A Bitcoin sidechain was drained of about $320M, then the hackers gave most of it back: what happened on Liquid

Blockstream's Liquid Network was drained of roughly 4,000 BTC through a software bug, and the attackers returned about 85 per cent, branding themselves 'white hats.' Here is what the Liquid Network is, why this is not a hack of Bitcoin itself, and what was actually lost.

A Bitcoin sidechain was drained of about $320M, then the hackers gave most of it back: what happened on Liquid
TL;DR

On 6 September 2026, Blockstream's Liquid Network, a Bitcoin sidechain used by exchanges, was drained of roughly 4,000 of the about 4,200 BTC in its federation wallet, worth around $320 million. Blockstream attributes it to a software bug in the Elements code that underpins the sidechain, not compromised private keys. A day later the attackers returned about 3,400 BTC (roughly 85 per cent), keeping around 598.5 BTC (about $47 million) and calling themselves "white hats." Two things to hold onto: this is the Liquid sidechain, not the Bitcoin main chain, and the net loss is the roughly $47 million still outstanding, not the full $320 million that briefly moved. The network paused bridge nodes and asked exchanges to halt L-BTC deposits and withdrawals while it recovers.

A headline that a "Bitcoin network" was drained of $320 million is technically true and badly misleading at the same time, so it is worth slowing down. On 6 September 2026, Blockstream's Liquid Network was drained of most of the bitcoin in its central wallet, and within a day the attackers handed the bulk of it back while branding the episode a "white hat" rescue. Here is what the Liquid Network is, what actually happened, and why your bitcoin on the main chain was never part of this.

What is the Liquid Network?

The Liquid Network is a Bitcoin sidechain built by Blockstream. It is a separate blockchain that runs alongside Bitcoin, operated by a federation of businesses (many of them exchanges), designed for faster, more private transfers and asset issuance. To use it, real bitcoin is locked on the main chain and an equivalent token, L-BTC, is issued on Liquid; you can later bridge back to ordinary BTC. That bridge, and the federation wallet that backs it, is what the exploit ultimately drained. Crucially, Liquid is a distinct system with its own software and operators; it is not Bitcoin itself.

What actually happened

Blockstream's account, corroborated across crypto and mainstream press, runs as follows:

  • On Sunday 6 September, roughly 4,000 of the about 4,200 BTC in Liquid's federation wallet, around $320 million, were withdrawn.
  • Blockstream attributes the cause to a software bug in the Elements code that underpins the sidechain, not stolen private keys. Reporting indicates the flaw let the attacker create unbacked, "phantom" L-BTC, which was then withdrawn through a legitimate peg-out key at the SideSwap venue; no keys were forged or compromised.
  • On 7 September, the actors returned about 3,400 BTC (about 85 per cent), leaving around 598.5 BTC (about $47 million) outstanding.
  • Blockstream disabled the bridge nodes and asked exchanges to pause L-BTC deposits and withdrawals while it investigates and plans a restart. Exact bug details and the restart timeline had not been published at the time of writing.

Why this is not a hack of Bitcoin

This is the line that gets mangled most, so be precise: Bitcoin, the main chain, was not hacked. No flaw in Bitcoin was exploited, no Bitcoin private keys were broken, and coins held in ordinary Bitcoin wallets were never at risk. The flaw was in the Elements software that runs Liquid, a codebase entirely separate from Bitcoin's. It is the same category of event as an exploit of any layer built on top of a blockchain: the base chain is untouched, and the hole is in the separate software that runs the layer. If you did not hold L-BTC on Liquid, this incident did not involve your coins.

It is also worth being careful with the "$320 million stolen" framing. That figure is the gross amount that briefly moved; because roughly 85 per cent came back, the net outstanding loss is the ~$47 million the attackers kept. Report the $320 million as what was drained, not as what the network ultimately lost.

"White hat," or extortion?

The attackers described their own actions as white-hat, implying they exploited the bug to protect funds and expected a reward. That framing is theirs, not an established fact, and it is contested. Ledger chief technology officer Charles Guillemet publicly pushed back, arguing that a negotiated reward under an on-chain contract "looks more like extortion" than white-hatting. Whether the retained roughly $47 million is best understood as a bounty, a ransom, or simply theft with a public-relations gloss is unresolved, and readers should treat the "good guys" label as a claim the attackers are making about themselves. The wider pattern of exploits against the bridges and layers built around Bitcoin is a recurring theme in crypto security.

Frequently asked questions

Was Bitcoin itself hacked?

No. The exploit hit Blockstream's Liquid Network, a separate Bitcoin sidechain, through a bug in the Elements software that underpins it. Bitcoin's main chain, its code and ordinary Bitcoin wallets were not affected. Only bitcoin represented as L-BTC on Liquid was involved.

What is the Liquid Network and L-BTC?

Liquid is a Bitcoin sidechain run by a federation of businesses for faster, more private transfers. Real bitcoin is locked on the main chain and an equivalent token, L-BTC, is issued on Liquid; you can bridge back to BTC later. The attack targeted the federation wallet and bridge that back L-BTC.

How much was taken, and how much was returned?

Roughly 4,000 BTC (about $320 million) were drained on 6 September 2026. The next day the attackers returned about 3,400 BTC (around 85 per cent), keeping roughly 598.5 BTC, about $47 million. The net outstanding loss is that ~$47 million, not the full $320 million.

Was it stolen keys or a software bug?

Blockstream attributes it to a software bug in the Elements code that underpins the sidechain, not compromised private keys. Reporting indicates it let the attacker create unbacked L-BTC that was then withdrawn through a legitimate peg-out key at the SideSwap venue; no keys were forged.

Are my bitcoin or L-BTC safe?

Bitcoin held on the main chain was never at risk. For L-BTC on Liquid, the network disabled bridge nodes and asked exchanges to pause L-BTC deposits and withdrawals while it recovers, so movements may be frozen until a safe restart. Follow your exchange's and Blockstream's official notices.