whose peg-out service processed the withdrawal, a customer submitted 4,000 L-BTC at 14:05 UTC on September 6. The service treated it like any other order: the L-BTC was burned on Liquid under a valid peg-out authorization, and at 14:28 UTC the Liquid Federation paid out 3,996 BTC to the customer's Bitcoin address.
Neither the Peg-out Authorization Key (PAK) nor any other key, and neither SideSwap's systems nor its hardware security modules, were compromised — the point was reiterated by both Liquid and SideSwap. Per SideSwap, Blockstream subsequently determined that the L-BTC in question had been created through a bug in Elements, the open-source software underlying Liquid. The coins were unbacked; the peg-out machinery processed them exactly as designed, because the machinery has no way to distinguish coins the issuance bug minted from legitimate ones.
SlowMist's incident tracker classifies the case accordingly: an Elements software vulnerability, with losses recorded at $320 million.
Containment
Liquid described those responsible as "purported white-hat hackers," a characterization whose accuracy is not independently confirmed. Blockstream said it was working to contact them through a signed on-chain message.
Federation members disabled the network's bridge nodes, preventing new transactions from being submitted — effectively pausing the sidechain, with no restart timeline published. Exchanges were notified and have paused, or were preparing to pause, L-BTC deposits and withdrawals. SideSwap suspended swaps, peg-ins, and peg-outs; AQUA Wallet said standard Bitcoin transactions continue normally.
An Unconfirmed Working Theory
JAN3 CEO Samson Mow publicly outlined a preliminary theory — emphasized as unconfirmed by developers — that the vulnerability involves Liquid's Confidential Transactions technology, characterizing it as a node-level issue unrelated to PAKs, HSMs, Blockstream Swaps, or AQUA's swap service. No root-cause analysis had been published at the time of writing.
The scale places the incident among the largest single losses of 2026, in a year whose H1 total already exceeded $1.3 billion and whose defining pattern has been infrastructure and process failure rather than broken smart contracts. The Liquid case sharpens that pattern to a point: the keys were fine, the authorizations were valid, and $320 million still moved — because the software that defines what a coin is had a bug, and every layer above it trusted the definition.
TrustGrade tracks the security posture of exchanges, sidechains, and chain infrastructure. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.