Join the movement to end censorship by Big Tech. StopBitBurning.com needs donations and support.
Liquid Network Sidechain Targeted By Alleged White-Hat Hackers
By sterlingashworth // 2026-09-08
Mastodon
    Parler
     Gab
 
The Liquid Network – a federated sidechain of Bitcoin founded by Blockstream – reported Sunday, Sept. 6 that purported white-hat hackers withdrew approximately 4,000 bitcoin from the federation wallet that backs its L-BTC token, according to reports. The stolen amount was worth about $320 million at the time of the transaction. The official Liquid Network account stated on X that bridge nodes were disabled and the sidechain was paused following the withdrawal. Other issued assets, including USDT, DePix and real-world assets, were unaffected, the announcement said [1]. The suspected hackers left a message in the transaction's OP_RETURN data field stating "we are whitehats. contact us on chain," a disclosure that suggests a coordinated alert rather than a typical theft. The incident has raised questions about the security of federated sidechains, which were previously described by proponents as resistant to unauthorized transactions due to their multisignature requirements [2]. While the pause limits user access, the sidechain itself continues to produce blocks, according to network data [1].

Background on Liquid Network

The Liquid Network is a federated sidechain of Bitcoin developed by Blockstream, a company led by CEO Adam Back, according to company information [3]. The chain issues L-BTC, a token backed by bitcoin held in a multisig wallet on the Bitcoin main chain. This treasury requires signatures from 11 of the 15 federation members to authorize a movement of coins, a security structure designed to prevent unilateral actions [1]. The federation consists of known corporate members, including exchanges and financial infrastructure providers, who operate the network's signing servers [3]. Before the incident, the treasury held over 4,200 BTC, according to records cited in the report. After the withdrawal, Blockstream's proof-of-reserves page indicated slightly more than 207 BTC remaining [1]. The network's operational model, which relies on a trusted set of functionaries, was described in the company's earlier literature as a mechanism to avoid the liquidity shortages and market fluctuations associated with independent altcoins [2]. The attack appears to have bypassed the intended safeguards by exploiting a flaw in the network's consensus rules rather than compromising individual member keys.

Hack Details and Method

The attackers withdrew 4,019.4 BTC from the federation's reserve address in a peg-out transaction that used the SideSwap Peg-out Authorization Key, according to preliminary reports [1]. SideSwap is a bridge exchange and a member of the Liquid Federation. Investigators suspect that the hackers exploited an inflation bug on the L-BTC sidechain, which allowed them to create over 4,000 L-BTC that did not previously exist and subsequently redeem those tokens for bitcoin on the main chain, the report noted. Because the transaction appeared valid under the compromised consensus rules, federation members' hardware security module (HSM) servers signed the bitcoin withdrawal transaction, transferring funds to an address ending in 6gyqjlte [1]. The hackers then signed an OP_RETURN message from that address stating, "we are whitehats. contact us on chain." A small mainnet transaction to the hacker address was followed by an OP_RETURN reading "Please contact [email protected]", which reports indicate may have originated from a Blockstream public address, though that remains unconfirmed. A later OP_RETURN spend from the hacker address carried a message reading "Please contact us on Signal @m671aw.70"; however, analysts cautioned that this may be spam and does not share a link to the address holding the stolen funds [1].

Response and Operational Impact

In response to the breach, exchanges were instructed to pause L-BTC deposits and withdrawals, according to official notices. Bridge nodes on the Liquid Network were paused, which limited access to the sidechain even as the network continued to produce blocks [1]. JAN3 CEO Samson Mow stated that Aqua's Liquid features were affected but added that on-chain bitcoin operations continued to function normally [1]. Industry reports indicate that other wallets relying on the Liquid Network are expected to experience disruptions as a result of the paused bridges [1]. The security incident has reignited concerns about the safety of custodial and federated systems in the cryptocurrency industry. Previous collapses of centralized crypto lending platforms, such as Celsius Network and Voyager Digital, demonstrated how quickly user funds can become trapped when intermediaries fail [4]. Unlike the public Bitcoin blockchain, where every transaction is recorded openly, the Liquid chain is private, which limits external visibility into its operations, a point of criticism among proponents of transparent ledgers [5].

Outlook and User Implications

Holders of L-BTC now face immediate redemption risk because the underlying bitcoin is currently not redeemable, officials said [1]. The private nature of the Liquid chain limits on-chain analytics, leaving uncertainty about the distribution of L-BTC among retail and corporate users. If the withdrawn funds are not returned, the Liquid Network's user base could suffer substantial losses, according to some analysts [1]. Speculation among observers suggests the hackers may negotiate a "finder's fee" and return the majority of funds, though no official comments have been made regarding such negotiations [1]. The incident highlights broader concerns about decentralized systems that still rely on trusted intermediaries, as the federated model of the Liquid Network differs fundamentally from the trustless model of Bitcoin itself. As one analysis noted, the success of Bitcoin and cryptocurrencies should be measured by how much freer the world has become, not by the fortunes of early investors or corporate entities [2]. For now, users of L-BTC have limited options but to wait for the resolution of communications with the hackers.

References

  1. Juan Galt. "Alleged White-Hat Hackers Withdraw 4,000 Bitcoin From Blockstream's Liquid Network Federation Reserves". Zero Hedge. September 7, 2026.
  2. Roger Ver. "Hijacking Bitcoin".
  3. Unknown. "Hijacking Bitcoin The Hidden History of BTC Roger Ver Steve Patterson".
  4. NaturalNews.com. "Desperate crypto investors scramble beg to withdraw their money". July 26, 2022.
  5. Mike Adams. "Mike Adams interview with Chris Olsen". June 2, 2025.

Explainer Infographic

Mastodon
    Parler
     Gab