
A software bug in the Elements protocol allowed the creation of unbacked L-BTC, leading to a massive unauthorized withdrawal from the Liquid Federation reserve.
AI-generated summary
Liquid Network is a sidechain for Bitcoin that uses a federation to manage reserves. It relies on the Elements software to facilitate peg-in and peg-out transactions.
Liquid Network was effectively halted after nearly $320 million in Bitcoin left its federation reserve through an abnormal peg-out.
The incident began Sept. 6 when a customer submitted 4,000 L-BTC to SideSwap’s peg-out service, which converts Bitcoin represented on Liquid back into BTC on the main network.
SideSwap said the request passed the normal authorization process and prompted the Liquid Federation to release about 3,996 BTC. The Bitcoin later moved to an address that held roughly 3,998.5 BTC at the latest check.
Liquid disabled its bridge nodes after the withdrawal, while SideSwap suspended swaps, peg-ins, and peg-outs. Exchanges also paused or prepared to pause L-BTC deposits and withdrawals as operators investigated the incident.
The actors controlling the Bitcoin subsequently identified themselves through on-chain messages as “whitehats” and said they intended to return most of the funds once the underlying bug had been fixed across the network.
That prospect could limit the eventual financial loss. However, it does not resolve the more important question of how almost 4,000 BTC left the federation without an apparent key compromise.
The withdrawal appears to have followed the rules
Liquid and SideSwap say the incident did not involve stolen signing credentials.
The withdrawal used SideSwap’s valid Peg-out Authorization Key, or PAK, and Liquid said neither that key nor other federation keys were compromised.
Instead, SideSwap said Blockstream traced the 4,000 L-BTC presented for redemption to a flaw in Elements, the software underlying Liquid.
If that explanation is confirmed, the problem occurred before the Bitcoin transaction was signed.
Liquid is designed to maintain one BTC in its federation reserve for every L-BTC in circulation. During a normal peg-out, L-BTC is burned, and an equivalent amount of Bitcoin is released.
In this case, SideSwap says a software bug created L-BTC without corresponding Bitcoin backing. Those tokens nevertheless entered a valid peg-out process, after which federation functionaries treated the withdrawal as legitimate and released real BTC.
Blockchain security firm Bitslab said at least 11 of Liquid’s 15 functionaries ultimately signed the transaction.
That points to a different type of failure from a conventional bridge exploit. Secure keys provide limited protection if every signer is presented with the same invalid state and accepts it as legitimate.
No independent technical postmortem or detailed patch description was public at the latest check, leaving the precise cause attributed to Liquid and SideSwap.
Whitehats want the bug fixed before returning Bitcoin
Meanwhile, the actors holding the funds have been communicating with Blockstream through Bitcoin transactions carrying OP_RETURN messages.
Galaxy Digital research head Alex Thorn said Blockstream first sent a message asking the holder to contact its security team. The holder later responded that it planned to send “most” of the Bitcoin back to the federation.
A subsequent message added a condition that Blockstream should fix the bug first and ensure every node is patched before returning the funds.
That puts Liquid’s next steps beyond simply recovering the Bitcoin.
The federation must identify and remediate the Elements flaw, distribute the fix across affected nodes, and establish that another batch of invalid L-BTC cannot pass through the same authorization process.
It must also reconcile the reserve.
The allegedly bug-created L-BTC was burned during the peg-out, but about 3,996 real BTC still left Liquid’s federation wallet. Until those funds return or the accounting is otherwise restored, the network still has to demonstrate that legitimate outstanding L-BTC remains backed one-for-one.
Liquid’s bridge nodes remain disabled while that work continues.
AI outlook — possibilities, not facts
Blockstream will release a patch for the Elements protocol.
Very likely · Within weeks

Ethereum-compatible layer-1 network Harmony proposed sunsetting its blockchain and migrating its native ONE token to Ethereum via an airdrop, following a recent exploit that created forged tokens.

Bitcoin sidechain Liquid paused operations after actors claiming to be white-hat hackers withdrew about 4,000 Bitcoin worth $320 million from its federation wallet.

Approximately 4,000 Bitcoin worth $319 million were drained from the Liquid Network sidechain, with unverified claims of a whitehat hack via an OP_RETURN message. Blockstream paused bridge nodes and advised exchanges to halt LBTC transactions while investigating. Funds moved through SideSwap using a non-compromised Peg-out Authorization Key, with Blockstream citing a bug in Elements software as the cause. Analysts suggest the lack of mixing indicates a whitehat extraction, though security flaws remain under scrutiny.

OpenAI released GPT-6 Astra on September 3, showcasing strong performance in visual understanding, coding, and computer use, including generating 3D models of cities and writing Bach-style music, but receiving criticism for poor writing quality compared to its predecessor, with pricing at $10 per million input and $50 per million output tokens.

Aave DAO voters are deciding whether to delegate limited V4 risk controls on Ethereum and Avalanche to Risk Stewards, allowing approved operators to make constrained changes without full governance votes. The proposal includes no-delay emergency roles that current steward software cannot use, with approval requiring execution by the V4 Security Council. The Risk Steward contracts are undergoing a Certora audit, nearing finalization. Emergency roles would be inert until a future release adds support, but assigning them now would enable faster emergency response later.

Trezor disclosed that a breach at logistics provider ShipMonk exposed contact and order data for approximately 67,000 additional U.S. customers, expanding the initial incident from 13,689 to a total of roughly 80,689 potentially affected individuals. The exposed data includes names, emails, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021, despite Trezor's 90-day data deletion policy and written assurances from ShipMonk. The breach did not compromise Trezor's wallet systems or private keys, but poses risks of phishing, fraud, and physical targeting.