Liquid Network recovered $268 million of the roughly $320 million in Bitcoin drained from its federation wallet on September 6, 2026, but the actors behind the exploit are still holding about $47 million, and Blockstream has not said why its system approved the withdrawal in the first place.
At first, the incident looked like the kind of crypto attack the industry has seen many times before, a huge amount of Bitcoin disappears and everyone starts asking whether the hackers stole the keys.
But that is not what happened.
Liquid says no federation key was compromised. SideSwap, the service involved in the redemption, also said its systems and Peg-out Authorization Key were not compromised.
So how did almost $320 million leave?
That question makes this incident more serious than a simple stolen-key attack.
How did $320 million leave without anyone stealing the keys?
To understand the incident, it helps to understand how Liquid works.
Liquid is a Bitcoin sidechain. Users can move Bitcoin into Liquid and receive L-BTC, a token designed to represent Bitcoin on the network at a 1:1 ratio.
When a user wants to move back to Bitcoin, the process works in reverse.
The L-BTC is burned and the Liquid federation releases the corresponding Bitcoin from its federation wallet. That is where the incident became unusual.
SideSwap said a customer sent about 4,000 L-BTC to its peg-out service at 14:05 UTC on September 6. The L-BTC was burned through what appeared to be a valid peg-out authorization.
Roughly 23 minutes later, the federation released about 3,996 BTC to the customer’s Bitcoin address.
The transaction therefore did not simply bypass Liquid’s security.
Liquid’s security appears to have been convinced that the withdrawal was valid.
If someone steals a federation key, the problem is obvious, the attacker controls the authority that can move the Bitcoin.
Here, the more important question is whether the software that determines what is valid was fooled before the federation ever signed the transaction.
Was the software the real gateway?
Liquid is built on Elements, an open-source blockchain platform developed by Blockstream.
Elements handles important parts of transaction validation, including the cryptographic checks used by Liquid.
Researchers have pointed to a possible problem involving Liquid’s confidential transactions, range-proof validation and a validation cache.
The theory is complicated, but the basic idea is not.
Liquid hides transaction amounts through confidential transactions. The network still needs to verify that those hidden amounts are valid and that new assets have not simply been created from nothing.
Some of those checks are expensive, so validation results can be cached.
If that cache incorrectly treats two different validation situations as the same, a malicious transaction could potentially reuse a result that should not belong to it.
In the worst case, that could allow invalid or unbacked L-BTC to pass validation.
This remains an independent technical theory, not a publicly confirmed final root-cause report from Blockstream.
That distinction is important because the exact vulnerability and the precise path used by the attackers are still being investigated.
But what exactly was the software bug?
Independent code analysis has focused on a recent Elements change involving the binding of range-proof cache entries to an asset and output script.
Some believe the change may have introduced a collision that could be exploited under particular conditions.
There has also been confusion about when the relevant code entered Elements, which versions contained it and which Liquid federation nodes were running those versions.
Some reports have suggested that a relevant fix had been added shortly before the attack.
But Bitcoin developer Mononaut has pushed back against simplified versions of that explanation, pointing to differences between development code, tagged releases and what federation members were actually running.
In other words, the timeline is not yet clean enough to say:
“This exact software update caused the $320 million loss.”
It is safer to say that the incident appears connected to a vulnerability in the software validation layer, while the exact technical chain remains under investigation.
And that uncertainty matters.
Because if the vulnerability was caused by a particular implementation, the next question is whether other Elements-based systems could be exposed to the same class of problem.
What happens when valid signatures approve invalid money?
This may be the most important lesson from the incident.
Liquid’s federation reportedly requires a large majority of its functionaries to authorize peg-outs.
That sounds extremely difficult to attack.
But multisignature security only protects the signing authority.
It does not automatically guarantee that the information presented to the signers is correct.
Imagine a bank with 15 executives who must agree before a vault can be opened.
The executives are honest. Their keys are secure.Nobody breaks into the vault.But an employee gives them a document saying that a customer has deposited $1 billion when the customer actually deposited nothing.
The executives check the document, approve the withdrawal and open the vault.The keys were never stolen.The security failure happened earlier.That is the concern Liquid now has to address.
The question is not simply whether the federation signed correctly. It is whether the software gave the federation something correct to sign.
Then why did the attackers return $268 million?
This is where the story took another unexpected turn.The people behind the exploit later described themselves as white-hat hackers.
They communicated with Blockstream through Bitcoin’s OP_RETURN messaging system and indicated that the vulnerability should be fixed before the funds were returned.
After Blockstream sent an on-chain message saying the bridge nodes had been patched and the funds were safe to return, about 3,400 BTC was sent back to the Liquid Federation wallet.
That is roughly $268 million at the prices reported around the time.
The return dramatically changed Liquid’s immediate financial position.
But it did not end the controversy.
Why are the hackers still holding $47 million?
About 598.5 BTC remains in the address associated with the actors. That was worth roughly $47 million at the time.And there is currently no publicly disclosed agreement showing that this amount is an officially negotiated bug bounty.
If the actors genuinely intended to protect Liquid, why keep nearly $47 million?One possibility is that they consider the Bitcoin a security bounty.
Another is that they are holding it temporarily while waiting for further assurances about the vulnerability and the network’s patches.
A more troubling possibility is that they discovered a vulnerability, exploited it and only later adopted the language of white-hat hacking.
Ledger CTO Charles Guillemet has questioned the white-hat characterization, arguing that without a negotiated reward agreement, keeping roughly 600 BTC can look more like extortion than responsible disclosure.
That is his assessment, not proof that the actors are extortionists.
But it states the central problem: there is no publicly established agreement explaining exactly why $47 million remains with them.
What could happen to the remaining 598.5 BTC?
There are several realistic possibilities.
The Bitcoin could still be returned
The actors could eventually return the remaining funds after Liquid demonstrates that the vulnerability has been fully addressed.
If that happens, the incident may ultimately be remembered as an extreme form of white-hat intervention.
But the amount involved would still make the operation highly controversial.
The Bitcoin could become a disputed bounty
Liquid or Blockstream could potentially negotiate a reward with the actors.That would give a clearer explanation for why some Bitcoin was retained.But no such public agreement has been established as of September 8th,2026.
The actors could keep it
This is the scenario that would create the biggest reputational problem.Keeping almost $47 million would make it harder to argue that the operation was purely about protecting users.
It could also trigger legal questions, depending on the identities and jurisdictions involved.
The incident could expose a wider software problem
This may be the most important possibility.If the underlying vulnerability affects other versions or deployments of Elements, Liquid may not be the only system that needs to be examined.
That could turn a $320 million Liquid incident into a broader blockchain infrastructure security problem.
Is Liquid financially safe again?
Much safer than it was on September 6.Before the incident, the federation wallet held roughly 4,200 BTC.After almost 4,000 BTC left, only around 200 BTC remained temporarily.
That meant Liquid’s Bitcoin reserves were suddenly only a small fraction of the L-BTC supply that users expected to be backed.
With 3,400 BTC returned, most of the missing Bitcoin is back.But restoring the coins is not the same thing as restoring confidence.
Liquid has paused the network, disabled bridge nodes and exchanges have suspended L-BTC deposits and withdrawals.There is also no clear public restart date yet.
And users now have to ask a different question:
Can Liquid prove that the software responsible for validating its assets is safe enough to trust again?
The bigger risk may be the loss of trust
A sidechain built around a 1:1 Bitcoin representation depends heavily on confidence.
If users believe every L-BTC can be redeemed for one real Bitcoin, the system works as intended.
If they start believing that software bugs can create unbacked L-BTC, the entire assumption becomes weaker.
That is why this incident could have consequences beyond the $320 million that moved.
The returned 3,400 BTC solves much of the immediate balance-sheet problem.It does not automatically solve the credibility problem.
Liquid will likely need to demonstrate that the vulnerability has been understood, that affected software has been patched and that federation members are running the correct versions before normal operations can safely resume.
And exchanges will have their own risk assessments to make before reopening L-BTC deposits and withdrawals.
What this incident really exposes about crypto security
The easy headline is that hackers drained $320 million from Liquid.
The harder story is more revealing.
Nobody needed to steal the federation keys.
The system’s own rules were apparently enough to authorize the movement of the Bitcoin after invalid L-BTC was accepted somewhere in the validation process.
That changes how the incident should be understood.Crypto projects spend enormous resources protecting private keys, multisignature wallets and signing infrastructure.
But what happens when the software deciding whether something deserves to be signed is wrong?
A perfectly secured key can still authorize a bad transaction if the system around that key has already been deceived.That is the lesson Liquid now has to confront.
The 3,400 BTC return may have rescued most of the money.
But the remaining 598.5 BTC, the unresolved technical questions and the uncertainty surrounding the so-called white-hat attackers leave a much bigger issue on the table.
The real question is no longer where the $47 million is.
It is whether Liquid can prove that the software deciding what deserves redemption can be trusted again.