
The Liquid Federation temporarily paused the Liquid Network after an unidentified party withdrew nearly 4,000 bitcoin, valued at approximately $320 million, from the federation’s wallet.
We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.
— Liquid Network 🌊 (@Liquid_BTC) September 6, 2026
What we know so far is that the funds…
The incident affected Liquid, a Bitcoin sidechain, and services that depend on it. The Bitcoin network itself was not affected and continued to operate normally.
Liquid described those responsible as “purported white-hat hackers,” although their identities and intentions have not been independently confirmed.
According to the network’s announcement, Blockstream was attempting to contact them through a signed on-chain message.
Initial statements from Liquid and SideSwap indicated that the withdrawal was processed through SideSwap’s peg-out service using a valid Peg-out Authorization Key, or PAK.
Both organizations maintained that neither the authorization key nor SideSwap’s systems had been compromised.
SideSwap reported that a customer submitted 4,000 L-BTC to its peg-out service at 14:05 UTC.
Statement on today's Liquid incident
— SideSwap (@side_swap) September 6, 2026
Today at 14:05 UTC a customer sent 4,000 L-BTC to the SideSwap peg-out service. Our service processed it like any other order: the L-BTC was burned on Liquid with a valid peg-out authorisation, and at 14:28 UTC the Liquid Federation paid…
The L-BTC was burned on Liquid with valid authorization, after which the Liquid Federation transferred 3,996 Bitcoin to the customer’s Bitcoin address at 14:28 UTC.
According to SideSwap, Blockstream later determined that the L-BTC involved had been created through a bug in Elements, the software underlying Liquid.
SideSwap explained that its service could not distinguish those coins from other L-BTC.
JAN3 CEO Samson Mow outlined a preliminary theory that the vulnerability involved Liquid’s Confidential Transactions technology, while emphasizing that developers had not confirmed the cause.
The working theory is that the vulnerability is with Liquid’s Confidential Transactions, but devs cannot confirm at this time. The vulnerability is a node level issue and is not related to PAKs or HSMs. https://t.co/x9XvWW4wjc
— Samson Mow (@Excellion) September 6, 2026
He characterized the suspected vulnerability as a node-level issue unrelated to PAKs, hardware security modules, Blockstream Swaps, or AQUA Wallet’s new swap service.
Federation members disabled Liquid’s bridge nodes during the investigation, preventing new transactions from being submitted and effectively pausing the sidechain.
Exchanges were also notified and asked to suspend L-BTC deposits and withdrawals.
The disruption affected Liquid functions within wallets and services such as AQUA and SideSwap.
AQUA clarified that standard Bitcoin transactions would continue to operate normally. SideSwap suspended swaps, peg-ins, and peg-outs pending the Liquid Network’s return.
Liquid reported that other assets on the sidechain, including USDt, DePix, and real-world asset tokens, were not affected by the incident.
SideSwap assured users that assets in its non-custodial wallet remained under their control.
Customers with incomplete peg-in or peg-out transactions were advised to contact the company with their transaction IDs and avoid submitting new deposits until service resumes.
Blockstream and members of the Liquid Federation continued to investigate the incident and assess when the network could safely return to operation.
At the time of the announcements, they had not provided a restart timeline.
