On September 6, 2026, approximately 4,000 BTC, worth approximately $320 million, was withdrawn from the Liquid Network federation wallet, a Bitcoin sidechain developed by Blockstream. This is almost 95% of all network reserves: before the incident, just over 4,200 BTC were stored in the treasury, and after the attack, according to the Blockstream Proof of Reserves page, only about 207 BTC remained. The network was immediately shut down, bridge nodes were disabled, and exchanges suspended L-BTC deposits and withdrawals.

Technical mechanism: emission bug, not stolen keys

According to preliminary data from Bitcoin Magazine, the cause was an error in the L-BTC issuance logic on the side chain - the attackers were able to “draw” more than 4,000 L-BTC tokens that actually had no collateral, taking advantage of a consensus bug. Since from the point of view of the internal logic of the network the transaction looked legitimate, the hardware security modules (HSMs) of the federation members automatically signed a request to withdraw real bitcoin from the reserves - in fact, the system itself “believed” that the fake tokens should be exchanged for real coins.

After withdrawing about 3,996 BTC to an external address, the attackers almost immediately signed a new transaction with a text message in the OP_RETURN field: “We are the ‘good guys.’ Contact us via blockchain.” The term “white-hat hackers” traditionally refers to security researchers who exploit vulnerabilities without malicious intent and typically return funds — sometimes for a reward. The Liquid Network team officially named the attackers as such, saying that Blockstream was attempting to reach out via a signed on-chain message.

However, there is currently no evidence that the funds will actually be returned - the industry is treating this statement with cautious skepticism, as similar wording is often used by attackers with other intentions to buy time for negotiations on a “reward”. An important nuance: other assets issued on the Liquid Network - including USDT, DePix and tokenized real assets (RWA) - were not affected by the attack, only the Bitcoin reserves that provide L-BTC were affected.

According to Aneurin Flynn, CEO of cybersecurity company FailSafe, preliminary data points to the exact bug that allowed the unauthorized issuance of L-BTC:

“With around 95% of reserves withdrawn and the network halted, the incident exposes a critical weakness in Liquid’s validation and provisioning model.”

This hack was far from the first blow to trust in the crypto market infrastructure in recent weeks: just a week before, an unknown attacker withdrew $6 million from a credit platform associated with Crypto.com, and in August, the hacking of the Coldcard hardware wallet caused a huge uproar, which called into question the security of even offline storage of crypto assets.

Who is Liquid Network?

Liquid Network, founded in 2018 by Blockstream — a company co-founded by Adam Beck, one of the crypto pioneers whose work was mentioned in the original Bitcoin whitepaper — is used by exchanges specifically to speed up settlements, as the main Bitcoin chain is often congested and expensive for fast transfers. The network’s clients include venues such as BTSE, Bitfinex and BitMEX. The company has not yet said when it plans to resume operations on the network, nor has it disclosed details of its negotiations with the alleged “good guys.”

#LiquidNetworkHacked