A reported Elements software flaw allowed actors claiming to be white hats to mint unbacked L BTC and redeem roughly 4,000 BTC—about 95% of Liquid’s 4,200 BTC reserve. The incident was not a break of Bitcoin consensus or a theft of SideSwap’s Peg out Authorization Key.
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What happened in the Liquid Network exploit—including how a bug in the Elements software allowed self-described white-hat hackers to mint un. Article summary: Liquid’s September 2026 incident was an inflation-and-redemption failure, not a compromise of Bitcoin itself or of SideSwap’s authorization key. Attackers who called themselves “white hats” exploited an Elements software. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
Liquid’s September 2026 security incident was a failure of the system meant to keep L-BTC fully backed by Bitcoin. Unknown actors, who described themselves as “white hats,” reportedly exploited a bug in the Elements software used by Liquid to create L-BTC without equivalent BTC held in reserve. They then used the ordinary peg-out process to receive real Bitcoin from the Liquid Federation wallet. 14
35
The result was extraordinary: about 4,000 BTC—roughly 95% of the wallet’s pre-incident balance of around 4,200 BTC—left the reserve. At the time, reports valued the withdrawal at approximately $320 million. 12
14
L-BTC is intended to represent Bitcoin held in custody by Liquid’s federation. In the expected model, BTC is locked on Bitcoin’s main chain and a corresponding amount of L-BTC circulates on Liquid. A holder can later destroy or redeem L-BTC through a peg-out and receive BTC from the federation reserve.
According to reporting on the incident, the vulnerability broke the first half of that model: it allowed unbacked L-BTC to be minted. The actors then presented roughly 4,000 L-BTC to SideSwap’s peg-out service. SideSwap processed the order using its normal authorization workflow, burned the received L-BTC, and the federation released 3,996 BTC to the designated Bitcoin address. 35
39
That distinction matters. Liquid said the SideSwap Peg-out Authorization Key (PAK) was used in the redemption but was not compromised, nor were other federation keys. The reported problem was that the system could not distinguish the illegitimately minted L-BTC from valid L-BTC before the redemption occurred. 33
53
The reported sequence was:
In other words, the peg-out mechanism executed as designed against invalid economic input. A normal-looking redemption path transformed an unbacked sidechain asset into BTC held in the federation’s main-chain reserve.
The party holding the BTC used Bitcoin transactions and OP_RETURN data to communicate publicly, including a message identifying itself as “whitehats.” Blockstream responded through an on-chain PGP-signed message after stating that bridge nodes had been patched. 7
45
The actors initially said they would return most of the funds after the vulnerability was fixed. On September 7, they returned 3,400 BTC to the Liquid peg address. Roughly 598.5 BTC remained at the holder address—about 15% of the withdrawn amount and valued in contemporaneous reporting at about $47 million to $48 million. 44
45
Calling the actors “white hats” should be treated as their own characterization, not an established legal or security conclusion. The retained amount was widely described as an implied bounty or finder’s fee, but the available reporting does not establish an agreed bug-bounty arrangement. 44
45
Liquid’s immediate containment measures included disabling bridge nodes and halting new transaction activity. Exchanges were notified to pause, or prepare to pause, L-BTC deposits and withdrawals. The network acknowledged that Liquid wallets would be affected while federation members worked on restoration. 12
33
53
The pause limited further bridge activity, but it also made the trust model visible: Liquid is a federated system whose operators can intervene operationally during an emergency. That ability can aid containment, yet it differs from Bitcoin’s permissionless consensus model.
Liquid said other assets issued on the sidechain—including USDT, DePix, and real-world-asset issuances—were not directly affected by this particular exploit. The primary immediate exposure was to L-BTC holders and services relying on L-BTC deposits, withdrawals, or peg activity. 11
33
53
Liquid’s core economic promise is that L-BTC is backed one-for-one by BTC under federation custody. Bitcoin itself does not enforce that relationship. It relies on Liquid’s issuance and validation logic, the federation’s custody and signing procedures, and the peg-in/peg-out process working together.
This incident illustrates why the entire chain of checks matters. Strong custody controls or a valid peg-out authorization are not enough if an issuance flaw permits a counterfeit claim to enter the system. Once the counterfeit L-BTC was accepted for redemption, it competed with legitimate L-BTC for the same finite BTC reserve. 14
35
39
The practical security invariant is simple but demanding: every redeemable unit of a wrapped asset must have verifiable backing, and the redemption system must reject assets whose issuance violates that backing rule.
The Liquid incident was not a conventional private-key theft. It instead centered on software validation and redemption infrastructure—an increasingly consequential attack surface in crypto systems.
CertiK reported more than $1.31 billion in losses across 344 crypto-security incidents in the first half of 2026. After excluding the exceptional Bybit breach from the prior-year comparison, its report said losses were about 28% higher year over year. 19 CoinGecko separately counted $3.63 billion stolen across 245 documented security incidents from January 2025 through July 2026, with supply-chain attacks, smart-contract exploits, and stolen keys among the major causes.
17
The lesson from Liquid is therefore broader than one sidechain: systems that bridge, wrap, or redeem assets must test their backing assumptions end to end. A single failure in issuance validation can turn an apparently legitimate redemption mechanism into the route by which reserve assets leave the system.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
A reported Elements software flaw allowed actors claiming to be white hats to mint unbacked L BTC and redeem roughly 4,000 BTC—about 95% of Liquid’s 4,200 BTC reserve.
A reported Elements software flaw allowed actors claiming to be white hats to mint unbacked L BTC and redeem roughly 4,000 BTC—about 95% of Liquid’s 4,200 BTC reserve. The incident was not a break of Bitcoin consensus or a theft of SideSwap’s Peg out Authorization Key.
Liquid halted bridge activity and new transactions while federation members patched affected infrastructure; Liquid said USDT, DePix, and RWA assets on the sidechain were not directly affected.