A federation wallet loses 95 percent of its bitcoin in one transaction

On September 6, 2026, roughly 4,019 BTC, worth about 320 million dollars, moved out of the federation wallet backing Blockstream's Liquid Network, a Bitcoin sidechain used by exchanges and trading desks to move bitcoin faster and more privately than the main chain allows. The federation's reserves fell from about 4,200 BTC to 197 BTC in a single withdrawal. Liquid confirmed the funds left through the SideSwap Peg-out Authorization Key, the mechanism a partner exchange uses to redeem its Liquid-based bitcoin token, L-BTC, for real bitcoin on the main chain.

Blockstream disabled the network's bridge nodes within hours, pausing new transactions, and notified exchanges to halt L-BTC deposits and withdrawals. Tether, the Brazilian real-pegged DePix token, and other real-world assets issued on Liquid were unaffected; only the bitcoin reserve was drained. An on-chain message embedded in a Bitcoin transaction and attributed to the people who moved the funds read: "we are whitehats. contact us on chain."

How you steal 320 million dollars without stealing a single key

Liquid's own statement narrowed the cause immediately: "the SideSwap key was not compromised, nor had any others." That single line separates this incident from almost every other bridge hack of the past few years, which typically involve a stolen private key or a forged multisignature approval. Here, the federation's signers approved a withdrawal that looked entirely legitimate under the sidechain's own consensus rules. Blockstream has confirmed only that the L-BTC involved "was created through a bug in the Elements software," the open-source codebase that runs Liquid, without naming the specific defect.

The mechanics reported by outside analysis: the attacker submitted a peg-out request for roughly 3,996 L-BTC through SideSwap. Because the underlying tokens passed the network's validity checks despite not being backed by any real bitcoin, the federation's automated signing servers treated the request as routine and released 4,019.44 BTC across 83 separate inputs to the attacker's address. No key theft, no social engineering, no compromised server, just a chain of software that could not tell a fraudulent claim from a genuine one.

The fix that existed before the money moved

An independent technical reconstruction by researchers at DeFiPrime, built from Blockstream's own public Elements code repository, found that a fix titled to bind a cache key to the correct asset and output script was authored by a Blockstream engineer on August 3, five weeks before the incident. That change landed in the project's main development branch on September 3, three days before the exploit. A pull request to bring the same fix into the stable 23.3.x release branch was opened September 4 and merged September 6 at 17:21 UTC, under three hours after the attacker's payout confirmed on the Bitcoin network.

The release that Liquid's federation members were actually running in production, version 23.3.3 from April 13, did not contain this change. DeFiPrime is careful to note that Blockstream has not publicly confirmed this specific fix is the one that would have prevented the exploit, and that only Blockstream can close that question. What is not in dispute is the gap itself: the deployed software predated a related patch by close to five months.

EventTime (UTC), Sept 6, 2026
Disputed Liquid block accepted13:53:10
Peg-out request submitted via SideSwap14:06:10
Bitcoin payout confirmed on-chain14:28:56
Cache-key fix merged into stable branch17:21:00
"Whitehat" on-chain message posted18:30:10
Blockstream public statement20:25:20

What this means for anyone trusting a federated bridge with real money

An on-chain promise to return funds is not a resolved incident. As of publication, the roughly 320 million dollars sat unmoved at a single address, contingent on Blockstream shipping a fix first, an arrangement with no enforcement mechanism beyond the attacker's own word. Liquid was marketed to exchanges and institutional partners as custody-grade infrastructure, secured by a federation of signers rather than any single company. That model is real protection against a single stolen key. It did nothing here, because the failure sat one layer below key custody, in the software that decides whether a withdrawal request is even valid.

The practical lesson for any owner relying on federated or bridged infrastructure, crypto or otherwise, is that key-management hygiene, hardware security modules, and multisignature thresholds answer only one threat model. The other one is release discipline: whether a fix written and merged into a codebase actually reaches the version running in production, and how long that gap is allowed to sit open. A signature the system verifies correctly is worthless if the thing being verified was never true to begin with.

Servola Journal

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.