Skip to content

Coins

Liquid Network Loses Nearly 4,000 BTC; Blockstream Seeks Contact with Hackers

Liquid Network Security Breach: Nearly 4,000 BTC Transferred Without Authorization Liquid Network, a Bitcoin sidechain developed by Blockstream to enable faster and more confidential transactions, confirmed a major security breach...

Liquid Network Security Breach: Nearly 4,000 BTC Transferred Without Authorization

Liquid Network, a Bitcoin sidechain developed by Blockstream to enable faster and more confidential transactions, confirmed a major security breach on Sunday, September 6. Approximately 3,996 BTC, valued at roughly $320 million at the time, were moved from the Liquid Federation’s Bitcoin wallet without standard authorization.

Unauthorized Peg-Out and On-Chain Message

The transfer was executed via a peg-out, the process that allows Bitcoin to move from the Liquid sidechain back to the main Bitcoin network. The Liquid Federation stated that this transaction was not authorized through its usual process.

The party responsible for the withdrawal left an on-chain message using the OP_RETURN function. The message read, “we are whitehats. contact us on chain.” It was included in Bitcoin transaction c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19. The Liquid Federation described those behind the event as “purported white-hat hackers” and reported that Blockstream was attempting to establish contact with them via a signed on-chain response.

Blockstream is trying to reach the individuals who removed the funds using a signed message, following a withdrawal conducted outside the regular authorization pathway.

Transaction Details and Analysis

Blockchain analyst ErgoBTC identified the significant payout as transaction 8db751…a7b140, which sent roughly 3,996 BTC to the address bc1qgs…c6wt7p. This was confirmed in Bitcoin block 965,783 at 14:28:56 UTC on September 6. On the Liquid sidechain, Blockstream’s explorer recorded the correlated transaction ce4cae…e988f2, reflecting a 3,996.01834922-LBTC peg-out.

The Liquid Federation indicated that the withdrawal used SideSwap’s Peg-out Authorization Key (PAK), yet claimed the key itself was not compromised. This distinction remains essential to understanding the breach.

Peg-Out Authorization Key in Focus

Liquid Network uses a two-way peg that allows users to lock BTC to create Liquid Bitcoin (LBTC) on the sidechain. Users can later destroy LBTC to redeem the locked BTC. Peg-out transactions are safeguarded by a Peg-out Authorization Key, designed to prevent compromised functionaries from moving user funds to malicious addresses.

According to project documentation, even if some block signers were compromised, the PAK system is meant to block unauthorized transfers. Liquid’s “Strong Federation” structure requires at least two-thirds of block signers to validate blocks and an even higher proportion of watchmen to approve BTC spending.

The Liquid Federation stated there were no signs that the key itself was breached. The focus now centers on how the transaction was approved with a valid, uncompromised authorization key.

White Hat Claims Under Scrutiny

The individuals responsible described themselves as “white hats,” but no evidence has been provided to support this claim beyond the message left on-chain. Previously, other incidents, such as the hack on TAC protocol, were only recognized as “white-hat operations” after the attacker returned most of the funds.

As long as the almost 4,000 BTC remain unrecovered, the “white hat” status asserted by the actors should be considered a claim rather than a conclusion.

There is currently no indication that the funds have reached exchanges or been sold, so any immediate market impact is uncertain. On-chain movement does not guarantee selling pressure unless the assets are deposited for trading.

Confidence in Federated Bridges at Stake

A report from TRM Labs covering crypto hacks in early 2026 found that issues with infrastructure and operations caused only about 15% of incidents, but accounted for an estimated 76% of total monetary losses. This shows that breaches affecting custody and bridges often inflict much greater damage than smaller exploits.

Research by Heritage Falodun and Samson Ojo in July 2026 highlighted that only 0.8% of circulating Bitcoin is used in decentralized finance, compared to about 30% for Ethereum. The study cited trust in infrastructure as a leading reason why capital remains on the Bitcoin base layer rather than being integrated into DeFi activities.

Blockstream, the firm leading Liquid’s development, published a roadmap in May addressing the need to minimize reliance on trusted third parties in bridge schemes. One ongoing initiative includes the development of the BitVM 1-of-n bridge, designed to enhance trustlessness and security. If federated bridge models continue to see incidents like this, such innovations may become increasingly critical.

It is still unclear how the hackers will respond to Blockstream and whether the stolen BTC will be returned, left dormant, or transferred to exchanges. The episode now stands as a major test not only of Liquid’s security but also of the broad confidence that Bitcoin users place in federated bridging solutions.

Evan Mercer

Penulis

Evan Mercer covers coins, digital assets and the market stories shaping everyday conversations about money. His work focuses on accessible explanations, useful context and the signals behind sudden moves.