Nearly 4,000 Bitcoin suddenly left the wallet securing one of Bitcoin's best-known sidechains over the weekend, triggering a network pause and raising an uncomfortable question for L-BTC holders:
What happens when the Bitcoin backing a sidechain token is unexpectedly withdrawn?
On September 6, roughly 4,000 BTC worth about $320 million was withdrawn from the Liquid Federation wallet by parties describing themselves as “white hats.” Liquid subsequently paused network activity while Blockstream investigated the incident. Reuters' report on the Liquid Network security incident
The situation then changed rapidly.
After Blockstream said affected bridge nodes had been patched, the party responsible returned approximately 3,400 BTC. Around 598.5 BTC, worth roughly $47 million at the time of reporting, remained in the party's wallet. latest report on the returned Liquid BTC
The incident is therefore more complicated than a conventional “$320 million Bitcoin hack.”
It exposes an important distinction between Bitcoin itself and systems that use BTC as backing for assets on other networks.
Liquid Network experienced a major security incident on September 6, 2026, when roughly 4,000 BTC was withdrawn from its Federation wallet.
The funds represented approximately 95% of the roughly 4,200 BTC held there before the incident.
The party behind the withdrawal left an on-chain message identifying itself as “white hats,” but that description should be treated as a claim rather than independent proof of benign intent.
According to information subsequently provided by SideSwap, 4,000 L-BTC was sent through its peg-out service and burned under a valid authorization. The Liquid Federation then paid approximately 3,996 BTC to the corresponding Bitcoin address.
SideSwap said its Peg-out Authorization Key was not compromised. Reporting on the investigation instead points to a vulnerability in the Elements software underlying Liquid.
After Blockstream said bridge nodes had been patched, approximately 3,400 BTC was returned.
The incident does not indicate that the Bitcoin blockchain itself was hacked.
Instead, it highlights the additional risks created when BTC is moved into federated bridges and represented as L-BTC on a sidechain.
Liquid is a Bitcoin sidechain originally developed by Blockstream.
Its purpose is to allow Bitcoin and other assets to move through a network designed for features that are difficult to provide directly on Bitcoin's base layer, including:
faster settlement;
confidential transactions;
asset issuance;
and institutional or exchange settlement.
Bitcoin transferred into Liquid becomes Liquid Bitcoin, or L-BTC.
In normal operation:
1 BTC locked
↓
1 L-BTC available on Liquid
The intended relationship is therefore:
1 L-BTC = 1 BTC
But maintaining that relationship requires an infrastructure layer between Bitcoin and Liquid.
That layer is central to understanding what happened.
L-BTC is not native BTC living directly on the Bitcoin blockchain.
BTC entering Liquid is secured through a federated structure.
Users can then transact with corresponding L-BTC inside Liquid.
When users want to move back to Bitcoin, the process reverses:
L-BTC
↓
peg-out request
↓
L-BTC removed/burned
↓
corresponding BTC released
That means L-BTC's relationship to Bitcoin depends on the integrity of the mechanisms controlling the BTC backing it.
The September incident targeted that infrastructure rather than Bitcoin's consensus mechanism.
According to SideSwap's explanation reported during the investigation, a customer sent approximately 4,000 L-BTC to its peg-out service.
SideSwap processed the request using a valid Peg-out Authorization Key.
The L-BTC was burned.
The Liquid Federation subsequently released approximately 3,996 BTC.
The problem was that the L-BTC used to trigger the withdrawal should not have legitimately existed in that quantity.
Investigators subsequently traced the issue to a bug involving Liquid's underlying Elements software.
This distinction is critical.
The incident was not simply:
attacker steals federation private keys → moves BTC.
Liquid stated that the relevant Peg-out Authorization Key had not been compromised.
Instead, the system accepted L-BTC that had been improperly created and then honored the corresponding peg-out.
This is one of the most important technical questions raised by the incident.
A bridge is supposed to maintain an accounting relationship:
BTC entering
≈
L-BTC circulating
≈
BTC available for redemption
If an attacker can create L-BTC that should not exist, then a valid-looking redemption request can become dangerous.
The peg-out machinery may see:
valid L-BTC → valid authorization → release BTC
even though the L-BTC itself originated from an invalid state.
That is why bridge security involves more than protecting private keys.
The system must also guarantee that the asset being redeemed was created legitimately.
Based on currently available information, Liquid says no.
The network stated that the Peg-out Authorization Key used in the transaction had not been compromised, and SideSwap similarly said its systems and PAK were not breached.
That makes this incident particularly instructive.
Crypto security is often reduced to:
Were the keys stolen?
But a system can fail even when cryptographic keys work exactly as designed.
Software logic can be exploited.
Invalid states can be created.
A bridge can execute an authorized transaction based on data that should never have become valid.
The Bitcoin address receiving the funds included an on-chain message stating that the actors were white hats and asking Blockstream to contact them on-chain.
Blockstream subsequently communicated through Bitcoin transactions and signed messages.
The party later indicated that the vulnerability should be fixed before funds were returned. After Blockstream announced that bridge nodes had been patched, approximately 3,400 BTC was sent back.
Returning most of the funds is consistent with some white-hat behavior.
But editorially, it remains important not to turn a self-description into a confirmed identity.
The safest wording is:
purported or self-described white-hat hacker(s).
As of the latest reporting available for this article:
| Item | Approximate amount |
|---|---|
| BTC originally held in Federation wallet | ~4,200 BTC |
| BTC withdrawn | ~4,000 BTC |
| BTC returned | ~3,400 BTC |
| BTC remaining with the party | ~598.5 BTC |
The remaining amount was worth approximately $47.3 million at the time of the latest update.
Because this is an active incident, these figures can change as additional transactions occur.
This is the question L-BTC holders should care about most.
During the incident, a very large portion of the BTC held in the Federation wallet was withdrawn.
That created an obvious temporary backing problem.
However, most of the withdrawn BTC has now been returned.
The correct conclusion is therefore not:
L-BTC permanently lost its Bitcoin backing.
Nor should the situation be described as if nothing happened.
The incident demonstrated that the mechanisms protecting the BTC side of the peg could fail in a way that allowed Bitcoin to leave the federation wallet.
Until the network fully restores normal operation and publishes complete post-incident accounting, users should distinguish between the intended 1:1 peg design and the actual reserve situation during the incident and recovery process.
According to MEXC senior crypto industry analyst Priya Sharma, the Liquid incident illustrates a distinction that becomes increasingly important as Bitcoin develops a larger ecosystem: owning native BTC and owning a representation of BTC on another system do not carry identical risks.
Bitcoin's base layer was not compromised. Instead, the incident occurred in infrastructure designed to make Bitcoin more useful outside its native settlement environment. Sharma notes that this pattern appears repeatedly across crypto: additional programmability, faster settlement and interoperability can create economic value, but every additional system also introduces another trust and software boundary.
The most important lesson, in Sharma's view, is therefore not that Bitcoin sidechains are inherently unsafe. It is that investors should understand where their asset actually lives and what mechanism guarantees redemption. Native BTC relies on Bitcoin's consensus and the holder's custody model. L-BTC additionally relies on Liquid's federation, bridge software and peg mechanisms. A token can maintain the same unit of account while carrying a different security architecture.
No evidence from this incident suggests that Bitcoin's underlying blockchain was compromised.
Bitcoin continued producing blocks.
Bitcoin consensus continued functioning.
Ordinary BTC held in self-custody wallets was not suddenly exposed because of the Liquid vulnerability.
The affected infrastructure was the system connecting BTC to Liquid.
This distinction matters because headlines such as:
“4,000 Bitcoin hacked”
can create the false impression that someone broke Bitcoin's cryptography.
That is not what happened.
Bridges have historically been one of crypto's most sensitive infrastructure layers.
The reason is economic.
A bridge often holds a valuable reserve on one side while issuing a representation on another.
That creates something similar to a vault.
If:
$500 million BTC
backs
$500 million tokenized BTC
then the bridge controls infrastructure protecting a very large pool of assets.
An attacker does not necessarily need to break Bitcoin.
They only need to find a weakness in the bridge.
Liquid uses a federated model rather than relying on a single custodian.
That architecture is designed to distribute operational control.
But federation does not eliminate software risk.
Even if signing keys remain secure, the nodes using those keys must interpret network state correctly.
The September incident demonstrates why the security model has to include:
key security
software correctness
asset accounting
peg validation
operational controls.
Following the incident, Liquid paused network activity and bridge operations while the vulnerability was investigated and patched.
That response limits further damage but introduces another trade-off.
A sidechain designed to provide faster settlement becomes temporarily unavailable precisely when users most want to move assets.
This is a reminder that sidechain performance should not be evaluated only by transaction speed.
Resilience during abnormal conditions matters just as much.
The next stage is more important than the initial headline.
Users should watch for:
full restoration of Liquid transactions;
resumption of peg-ins and peg-outs;
final accounting of returned BTC;
treatment of the remaining ~598.5 BTC;
a technical post-mortem;
the exact Elements vulnerability;
whether affected software existed elsewhere;
and any changes to Liquid's bridge architecture.
The technical post-mortem will be particularly important.
Without understanding exactly how invalid L-BTC was created and why the peg-out system accepted it, it is difficult to judge whether the patch addresses only this exploit or a broader class of vulnerabilities.
Bitcoin's ecosystem is increasingly experimenting with ways to make BTC more programmable.
That includes:
sidechains;
bridges;
wrapped Bitcoin;
payment networks;
rollup-style systems;
and other Bitcoin-connected protocols.
The attraction is obvious.
Bitcoin has enormous liquidity and a strong settlement network.
Developers want to make that capital useful in more environments.
But every time BTC moves away from native Bitcoin ownership, users should ask:
Who controls the underlying BTC?
What backs the representation?
How can it be redeemed?
What happens if the bridge fails?
Can the network be paused?
Those questions are becoming more important as Bitcoin-based finance expands.
This incident provides a useful framework for evaluating any Bitcoin-backed asset.
Consider three situations:
| Asset | Main security dependency |
|---|---|
| Native BTC in self-custody | Bitcoin network + user's key security |
| Custodial BTC balance | Bitcoin + custodian |
| Sidechain/wrapped BTC | Bitcoin + bridge/custodian/federation + software |
The further an asset moves from native Bitcoin, the more layers users may need to trust.
Those additional layers can provide useful features.
But they should not be invisible.
Liquid Network described the event as a security incident in which purported white-hat hackers withdrew roughly 4,000 BTC from the Liquid Federation wallet.
Approximately 4,000 BTC, worth around $320 million at the time.
Approximately 3,400 BTC has been returned following the patching of affected bridge nodes. Roughly 598.5 BTC remained with the party at the latest reported update.
No. The incident affected Liquid's sidechain and bridge infrastructure, not Bitcoin's underlying blockchain consensus.
L-BTC is the Bitcoin-pegged asset used on Liquid Network. It is designed to correspond 1:1 with BTC held through Liquid's federation infrastructure.
SideSwap said its systems and Peg-out Authorization Key were not compromised. The investigation instead pointed to a vulnerability involving Liquid's underlying Elements software.
Most of the withdrawn BTC has been returned and affected bridge nodes were reported patched, but users should follow official network updates and the eventual technical post-mortem before drawing conclusions about the completed recovery.
The network paused activity and bridge operations to prevent further exploitation while the vulnerability was investigated and patched.
Key developments include full network restoration, reserve accounting, the remaining BTC, the technical vulnerability report and any changes to the federation or bridge architecture.
This article is for informational and educational purposes only and does not constitute financial or investment advice. The Liquid Network incident remains an evolving security event. Fund balances, network status and technical findings may change as the investigation and recovery continue.

Binance no longer publishes a single daily withdrawal limit: it depends on your verification level and country and appears on the Identification page, per the FAQ updated 5 June 2026. The 0.06 BTC

For traders outside South Korea, MEXC is the better choice in this comparison, because Bithumb's account opening runs through a Korean real-name bank account and the fee schedule you came to compare

For traders outside South Korea, MEXC is the better choice in this comparison on two verified numbers: 0.0500% taker against the 0.25% Upbit charges in the BTC and USDT markets, on 1,627 listed coins

I. Macro & Market Sentiment Market Data: BTC $79,384 (-0.67%) | ETH $2,501.71 (-0.08%) | SOL $104.27 (-1.00%) Market Sentiment: Funding Rate +0.0074% | Fear & Greed Index 69 (Greed) Data Preview: The

I. Macro & Market Sentiment Market Data: BTC $79,930 (-0.02%) | ETH $2,504 (-0.03%) | SOL $105 (+1.28%) Market Sentiment: Funding Rate +0.0025% | Fear & Greed Index 71 (Greed) Geopolitics: Direct

I. Macro & Market Sentiment Market Data: BTC $81,006 (+4.74%) | ETH $2,507 (+5.05%) | SOL $103.79 (+3.58%) Market Sentiment: Funding Rate +0.0088% | Fear & Greed Index 74 (Greed) Geopolitical Risk:

Bitcoin hardware wallet maker Coinkite has warned users about a seed-generation issue affecting Coldcard devices, including every Mk3 firmware version from 4.0.1 onward. The warning emerged as securit

The Bitcoin rally accelerated again as BTC climbed to $73,546.77 while Ether traded at $2,336.17, extending a broad rebound across the cryptocurrency market. The move came as several catalysts converg

Moving U.S. dollars from Singapore to New York on a Saturday has traditionally meant running into one unavoidable obstacle:the banking week.On September 5, 2026, DBS and Citi demonstrated a different

How much money is actually on Robinhood Chain?Depending on which number you look at, the answer can appear to be:$800 million$1.27 billionor:more than $3 billion.These figures do not necessarily contr

Robinhood Chain is designed as a low-cost Ethereum Layer 2.But “low gas” does not automatically mean “cheap trade.”For an ordinary user, the true cost of entering Robinhood Chain can include several s