
Blockstream's Liquid Network Recovers 3,400 of 4,000
A software bug in Liquid's Elements codebase — not a stolen key — let an outsider mint unbacked L-BTC and drain roughly $320 million from the network's federation reserve. Most of the bitcoin is back, but a $47 million shortfall still leaves the 1:1 peg unresolved.
Attackers exploited a software bug in Blockstream's Elements code to mint unbacked L-BTC and redeem it for roughly 4,000 real bitcoin ($320 million) from Liquid Network's federation reserve on September 6, 2026. Self-described 'whitehats' have since returned 3,400 BTC (~$268 million) after Blockstream confirmed a patch, but 598.5 BTC (~$47 million) remains outstanding, leaving L-BTC's 1:1 backing unresolved.
The Ledger Desk · 4 min read- The exploit stemmed from a bug in Elements, Liquid's open-source codebase — Blockstream and SideSwap both said the federation's private keys and SideSwap's Peg-out Authorization Key were not compromised.
- Attackers drained roughly 4,000 BTC (~95% of the federation's reserve) on September 6, 2026, then returned 3,400 BTC (~$268 million) after Blockstream confirmed a patch via on-chain message.
- 598.5 BTC (~$47 million) remains outstanding, leaving L-BTC undercollateralized against its 1:1 bitcoin backing until the shortfall is closed.
- Bitfinex and the Aqua wallet suspended L-BTC deposits and withdrawals, and Blockstream disabled bridge nodes network-wide to freeze the peg-out system.
- No formal bounty agreement has been confirmed; CertiK flagged the retained 598.5 BTC as a possible reward, not a settled deal.
Blockstream's Liquid Network has recovered most of the roughly 4,000 bitcoin — about $320 million — that an attacker withdrew from its federation reserve on September 6, 2026, by exploiting a software bug rather than stealing a private key. Self-described "whitehats" returned 3,400 BTC (about $268 million) on September 7 after Blockstream confirmed the underlying flaw in its Elements codebase was patched, according to CoinDesk and CryptoTimes. But 598.5 BTC (roughly $47 million) remains outstanding, leaving L-BTC's 1:1 bitcoin backing unresolved and Bitfinex and the Aqua wallet still blocking L-BTC deposits and withdrawals.
How the exploit worked
Attackers withdrew roughly 4,000 BTC — about $320 million at the time — from the Bitcoin reserve backing Blockstream's Liquid Network sidechain on September 6, 2026, according to CoinDesk. The exploit traced to a software bug in Elements, the open-source codebase Liquid runs on, executed through a peg-out via SideSwap around 14:05 UTC. Blockstream and SideSwap both said the attack did not involve a compromise of the federation's private keys or SideSwap's Peg-out Authorization Key — the flaw let the attacker mint unbacked L-BTC and redeem it for real bitcoin, per CoinDesk and CryptoTimes.
The whitehat return
The people behind the withdrawal identified themselves as 'whitehats' and negotiated with Blockstream entirely through messages posted on the Bitcoin blockchain, CoinDesk reported. Blockstream confirmed a patch at 09:19:46 UTC on September 7 with the on-chain message 'Bridge nodes are patched, safe to return the funds'; the attackers then returned 3,400 BTC (about $268 million) but kept 598.5 BTC (roughly $47 million), according to CryptoTimes. Blockchain-security firm CertiK flagged the retained sum as a possible bounty, though neither party has confirmed a formal reward agreement.
Why the shortfall matters for the peg
L-BTC is designed to trade 1:1 against bitcoin because each token is supposed to be backed by an equivalent amount of BTC held in Liquid's federation reserve. With 598.5 BTC still missing, that backing is short by roughly $47 million, and Coinpedia reported the deficit risks pushing L-BTC to trade at a discount to bitcoin if it isn't closed — a dynamic that could trigger capital flight from the token. Bitfinex and the Aqua wallet have already suspended L-BTC deposits and withdrawals while the shortfall persists.
The infrastructure read
This is a code-integrity failure, not a custody-key theft, which is the more instructive distinction for anyone assessing federated Bitcoin sidechains and similar wrapped-asset bridges. Liquid's federation model is built to resist key compromise, but a bug in the shared Elements software let an outsider print claims on reserves the keys never had to move. Blockstream's response — disabling bridge nodes to freeze the entire peg-out system — shows the containment tool available to a federated design is blunt, and it stopped the bleeding only after roughly 95% of the reserve was already gone.
- What actually caused the Liquid Network exploit?
- A bug in Elements, the open-source software Liquid runs on, let an attacker mint unbacked L-BTC and redeem it for real bitcoin through a peg-out via SideSwap — Blockstream and SideSwap both said no private keys or the Peg-out Authorization Key were compromised.
- Is L-BTC still fully backed by bitcoin?
- No. Of the roughly 4,000 BTC taken, 598.5 BTC (~$47 million) has not been returned, leaving a shortfall against L-BTC's intended 1:1 bitcoin backing.
- Why did attackers return most of the funds instead of keeping all of it?
- The attackers identified themselves as 'whitehats' and negotiated with Blockstream via messages posted directly on the Bitcoin blockchain, returning 3,400 BTC only after Blockstream confirmed the underlying bug had been patched.