4,000 BTC leave Blockstream’s Liquid sidechain after hack
What happened
On the afternoon of September 6, 2026, roughly 4,000 Bitcoin (about $320 million) left the Blockstream Liquid Federation wallet after a hack. Eleven of the fifteen federation keys signed a transaction that moved the funds, even though the Liquid Bitcoin (LBTC) tokens used should not have existed.
Key facts
- Attacker’s address held 3,998 BTC by Monday morning and posted an OP_RETURN message saying “we are whitehats. contact us on chain.”
- SideSwap, the peg‑out service used, blamed a faulty LBTC from a third‑party Elements bug and denied system responsibility.
- Liquid Network announced the sidechain was paused, bridge nodes disabled and exchanges stopped LBTC deposits and withdrawals.
- Mempool.space recorded an unauthorized withdrawal of 4,019 BTC and showed the loss before the official Liquid dashboard.
- All 83 inputs to the draining transaction were signed with exactly 11 valid signatures, bypassing the emergency backup path that would normally take about 56 days.
Official response
Liquid Network posted on X that the sidechain is paused until the issue is resolved and that the peg‑out authorization key (PAK) was not compromised.
Community observations
Bitcoin Core contributor Antoine Poinsot noted that block 4,050,336, which contains the peg‑out, was rejected by Mempool.space but accepted by Blockstream. Mempool.space’s real‑time audit flagged the withdrawal, and its numbers differed from the Liquid.net dashboard.
Casa security chief Jameson Lopp remarked that the Liquid functionary codebase had not been updated since April 2024, which may be a concern.
Technical details
The hack used a regular peg‑out request with 11‑of‑15 signatures, avoiding the emergency path that requires two backup keys and a waiting period of 8,064 blocks (about 56 days). The Elements software, which validates Liquid transactions, received a commit on September 1 that forces “always validate” dynafed header heights, but it is unclear whether this change is related to the exploit.
Some commentators suggested the new OpenAI GPT‑6 Astra model, released three days before the incident, could have helped discover the vulnerability, though no direct link was proven.
Why it matters
The incident shows that a large amount of Bitcoin can be moved out of a sidechain when the multi‑signature federation is compromised. It also highlights potential gaps in the Liquid Network’s monitoring and the need for timely software updates.