$320 Million in Bitcoin Drained From Blockstream’s Liquid Network as Attacker Claims White-Hat Status

SECURITY

95% of Reserves Gone in 23 Minutes

On September 6, 2026, roughly 4,000 of the approximately 4,200 BTC held in the Liquid Federation wallet were withdrawn in a single transfer worth about $320 million. The wallet, which backs every unit of L-BTC in circulation on Blockstream’s Liquid Network sidechain, was left holding just over 200 BTC. Blockstream disabled the network’s bridge nodes and paused the sidechain within hours, halting all new peg-in and peg-out activity.

The exploit targeted a software bug in Elements, the open-source codebase underlying Liquid. Preliminary analysis suggests the vulnerability enabled the unauthorized minting of L-BTC, which then passed through SideSwap’s peg-out service as though it were legitimate. SideSwap’s authorization system could not distinguish between real and exploit-created coins, and Liquid’s federation of 15 rotating signers approved the withdrawal through its standard 11-of-15 multisig threshold. Bitcoin’s base layer was never compromised. BTC price held steady around $80,000 throughout the incident.

An On-Chain Negotiation for $320 Million

The attacker attached a message to a Bitcoin transaction identifying themselves as a white hat and inviting Blockstream to get in touch. The two sides have since been communicating through small Bitcoin transactions carrying messages permanently recorded on the Bitcoin blockchain. The attacker has offered to return “most” of the funds once Blockstream patches the underlying bug across all affected nodes. As of September 7, the funds remain in the attacker’s address and no return has been confirmed.

Not everyone accepts the white-hat framing. Ledger CTO Charles Guillemet pointed out that legitimate security researchers do not typically drain a reserve for $320 million and then negotiate through on-chain messages. Cybersecurity firm FailSafe CEO Aneirin Flynn noted the drainage of roughly 95% of reserves highlights severe vulnerabilities within Liquid’s validation and backing model.

Another Infrastructure Failure in a Brutal 2026

The Liquid exploit compounds what has been the most damaging period for Bitcoin infrastructure security in recent memory. In August alone, the Coldcard firmware exploit saw approximately 1,596 BTC stolen from roughly 500 users. SafePal disclosed a data breach exposing 40,000 customers’ personal information. BitBox patched two severe firmware vulnerabilities before they were exploited. BTCPay Server patched a critical flaw that drained merchant Lightning nodes. And Boltz suspended its Bitcoin swap services indefinitely after AI-assisted attacks outpaced its team’s ability to patch.

The pattern is consistent: the tools and infrastructure that Bitcoin users depend on for self-custody, payments, and settlement are under sustained, sophisticated pressure. The Liquid incident is the largest single loss of 2026 and raises fundamental questions about the federated sidechain model, where a small group of known signers jointly custody reserves that back an entire network’s value.

ENJOYED THIS ARTICLE?Support the authorSend a zap over Lightning or on-chain