About 4,000 BTC—roughly 95% of Liquid’s reported reserve—was withdrawn in a reported September 2026 peg out after allegedly bug created LBTC passed an authorized redemption path. The incident highlights a bridge risk beyond stolen keys: a federation can sign a withdrawal that meets its configured checks even if an u...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What happened in the reported $320 million Liquid Network incident in which purported white-hat hackers withdrew about 4,000 BTC—roughly 95%. Article summary: The reported incident was not a theft of the federation’s signing keys in the usual sense; it appears to have been a failure of the peg-out validation path. Attackers allegedly created LBTC through an Elements inflation . Topic tags: general, general web, user generated, academic, documentation. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, w
Liquid Network paused bridge activity after approximately 4,000 BTC—reported as about $320 million at the time—left the federation wallet backing L-BTC. The withdrawal represented roughly 95% of the reported reserve. Available reporting points to an alleged Elements software inflation flaw rather than stolen federation or SideSwap authorization keys, but public technical details remain incomplete. 4
13
The reported sequence is straightforward, even if the underlying bug is not yet fully disclosed:
In other words, the reported failure was not that someone stole the keys controlling the reserve. It was that a withdrawal apparently satisfied the system’s authorization checks despite the L-BTC allegedly having invalid economic backing.
Liquid uses a Strong Federation model: federation members collectively operate the sidechain and control the Bitcoin-side reserve through threshold signing. Liquid’s own technical documentation describes its consensus model as Strong Federations.
Hardware security modules, or HSMs, protect signing keys and enforce configured policies. They are not a general-purpose, independent judge of every historical fact relevant to an asset’s backing. If a peg-out request presents inputs that the system recognizes as valid—including a valid authorization path—the HSMs can sign without any private key being stolen.
That is the core reported distinction in this incident:
SideSwap said the roughly 4,000 BTC peg-out came through its service as a customer order, that its PAK was not compromised, and that the L-BTC originated from an Elements bug rather than SideSwap’s own systems.
The implication is not that threshold signatures or HSM cryptography failed. Rather, a shared validation or issuance defect can cause correctly functioning automated signers to approve a withdrawal that should never have been eligible. A valid signature proves that the signing policy was met; it does not, by itself, prove that the redeemed asset was properly backed.
The actors attached an on-chain message stating: “we are whitehats. contact us on chain.” 16
Reporting also indicates that Blockstream/Liquid contacted the actors through signed on-chain messages and that the actors offered to return “most” of the funds after the vulnerability is patched across the network. 4
18
Those facts establish that the actors asserted a security-researcher rationale and left a communication channel. They do not independently establish white-hat status. At the time of the reporting, the funds had not been confirmed returned, and no public patch or network reopening had been confirmed. 13
“Purported white hats” is therefore the most accurate description. The label should not be treated as a conclusion until the funds, exploit details, and remediation are independently verified.
Liquid disabled bridge nodes and paused operations, preventing normal movement between Bitcoin and Liquid. Exchanges were notified to pause, or prepare to pause, L-BTC deposits and withdrawals. 4
8
SideSwap said it paused peg-ins and peg-outs while Liquid remained paused.
These measures are containment steps: they limit additional bridge movement while operators investigate the reported vulnerability, assess the reserve position, and determine the conditions for a safe restart. The reported recovery plan depended on fixing the flaw, updating affected nodes, and resolving the status of the withdrawn BTC. 13
18
L-BTC is intended to be Bitcoin on Liquid, but its practical equivalence to readily redeemable BTC depends on the bridge being available and credibly backed.
With about 4,000 BTC reported withdrawn from a reserve of roughly 4,200 BTC—and bridge activity paused—ordinary L-BTC redemption was disrupted and the reported reserve shortfall became the immediate issue for holders. 3
13
That does not establish a final recovery outcome. It does mean that, during the incident, holding L-BTC was not operationally the same as holding BTC that could be freely withdrawn on Bitcoin’s base layer. The eventual outcome depends on recovery of funds, remediation of the alleged bug, federation decisions, and service-provider policies.
Other assets on Liquid are not automatically removed from their issuers’ reserves merely because BTC left the federation wallet. Liquid stated that assets including USDT, DePix, and RWAs were unaffected by the incident itself.
Still, “unaffected” should not be read as “risk-free.” A network pause can affect wallet access, exchange support, liquidity, transaction availability, and the ability to use L-BTC as the network’s fee and bridge asset. Each asset’s direct backing remains dependent on its own issuer and custody arrangement, while its operational usability depends on Liquid infrastructure returning to normal.
Liquid’s current design relies on a known, permissioned federation and threshold-controlled reserve. That is different from Bitcoin consensus directly verifying that every redemption is backed.
| Current federated peg | Proposed BitVM-style 1-of-n direction |
|---|---|
| A fixed federation controls the Bitcoin reserve through threshold signing. | Blockstream describes this as a longer-term research initiative, not a deployed Liquid replacement. |
| Security depends on key protection, signer operations, and the correctness of shared validation and policy software. | The goal is lower trust assumptions than conventional threshold-signature designs. |
| A common software defect can potentially cause all automated signers to accept the same invalid interpretation. | BitVM-style systems use optimistic verification and challenge mechanisms; security depends on correct protocol design and an active honest challenger. |
A BitVM-style model does not eliminate bridge risk. It moves risk into different assumptions: challengers must be able and willing to act, the fraud-proof process must be correct, and withdrawals can involve more complexity or delay. Research on BitVM-based bridges characterizes the target security model as requiring at least one honest participant, while BitVM2 aims to let anyone challenge an invalid assertion during runtime.
The Liquid incident, if the reported mechanism is confirmed, illustrates why that distinction matters. A threshold federation can be secure against stolen keys and still be exposed when every signer relies on the same flawed software interpretation of whether an asset is valid for redemption.
The reported $320 million Liquid event was a bridge-validation crisis, not a conventional private-key theft. An allegedly unbacked batch of L-BTC appears to have passed an authorized peg-out path, leading the federation to release real BTC. 2
4
The outstanding questions are consequential: the precise Elements vulnerability, the final reserve and L-BTC backing position, whether funds are returned, and what controls must change before the bridge can safely resume. Until those answers are publicly verified, users should treat the event as unresolved rather than as a completed white-hat disclosure or a routine service interruption.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
About 4,000 BTC—roughly 95% of Liquid’s reported reserve—was withdrawn in a reported September 2026 peg out after allegedly bug created LBTC passed an authorized redemption path.
About 4,000 BTC—roughly 95% of Liquid’s reported reserve—was withdrawn in a reported September 2026 peg out after allegedly bug created LBTC passed an authorized redemption path. The incident highlights a bridge risk beyond stolen keys: a federation can sign a withdrawal that meets its configured checks even if an upstream software defect makes the redeemed asset appear valid.
Actors called themselves “whitehats” and said they would return “most” funds after a patch, but that claim is unproven until funds are actually returned.