Liquid Sidechain Halted as ‘White Hats’ Drain 4,000 BTC via Elements Bug, On-Chain Talks Begin
Blockstream’s Liquid paused after ~4,000 BTC (~$320M) left its federation wallet via a software bug. Hackers propose returns if a patch is deployed network-wide.

Because Bitcoin
September 7, 2026
What broke here wasn’t a multisig—it was governance. Blockstream’s Liquid sidechain is paused after roughly 4,000 BTC—about $320 million—exited the federation wallet that backs L-BTC. The incident flowed through a valid peg-out path, revealing how a subtle software flaw can overpower careful key management when patch discipline lags.
What happened - Sunday at 14:05 UTC, SideSwap (a Liquid federation member running a peg-out service) received 4,000 L-BTC from a customer and burned them with a valid authorization. Twenty-three minutes later, the federation paid out 3,996 BTC. - Liquid said the withdrawal moved using SideSwap’s Peg-out Authorization Key, but emphasized that neither that key nor any other federation key was compromised. - SideSwap reported no system breach and pointed instead to a bug in Elements, the software underlying Liquid. Blockstream has not detailed the flaw, though a fix was committed to the codebase five weeks earlier. - This wasn’t a forced drain; someone appears to have created L-BTC not backed by Bitcoin and redeemed it via a normal-looking peg-out. - The federation wallet fell from around 4,200 BTC to roughly 200 BTC—about 5% of its prior balance. Bridge nodes were disabled, effectively pausing the network.
On-chain negotiations - The withdrawing party embedded an on-chain note stating they were white hats and asked to coordinate on-chain. Blockstream responded with contact details, and both sides have been exchanging PGP-signed messages inside Bitcoin transactions. - The hackers offered to return most of the BTC, conditional on the bug being patched and every node updated—arguing the chain remains at risk on the latest commit. Blockstream acknowledged the offer on-chain. - Ledger CTO Charles Guillemet questioned the “white hat” framing, likening the pattern to episodes like Ronin or Euler, and argued that modern practice often withholds funds until fixes land—an ethical gray that looks protective to some and coercive to others. - Former Blockstream security lead Samson Mow shared a timeline and estimated the relevant address at about 3,998.5 BTC.
Blast radius and price context - Other Liquid-issued assets—including USDT, DePix, and various tokenized RWAs—were untouched. Bitcoin’s base layer is unaffected. - BTC traded around $79,420 (-0.64% 24h) with a 24h range of $79,081–$80,494 and ~$827.8M volume (CoinGecko). Prediction odds (Myriad): 86% for a $78k–$80k range today; 58% chance BTC finishes the week below $80k.
My take: federated patch latency is the real risk Federated bridges live and die by invariants—chiefly that circulating L-BTC equals BTC held in the federation. Here, the failure path wasn’t signature theft; it was an Elements bug that let an adversary synthesize unbacked L-BTC and pass standard checks. A fix existed five weeks earlier but hadn’t propagated. In federations, update cadence, coordination, and invariant enforcement are as critical as cryptography.
Technically, Liquid needs defense-in-depth around backing verification and peg-out gating: - Block peg-outs on any detected supply mismatch between L-BTC and BTC in custody. - Add real-time invariant proofs before authorizing redemptions, with circuit-breakers and rate limits. - Enforce mandatory, staged rollouts for consensus-critical patches across signers, with automated health checks.
From a business and reputational lens, this is a credit exposure to governance, not just a software bug. Traders often price L-BTC as tightly pegged; episodes like this argue for a nonzero governance premium until invariant checks are provably automated and frequently audited.
The “white hat” posture complicates disclosure norms. Conditioning returns on network-wide updates can be read as responsible containment or leverage. Either way, public PGP-signed coordination on-chain is becoming an incident-management pattern, and teams should be prepared to engage in that theater without conceding control.
Expect funds to come back if the patch deploys cleanly across nodes. Until then, participants should assume tighter withdrawal controls, slower peg-outs, and heightened monitoring across federated bridges—where the soft risk surface is coordination, not keys.