SECURITY

Post-mortem: How an Elements bug claim and a SideSwap peg-out path moved ~4,000 BTC out of Liquid’s federation wallet

Sep 7, 2026 · SECURITY

On the Sep 6–7, 2026 window, Liquid Network said actors claiming white-hat status withdrew about 4,000 BTC, worth about $320 million, from the federation wallet that backs L-BTC. Cointelegraph (Ezra Reguerra, updated Sep 7, 07:30 UTC) framed the take as roughly 95% of the wallet’s approximately 4,200 BTC balance. Bitcoin Magazine reported a peg-out of 4,019.4 BTC through the SideSwap Peg-out Authorization Key (PAK) to an address ending 6gyqjlte, with an OP_RETURN-style message reading “we are whitehats. contact us on chain.” Cointelegraph’s Hodler’s Digest said Liquid explorer data showed the federation wallet balance falling from about 4,200 BTC to 207.275 BTC, and described the extraction as a shade under 4,000 BTC / about $319 million.

What makes this an Expert Arena case is the split between reserve design and software path. Liquid is a federated Bitcoin sidechain: L-BTC is meant to be backed by BTC held under federation control. Under normal mechanics described in public coverage, L-BTC is burned on the sidechain before BTC leaves reserves, and movement from the treasury is framed as an 11-of-15 federation multisig over a large multi-member set. A large unexpected peg-out does not merely move coins; it drains the reserve that makes the peg accounting credible for remaining L-BTC holders until funds return or reserves are rebuilt.

Two trust layers matter more than the headline. First is Elements software correctness: what L-BTC can be created or spent on the sidechain. Second is the peg-out authorization path that lets a seemingly valid customer order move mainnet BTC. SideSwap said the withdrawal passed through its peg-out service as a customer order using its PAK, and that the PAK itself was not compromised. It said the L-BTC used in the order originated from a bug in Elements, the open-source software underpinning Liquid, rather than from SideSwap systems. Liquid’s own messaging, as relayed by outlets, also said funds left via the SideSwap PAK without that key being compromised. Bitcoin Magazine noted an inflation-bug narrative on the L-BTC side as a leading hypothesis, while full public technical confirmation of the exact consensus path remained incomplete at the time of those reports. The cautious reading is therefore: key compromise is not the story the operators are telling; invalid or unexpected L-BTC creation plus a legitimate-looking peg-out is.

Operational response isolated the BTC peg surface. Liquid said bridge nodes were disabled, preventing new transactions on that rail, while exchanges halted or prepared to halt L-BTC deposits and withdrawals. Other assets issued on Liquid — including USDT, DePix and real-world assets — were described as unaffected. That split is informative: the network treated the incident as a peg-reserve problem, not a blanket freeze of every Liquid-issued asset.

The disclosure channel was also unusual. Blockstream contacted the actors through signed on-chain messages. JAN3 CEO Samson Mow compiled a public timeline from those embedded messages: exchange began at 11:30 am Pacific time when the actors identified as white hats and requested on-chain contact; Blockstream replied about an hour later pointing to its security email, then sent a PGP-encrypted message; hours later the actors asked whether they could return most BTC to a Blockstream address and demanded the vulnerability be fixed and every node updated before transfer. Mow said Blockstream’s “Yes, thank you” answered the return-address question, not the patching condition. Cointelegraph reported about 3,998.5 BTC still unmoved at that checkpoint, with no further messages as of 9:12 pm Pacific time in that writeup, and funds not returned at the time of writing. Self-description as white hats is a claim, not proof of intent; the observable facts are the reserve drain, the pause, and the conditional-return negotiation still open in public reporting.

What would update or falsify this reading: funds returned without a further peg-out; a Blockstream or Liquid post-mortem naming a root cause other than an Elements bug; confirmed PAK or federation key compromise; L-BTC circulating-supply accounting that does not match a pure reserve drain; or additional peg-outs after the bridge pause. Until those arrive, the mechanism signal is clear: sidechain peg credibility rests on both software correctness and the authorization path that turns sidechain claims into mainnet BTC.

Key signals

Cointelegraph (Ezra Reguerra, Sep 7, 2026); Cointelegraph Hodler’s Digest; Bitcoin Magazine; Liquid Network / SideSwap statements via those outlets; Samson Mow (JAN3) on-chain message timeline

Content on this page is for informational purposes only and is not financial advice.