Nearly 4,000 Bitcoin suddenly left the wallet securing one of Bitcoin's best-known sidechains over the weekend, triggering a network pause and raising an uncomfortable question for L-BTC holders:Nearly 4,000 Bitcoin suddenly left the wallet securing one of Bitcoin's best-known sidechains over the weekend, triggering a network pause and raising an uncomfortable question for L-BTC holders:
Learn/Market Insights/Hot Topic Analysis/Liquid Netw...L-BTC Safe?

Liquid Network Hack Explained: What Happened to Nearly 4,000 BTC and Is L-BTC Safe?

Sep 8, 2026Priya Sharma
0m
Bitcoin
BTC$78,637.36-1.48%
4
4$0.024092+7.40%
Notcoin
NOT$0.0004697+2.39%

Nearly 4,000 Bitcoin suddenly left the wallet securing one of Bitcoin's best-known sidechains over the weekend, triggering a network pause and raising an uncomfortable question for L-BTC holders:

What happens when the Bitcoin backing a sidechain token is unexpectedly withdrawn?

On September 6, roughly 4,000 BTC worth about $320 million was withdrawn from the Liquid Federation wallet by parties describing themselves as “white hats.” Liquid subsequently paused network activity while Blockstream investigated the incident. Reuters' report on the Liquid Network security incident

The situation then changed rapidly.

After Blockstream said affected bridge nodes had been patched, the party responsible returned approximately 3,400 BTC. Around 598.5 BTC, worth roughly $47 million at the time of reporting, remained in the party's wallet. latest report on the returned Liquid BTC

The incident is therefore more complicated than a conventional “$320 million Bitcoin hack.”

It exposes an important distinction between Bitcoin itself and systems that use BTC as backing for assets on other networks.

Summary

Liquid Network experienced a major security incident on September 6, 2026, when roughly 4,000 BTC was withdrawn from its Federation wallet.

The funds represented approximately 95% of the roughly 4,200 BTC held there before the incident.

The party behind the withdrawal left an on-chain message identifying itself as “white hats,” but that description should be treated as a claim rather than independent proof of benign intent.

According to information subsequently provided by SideSwap, 4,000 L-BTC was sent through its peg-out service and burned under a valid authorization. The Liquid Federation then paid approximately 3,996 BTC to the corresponding Bitcoin address.

SideSwap said its Peg-out Authorization Key was not compromised. Reporting on the investigation instead points to a vulnerability in the Elements software underlying Liquid.

After Blockstream said bridge nodes had been patched, approximately 3,400 BTC was returned.

The incident does not indicate that the Bitcoin blockchain itself was hacked.

Instead, it highlights the additional risks created when BTC is moved into federated bridges and represented as L-BTC on a sidechain.

What Is Liquid Network?

Liquid is a Bitcoin sidechain originally developed by Blockstream.

Its purpose is to allow Bitcoin and other assets to move through a network designed for features that are difficult to provide directly on Bitcoin's base layer, including:

faster settlement;

confidential transactions;

asset issuance;

and institutional or exchange settlement.

Bitcoin transferred into Liquid becomes Liquid Bitcoin, or L-BTC.

In normal operation:

1 BTC locked

1 L-BTC available on Liquid

The intended relationship is therefore:

1 L-BTC = 1 BTC

But maintaining that relationship requires an infrastructure layer between Bitcoin and Liquid.

That layer is central to understanding what happened.

How Does L-BTC Work?

L-BTC is not native BTC living directly on the Bitcoin blockchain.

BTC entering Liquid is secured through a federated structure.

Users can then transact with corresponding L-BTC inside Liquid.

When users want to move back to Bitcoin, the process reverses:

L-BTC

peg-out request

L-BTC removed/burned

corresponding BTC released

That means L-BTC's relationship to Bitcoin depends on the integrity of the mechanisms controlling the BTC backing it.

The September incident targeted that infrastructure rather than Bitcoin's consensus mechanism.

What Actually Happened to the 4,000 BTC?

According to SideSwap's explanation reported during the investigation, a customer sent approximately 4,000 L-BTC to its peg-out service.

SideSwap processed the request using a valid Peg-out Authorization Key.

The L-BTC was burned.

The Liquid Federation subsequently released approximately 3,996 BTC.

The problem was that the L-BTC used to trigger the withdrawal should not have legitimately existed in that quantity.

Investigators subsequently traced the issue to a bug involving Liquid's underlying Elements software.

This distinction is critical.

The incident was not simply:

attacker steals federation private keys → moves BTC.

Liquid stated that the relevant Peg-out Authorization Key had not been compromised.

Instead, the system accepted L-BTC that had been improperly created and then honored the corresponding peg-out.

Why Didn't the Federation Stop the Withdrawal?

This is one of the most important technical questions raised by the incident.

A bridge is supposed to maintain an accounting relationship:

BTC entering

L-BTC circulating

BTC available for redemption

If an attacker can create L-BTC that should not exist, then a valid-looking redemption request can become dangerous.

The peg-out machinery may see:

valid L-BTC → valid authorization → release BTC

even though the L-BTC itself originated from an invalid state.

That is why bridge security involves more than protecting private keys.

The system must also guarantee that the asset being redeemed was created legitimately.

Was Liquid Network's Private Key Hacked?

Based on currently available information, Liquid says no.

The network stated that the Peg-out Authorization Key used in the transaction had not been compromised, and SideSwap similarly said its systems and PAK were not breached.

That makes this incident particularly instructive.

Crypto security is often reduced to:

Were the keys stolen?

But a system can fail even when cryptographic keys work exactly as designed.

Software logic can be exploited.

Invalid states can be created.

A bridge can execute an authorized transaction based on data that should never have become valid.

Why Did the Party Call Itself a White Hat?

The Bitcoin address receiving the funds included an on-chain message stating that the actors were white hats and asking Blockstream to contact them on-chain.

Blockstream subsequently communicated through Bitcoin transactions and signed messages.

The party later indicated that the vulnerability should be fixed before funds were returned. After Blockstream announced that bridge nodes had been patched, approximately 3,400 BTC was sent back.

Returning most of the funds is consistent with some white-hat behavior.

But editorially, it remains important not to turn a self-description into a confirmed identity.

The safest wording is:

purported or self-described white-hat hacker(s).

How Much Bitcoin Has Been Returned?

As of the latest reporting available for this article:

ItemApproximate amount
BTC originally held in Federation wallet~4,200 BTC
BTC withdrawn~4,000 BTC
BTC returned~3,400 BTC
BTC remaining with the party~598.5 BTC

The remaining amount was worth approximately $47.3 million at the time of the latest update.

Because this is an active incident, these figures can change as additional transactions occur.

Is L-BTC Still Backed 1:1 by Bitcoin?

This is the question L-BTC holders should care about most.

During the incident, a very large portion of the BTC held in the Federation wallet was withdrawn.

That created an obvious temporary backing problem.

However, most of the withdrawn BTC has now been returned.

The correct conclusion is therefore not:

L-BTC permanently lost its Bitcoin backing.

Nor should the situation be described as if nothing happened.

The incident demonstrated that the mechanisms protecting the BTC side of the peg could fail in a way that allowed Bitcoin to leave the federation wallet.

Until the network fully restores normal operation and publishes complete post-incident accounting, users should distinguish between the intended 1:1 peg design and the actual reserve situation during the incident and recovery process.

MEXC Analyst View: Bitcoin Security and Bitcoin-Based System Security Are Not the Same Thing

According to MEXC senior crypto industry analyst Priya Sharma, the Liquid incident illustrates a distinction that becomes increasingly important as Bitcoin develops a larger ecosystem: owning native BTC and owning a representation of BTC on another system do not carry identical risks.

Bitcoin's base layer was not compromised. Instead, the incident occurred in infrastructure designed to make Bitcoin more useful outside its native settlement environment. Sharma notes that this pattern appears repeatedly across crypto: additional programmability, faster settlement and interoperability can create economic value, but every additional system also introduces another trust and software boundary.

The most important lesson, in Sharma's view, is therefore not that Bitcoin sidechains are inherently unsafe. It is that investors should understand where their asset actually lives and what mechanism guarantees redemption. Native BTC relies on Bitcoin's consensus and the holder's custody model. L-BTC additionally relies on Liquid's federation, bridge software and peg mechanisms. A token can maintain the same unit of account while carrying a different security architecture.

Was Bitcoin Itself Hacked?

No evidence from this incident suggests that Bitcoin's underlying blockchain was compromised.

Bitcoin continued producing blocks.

Bitcoin consensus continued functioning.

Ordinary BTC held in self-custody wallets was not suddenly exposed because of the Liquid vulnerability.

The affected infrastructure was the system connecting BTC to Liquid.

This distinction matters because headlines such as:

“4,000 Bitcoin hacked”

can create the false impression that someone broke Bitcoin's cryptography.

That is not what happened.

Why Bridges Are a Special Security Risk

Bridges have historically been one of crypto's most sensitive infrastructure layers.

The reason is economic.

A bridge often holds a valuable reserve on one side while issuing a representation on another.

That creates something similar to a vault.

If:

$500 million BTC

backs

$500 million tokenized BTC

then the bridge controls infrastructure protecting a very large pool of assets.

An attacker does not necessarily need to break Bitcoin.

They only need to find a weakness in the bridge.

What Makes Liquid Different From a Typical DeFi Bridge?

Liquid uses a federated model rather than relying on a single custodian.

That architecture is designed to distribute operational control.

But federation does not eliminate software risk.

Even if signing keys remain secure, the nodes using those keys must interpret network state correctly.

The September incident demonstrates why the security model has to include:

key security



software correctness



asset accounting



peg validation



operational controls.

Why the Network Was Paused

Following the incident, Liquid paused network activity and bridge operations while the vulnerability was investigated and patched.

That response limits further damage but introduces another trade-off.

A sidechain designed to provide faster settlement becomes temporarily unavailable precisely when users most want to move assets.

This is a reminder that sidechain performance should not be evaluated only by transaction speed.

Resilience during abnormal conditions matters just as much.

What Should L-BTC Users Watch Now?

The next stage is more important than the initial headline.

Users should watch for:

full restoration of Liquid transactions;

resumption of peg-ins and peg-outs;

final accounting of returned BTC;

treatment of the remaining ~598.5 BTC;

a technical post-mortem;

the exact Elements vulnerability;

whether affected software existed elsewhere;

and any changes to Liquid's bridge architecture.

The technical post-mortem will be particularly important.

Without understanding exactly how invalid L-BTC was created and why the peg-out system accepted it, it is difficult to judge whether the patch addresses only this exploit or a broader class of vulnerabilities.

What Does This Mean for Bitcoin Layer 2 and Sidechains?

Bitcoin's ecosystem is increasingly experimenting with ways to make BTC more programmable.

That includes:

sidechains;

bridges;

wrapped Bitcoin;

payment networks;

rollup-style systems;

and other Bitcoin-connected protocols.

The attraction is obvious.

Bitcoin has enormous liquidity and a strong settlement network.

Developers want to make that capital useful in more environments.

But every time BTC moves away from native Bitcoin ownership, users should ask:

Who controls the underlying BTC?

What backs the representation?

How can it be redeemed?

What happens if the bridge fails?

Can the network be paused?

Those questions are becoming more important as Bitcoin-based finance expands.

The Bigger Lesson: “Backed by Bitcoin” Is Not the Same as “Is Bitcoin”

This incident provides a useful framework for evaluating any Bitcoin-backed asset.

Consider three situations:

AssetMain security dependency
Native BTC in self-custodyBitcoin network + user's key security
Custodial BTC balanceBitcoin + custodian
Sidechain/wrapped BTCBitcoin + bridge/custodian/federation + software

The further an asset moves from native Bitcoin, the more layers users may need to trust.

Those additional layers can provide useful features.

But they should not be invisible.

FAQ

Was Liquid Network hacked?

Liquid Network described the event as a security incident in which purported white-hat hackers withdrew roughly 4,000 BTC from the Liquid Federation wallet.

How much Bitcoin was withdrawn from Liquid?

Approximately 4,000 BTC, worth around $320 million at the time.

Did the hackers return the Bitcoin?

Approximately 3,400 BTC has been returned following the patching of affected bridge nodes. Roughly 598.5 BTC remained with the party at the latest reported update.

Was Bitcoin itself hacked?

No. The incident affected Liquid's sidechain and bridge infrastructure, not Bitcoin's underlying blockchain consensus.

What is L-BTC?

L-BTC is the Bitcoin-pegged asset used on Liquid Network. It is designed to correspond 1:1 with BTC held through Liquid's federation infrastructure.

Was SideSwap hacked?

SideSwap said its systems and Peg-out Authorization Key were not compromised. The investigation instead pointed to a vulnerability involving Liquid's underlying Elements software.

Is L-BTC safe now?

Most of the withdrawn BTC has been returned and affected bridge nodes were reported patched, but users should follow official network updates and the eventual technical post-mortem before drawing conclusions about the completed recovery.

Why was Liquid paused?

The network paused activity and bridge operations to prevent further exploitation while the vulnerability was investigated and patched.

What should L-BTC holders watch next?

Key developments include full network restoration, reserve accounting, the remaining BTC, the technical vulnerability report and any changes to the federation or bridge architecture.

Disclaimer

This article is for informational and educational purposes only and does not constitute financial or investment advice. The Liquid Network incident remains an evolving security event. Fund balances, network status and technical findings may change as the investigation and recovery continue.

Market Opportunity
Bitcoin Logo
Bitcoin Price(BTC)
$78,625
$78,625$78,625
-0.24%
USD
Bitcoin (BTC) Live Price Chart

Popular Articles

View More
Binance Daily Withdrawal Limit: Current Limits by Level, Fees by Network and How Long Withdrawals Take

Binance Daily Withdrawal Limit: Current Limits by Level, Fees by Network and How Long Withdrawals Take

Binance no longer publishes a single daily withdrawal limit: it depends on your verification level and country and appears on the Identification page, per the FAQ updated 5 June 2026. The 0.06 BTC

MEXC vs Bithumb 2026: Is 0.001 BTC the Fee or the Minimum?

MEXC vs Bithumb 2026: Is 0.001 BTC the Fee or the Minimum?

For traders outside South Korea, MEXC is the better choice in this comparison, because Bithumb's account opening runs through a Korean real-name bank account and the fee schedule you came to compare

MEXC vs Upbit 2026: Are You Paying 5 Times More Without Knowing It?

MEXC vs Upbit 2026: Are You Paying 5 Times More Without Knowing It?

For traders outside South Korea, MEXC is the better choice in this comparison on two verified numbers: 0.0500% taker against the 0.25% Upbit charges in the BTC and USDT markets, on 1,627 listed coins

Standard Chartered Launches Bitcoin and Ethereum Trading in UAE: Why It Matters for Institutional Crypto

Standard Chartered Launches Bitcoin and Ethereum Trading in UAE: Why It Matters for Institutional Crypto

Institutional crypto adoption is moving from products built around banks to products delivered directly by banks. On September 3, 2026, Standard Chartered announced that eligible institutional

Hot Crypto Updates

View More
MEXC Alpha Trader – Daily Market Brief (September 8, 2026)

MEXC Alpha Trader – Daily Market Brief (September 8, 2026)

I. Macro & Market Sentiment Market Data: BTC $79,384 (-0.67%) | ETH $2,501.71 (-0.08%) | SOL $104.27 (-1.00%) Market Sentiment: Funding Rate +0.0074% | Fear & Greed Index 69 (Greed) Data Preview: The

MEXC Alpha Trader – Daily Market Brief (September 7, 2026)

MEXC Alpha Trader – Daily Market Brief (September 7, 2026)

I. Macro & Market Sentiment Market Data: BTC $79,930 (-0.02%) | ETH $2,504 (-0.03%) | SOL $105 (+1.28%) Market Sentiment: Funding Rate +0.0025% | Fear & Greed Index 71 (Greed) Geopolitics: Direct

MEXC Alpha Trader – Daily Market Brief (September 4, 2026)

MEXC Alpha Trader – Daily Market Brief (September 4, 2026)

I. Macro & Market Sentiment Market Data: BTC $81,006 (+4.74%) | ETH $2,507 (+5.05%) | SOL $103.79 (+3.58%) Market Sentiment: Funding Rate +0.0088% | Fear & Greed Index 74 (Greed) Geopolitical Risk:

MEXC Alpha Trader – Daily Market Brief (September 3, 2026)

MEXC Alpha Trader – Daily Market Brief (September 3, 2026)

I. Macro & Market Sentiment Market Data: BTC $77,373 (+0.62%) | ETH $2,388 (-0.30%) | SOL $100.28 (+1.26%) Market Sentiment: Funding Rate +0.0076% | Fear & Greed Index 65 (Greed) Global bond selloff

Trending News

View More
Coldcard Mk3 Warning Follows $38M Bitcoin Sweep, but Cause Remains Unconfirmed

Coldcard Mk3 Warning Follows $38M Bitcoin Sweep, but Cause Remains Unconfirmed

Bitcoin hardware wallet maker Coinkite has warned users about a seed-generation issue affecting Coldcard devices, including every Mk3 firmware version from 4.0.1 onward. The warning emerged as securit

Bitcoin Rally Surges Past $73K—What’s Fueling the Move?

Bitcoin Rally Surges Past $73K—What’s Fueling the Move?

The Bitcoin rally accelerated again as BTC climbed to $73,546.77 while Ether traded at $2,336.17, extending a broad rebound across the cryptocurrency market. The move came as several catalysts converg

BTR Price Surge Explodes 300%: What Drove It?

BTR Price Surge Explodes 300%: What Drove It?

The BTR price surge has pushed Bitlayer into the center of crypto trading activity after the token gained more than 300% over a 24-hour window on MEXC. According to platform data, BTR also ranked seco

Sberbank Eyes BTC, ETH and USDT for Crypto-Backed Loans

Sberbank Eyes BTC, ETH and USDT for Crypto-Backed Loans

Sberbank is preparing to push crypto assets deeper into traditional banking by expanding its secured-lending framework to Bitcoin, Ether and Tether’s USDT. The plan is significant because it treats ma

Related Articles

View More
DBS and Citi Complete Weekend Tokenized Deposit Payment: Can Bank Money Finally Move 24/7?

DBS and Citi Complete Weekend Tokenized Deposit Payment: Can Bank Money Finally Move 24/7?

Moving U.S. dollars from Singapore to New York on a Saturday has traditionally meant running into one unavoidable obstacle:the banking week.On September 5, 2026, DBS and Citi demonstrated a different

Robinhood Chain TVL Explained: Protocol TVL vs DeFi TVL vs Bridged TVL

Robinhood Chain TVL Explained: Protocol TVL vs DeFi TVL vs Bridged TVL

How much money is actually on Robinhood Chain?Depending on which number you look at, the answer can appear to be:$800 million$1.27 billionor:more than $3 billion.These figures do not necessarily contr

How Much Does It Really Cost to Use Robinhood Chain? Gas, Bridge Fees, Slippage and Hidden Trading Costs

How Much Does It Really Cost to Use Robinhood Chain? Gas, Bridge Fees, Slippage and Hidden Trading Costs

Robinhood Chain is designed as a low-cost Ethereum Layer 2.But “low gas” does not automatically mean “cheap trade.”For an ordinary user, the true cost of entering Robinhood Chain can include several s

Robinhood Chain Has 12.3 Million Addresses — How Many Are Actually Active Users?

Robinhood Chain Has 12.3 Million Addresses — How Many Are Actually Active Users?

Robinhood Chain reported 12.3 million addresses only two months after launching its public mainnet.That number looks enormous.But it does not mean 12.3 million people use Robinhood Chain.Blockchain an

Sign Up on MEXC
Sign Up & Receive Up to 10,000 USDT Bonus
SNOW Soars 24%: What Drove It?
SNOW Soars 24%: What Drove It?SNOW Soars 24%: What Drove It?
$1.55B in revenue and AI growth lift the outlook