Liquid Network has suffered one of the largest security incidents involving a Bitcoin sidechain after approximately 4,000 BTC was withdrawn from its federation reserves. The incident began on September 6 after a vulnerability in the open-source Elements software was exploited to create roughly 4,000 LBTC that were not backed by bitcoin.
The attack ultimately resulted in approximately 4,000 BTC leaving the Liquid Federation’s reserve wallet through the network’s standard peg-out mechanism. Reuters reported that the withdrawal was worth roughly $320 million at the time and represented almost the entire reserve held by the federation.
Related: Liquid Network Loses 4,000 BTC as $320 Million Peg-Out Triggers Emergency Halt
Liquid subsequently halted network operations, including LBTC deposits and withdrawals, while Blockstream and federation members investigated the vulnerability. The incident has raised difficult questions about how a software-level validation failure could ultimately result in legitimate infrastructure processing unbacked assets as if they were valid.
Importantly, the incident did not involve the theft of private keys. Liquid and SideSwap have said the relevant peg-out authorization key was not compromised, meaning the problem occurred earlier in the validation process rather than through a direct compromise of the authorization infrastructure.
How the Liquid Network Exploit Happened
According to the incident report, the vulnerability involved how Liquid nodes cached range-proof verifications. Range proofs are an important part of Liquid’s confidential transaction system because they help verify that transaction amounts are valid without publicly revealing the underlying values.
The flaw allowed attackers to create LBTC that appeared valid to the network despite not being backed by bitcoin held in Liquid’s reserve. Because the validation failure occurred before the peg-out process, SideSwap’s infrastructure and Liquid’s distributed functionary nodes accepted the transactions as legitimate.
The exploiters then used SideSwap, a Liquid Federation member authorized to process peg-outs, to convert the fabricated LBTC into BTC. SideSwap’s systems were not themselves compromised; they processed an apparently valid request using the authorization mechanism as designed.
Before the incident, the federation reserve contained approximately 4,205 BTC. Following the major withdrawal and additional peg-outs processed before operations were stopped, Liquid reported that only about 197 BTC remained in the reserve.
The scale of the incident made the rapid response particularly important. Blockstream disabled the affected bridge infrastructure and began preparing a software fix, while Liquid halted transactions to prevent additional losses. Other assets issued on Liquid, including USDT and other tokens, were not affected by the underlying vulnerability, although their use was temporarily restricted while the network remained paused.
The exploiters subsequently identified themselves publicly as white-hat security researchers through a message recorded on the Bitcoin blockchain. They asked Blockstream to repair the vulnerability and ensure the affected nodes were patched before returning the majority of the bitcoin.
Liquid Recovers Most of the Stolen Bitcoin
Blockstream confirmed that a patch had been deployed to the affected bridge nodes on September 7. Following that confirmation, the exploiters returned 3,400 BTC to the Liquid Federation’s peg wallet, representing approximately 85% of the bitcoin removed during the incident.
However, approximately 598.5 BTC remains outstanding. At current prices, that represents roughly $47 million, meaning the recovery is substantial but incomplete. The parties remain in communication over the return of the remaining bitcoin, according to reporting on the recovery.
The partial recovery has also created debate over whether the exploiters should be described as white-hat hackers. A conventional security researcher normally reports a vulnerability before taking control of funds, while the Liquid actors first exploited the flaw and only later negotiated the return of most of the assets. No public agreement establishing the retained bitcoin as a legitimate bounty has been disclosed.
For Liquid users, the immediate concern remains network restoration and the status of LBTC’s bitcoin backing. Liquid is still paused while Blockstream prepares an emergency Elements release and federation operators coordinate the changes required to restore the network safely.
The incident also highlights a broader lesson for Bitcoin sidechains and other cross-chain systems. Security does not depend only on private keys or consensus mechanisms. Software validation, bridge infrastructure, asset issuance and withdrawal procedures can all become critical points of failure.
For now, Liquid’s priority is to restore the network with corrected software and 1:1 bitcoin backing while recovering the remaining funds. The return of 3,400 BTC is an important development, but the incident will ultimately be judged by the technical post-mortem, the treatment of the remaining 598.5 BTC and whether Liquid can demonstrate that the same class of vulnerability cannot be exploited again.















