VERSE PRESS

Crypto News, Global First.

Liquid Network Hit by $320 Million Bitcoin Drain as Attackers Claim White-Hat Status

Blockstream's federated Bitcoin sidechain lost roughly 95% of its BTC reserves on September 6 after parties claiming to be security researchers exploited a protocol-level software bug. The incident has halted operations across a network used by nearly 60 exchanges and institutions worldwide.

|

Unknown actors drained approximately 4,000 BTC, worth around $320 million at the time, from the Liquid Network federation wallet on September 6, 2026. The Liquid Network is a Bitcoin sidechain built by Blockstream and governed by a federation of exchanges and financial institutions, designed to enable faster and more confidential settlement between exchanges and institutional traders. The withdrawal stripped the network of roughly 95% of its total Bitcoin reserves, leaving only about 207 BTC in the federation wallet. Shortly after, Liquid Network paused all bridge nodes and instructed every connected exchange to halt deposits and withdrawals of LBTC, the sidechain's native Bitcoin-pegged token.

The attackers left two messages embedded directly in Bitcoin transaction data using a protocol field called OP_RETURN, which allows parties to attach text to a transaction. The first read: "we are whitehats. contact us on chain." A second pointed to a Signal handle, @m671aw.70, for further contact. Liquid Network's official account confirmed that the Blockstream team was working to reach the parties on-chain with a signed message. The claim of white-hat status, meaning a security researcher who exposes flaws rather than stealing funds, has not been verified and is contested by at least one senior industry figure.

Charles Guillemet, chief technology officer of hardware wallet maker Ledger, whose company is a member of the Liquid Federation, publicly challenged the white-hat framing. He argued that withdrawing hundreds of millions of dollars before initiating contact diverges substantially from how legitimate security researchers typically operate, noting that responsible disclosure usually means alerting a project to a vulnerability before touching its funds. He pointed to the 2022 Ronin bridge theft and the 2023 Euler Finance exploit as cases where attackers communicated only after the fact. His position: moving collateral first and asking questions later differs sharply from conventional vulnerability disclosure practices.

The root cause is a software bug, not a stolen key. Technical analysis by SpendNode attributed the incident to a flaw in Elements, the open-source blockchain codebase that Liquid is built on. Investigators described it as a mint bug, a consensus-layer error that can allow the network to accept the creation of LBTC units that have no real BTC backing them. This is a meaningful technical distinction. A stolen private key would mean real BTC physically left the federation multisig wallet. A mint bug, by contrast, means unbacked LBTC could be created without moving real BTC reserves: a consensus-level flaw that lets the network accept something it should reject. Liquid Network confirmed that SideSwap's Peg-out Authorization Key, a credential used in the withdrawal process, was not itself stolen, which points toward the software flaw explanation. Whether actual BTC has left federation custody or whether this is primarily a peg-integrity crisis remains unresolved as of publication. Either way, existing LBTC holders face dilution risk until the discrepancy is reconciled.

The hack lands in a damaging context for the broader sector. More than $1.3 billion has been lost to DeFi exploits in 2026 through the end of August, and bridge and infrastructure attacks have accounted for roughly 76% of total losses by dollar value. The Liquid incident would rank among the two or three largest single events of the year, comparable to the KelpDAO exploit in April, which cost approximately $292 million. For context, only approximately 0.8% of circulating Bitcoin is used in any DeFi setting, compared to roughly 30% of Ether, a figure that illustrates why Liquid remained a niche, institution-adjacent layer and helps calibrate the incident's broader systemic significance. Other assets issued on the Liquid Network, including USDT, DePix, and tokenized real-world assets, were reported as unaffected.

The operational fallout is concentrated heavily in Asia. A significant share of Liquid Federation members are exchanges and institutions operating across Asian markets. Global exchanges with significant Asian user bases, including Bitfinex and Huobi, along with multiple Japan-licensed platforms such as bitbank, BTCBOX, Coincheck, DMM Bitcoin, and GMO Coin, as well as South Korea's Coinone and GOPAX, and Singapore's Coinut, have all been instructed to suspend LBTC activity. For institutional traders in those markets who rely on Liquid's two-block finality for rapid Bitcoin settlement between counterparties, the suspension creates immediate operational gaps with no public timeline for resolution disclosed as of publication. In South Asia, no major exchanges are direct federation members, but institutional traders routing through Bitfinex or OKX face the same settlement freeze. The broader risk for the region is reputational: India's crypto market processed over $29 billion in on-chain volume in 2025, and growing interest in Bitcoin Layer 2 infrastructure for remittance and cross-border payments now faces a high-profile federated sidechain failure as a cautionary reference point.

The incident carries significant implications for Africa's emerging Bitcoin ecosystem as well. Across Nigeria, Ghana, Kenya, and South Africa, where Bitcoin adoption has accelerated on the back of currency instability and remittance demand, the federated sidechain model had been under evaluation as a potential settlement and payments layer. The Liquid exploit puts that calculus in question. Non-custodial alternatives offer a meaningful contrast in this context: Machankura, a Lightning Network-based service built for feature phones, bypasses the consortium trust requirement entirely, operating without a federation of parties holding pooled backing assets. For African Bitcoin fintech developers weighing infrastructure choices, the September 6 event illustrates precisely what is at stake when software governs a consortium-held reserve and the software fails.

Blockstream's own May 2026 roadmap had already signaled a planned shift toward a BitVM 1-of-n bridge model, an approach in which any one of n parties can independently exit without requiring trust in the broader consortium. That architecture would substantially reduce the network's dependence on a federation of trusted parties holding backing assets, and it addresses directly the structural vector the September 6 exploit exposed. That transition now carries far greater urgency. The hack surfaces a structural question that federated peg models have always carried: a consortium controlling billions in backing assets is only as safe as the software governing how those assets move. For exchanges, developers, and remittance-focused projects across emerging markets that were evaluating Liquid as a settlement layer, the answer they received on September 6 arrived at considerable cost.


Verse Press is continuing to monitor on-chain activity. Fund recovery and peg reconciliation status remain unconfirmed at time of publication.