Liquid Network was effectively halted after nearly $320 million in Bitcoin left its federation reserve through an abnormal peg-out.
The incident began Sept. 6 when a customer submitted 4,000 L-BTC to SideSwap’s peg-out service, which converts Bitcoin represented on Liquid back into BTC on the main network.
SideSwap said the request passed the normal authorization process and prompted the Liquid Federation to release about 3,996 BTC. The Bitcoin later moved to an address that held roughly 3,998.5 BTC at the latest check.
Liquid disabled its bridge nodes after the withdrawal, while SideSwap suspended swaps, peg-ins, and peg-outs. Exchanges also paused or prepared to pause L-BTC deposits and withdrawals as operators investigated the incident.
The actors controlling the Bitcoin subsequently identified themselves through on-chain messages as “whitehats” and said they intended to return most of the funds once the underlying bug had been fixed across the network.
That prospect could limit the eventual financial loss. However, it does not resolve the more important question of how almost 4,000 BTC left the federation without an apparent key compromise.
The withdrawal appears to have followed the rules
Liquid and SideSwap say the incident did not involve stolen signing credentials.
The withdrawal used SideSwap’s valid Peg-out Authorization Key, or PAK, and Liquid said neither that key nor other federation keys were compromised.
Instead, SideSwap said Blockstream traced the 4,000 L-BTC presented for redemption to a flaw in Elements, the software underlying Liquid.
If that explanation is confirmed, the problem occurred before the Bitcoin transaction was signed.
Liquid is designed to maintain one BTC in its federation reserve for every L-BTC in circulation. During a normal peg-out, L-BTC is burned, and an equivalent amount of Bitcoin is released.

In this case, SideSwap says a software bug created L-BTC without corresponding Bitcoin backing. Those tokens nevertheless entered a valid peg-out process, after which federation functionaries treated the withdrawal as legitimate and released real BTC.
Blockchain security firm Bitslab said at least 11 of Liquid’s 15 functionaries ultimately signed the transaction.
That points to a different type of failure from a conventional bridge exploit. Secure keys provide limited protection if every signer is presented with the same invalid state and accepts it as legitimate.
No independent technical postmortem or detailed patch description was public at the latest check, leaving the precise cause attributed to Liquid and SideSwap.
Whitehats want the bug fixed before returning Bitcoin
Meanwhile, the actors holding the funds have been communicating with Blockstream through Bitcoin transactions carrying OP_RETURN messages.
Galaxy Digital research head Alex Thorn said Blockstream first sent a message asking the holder to contact its security team. The holder later responded that it planned to send “most” of the Bitcoin back to the federation.


A subsequent message added a condition that Blockstream should fix the bug first and ensure every node is patched before returning the funds.
That puts Liquid’s next steps beyond simply recovering the Bitcoin.
The federation must identify and remediate the Elements flaw, distribute the fix across affected nodes, and establish that another batch of invalid L-BTC cannot pass through the same authorization process.
It must also reconcile the reserve.
The allegedly bug-created L-BTC was burned during the peg-out, but about 3,996 real BTC still left Liquid’s federation wallet. Until those funds return or the accounting is otherwise restored, the network still has to demonstrate that legitimate outstanding L-BTC remains backed one-for-one.
Liquid’s bridge nodes remain disabled while that work continues.
While the incident may ultimately end with most of the Bitcoin recovered, the harder task is proving that the system which authorized its release cannot make the same mistake twice.






