Liquid Network Recovers 85% of Misappropriated Bitcoin Following Peg-Out Exploit
The Liquid Network federation has recovered a substantial portion of the Bitcoin ($BTC) withdrawn from its federation wallet over the weekend, yet the incident exposes a deeper structural vulnerability in the sidechain’s peg-out mechanism. On Monday, September 7, the entity responsible for the unauthorized withdrawal returned 3,400 $BTC to the federation, restoring approximately 85% of the misappropriated funds. The transaction left the actors with 598.5 $BTC still outstanding. For consistency, all dollar conversions in this article use CoinMarketCap’s Bitcoin-to-USD rate of $79,001.61, recorded on September 7.
A Valid Peg-Out the Federation Never Authorized
At first glance, the transaction appeared routine. SideSwap reported that at 14:05 UTC on Sunday, a customer transmitted 4,000 L-$BTC to its peg-out service. After presenting a valid SideSwap peg-out authorization, roughly 3,996 $BTC was released from the federation’s wallet at 14:28:56 UTC.
Critically, the authorization key was not compromised. Liquid confirmed that SideSwap’s authorization key was not used improperly. SideSwap further disclosed that Blockstream identified the root cause as a failure in Elements software, which enabled the generation of invalid L-$BTC. Consequently, the peg-out mechanism processed tokens that appeared legitimate but lacked the required Bitcoin backing.
This distinction moves the incident beyond typical key-compromise scenarios into the realm of accounting integrity. According to Liquid’s whitepaper, L-$BTC is defined as Bitcoin that enters the sidechain via a two-way peg, where federation-held $BTC collateralizes the issued tokens. If L-$BTC can enter the redemption path without valid backing, the integrity of the reserves becomes as critical as the security of the authorization keys themselves.
Negotiation Conducted Via Bitcoin Transaction Messages
Communication between Blockstream and the actors unfolded through messages embedded in Bitcoin transactions. A timeline from Samson Mow indicated the actors pressed Blockstream to remediate the vulnerability before returning the funds.
Blockstream subsequently transmitted a signed note stating, “Bridge nodes are patched, safe to return the funds.” The actors confirmed the final destination with Blockstream and returned 3,400 $BTC to the Liquid Federation at 16:09:25 UTC on September 7.
Outstanding 598.5 BTC Keeps Reserve Questions Open
While the recovery of 85% of the funds represents a significant win, it does not resolve the fundamental issue for a system predicated on one-to-one backing. Approximately 598.5 $BTC—valued at roughly $47.3 million at the referenced market price—remains outside federation control.
As previously reported by Cryptopolitan, a peculiar aspect of the exploit was its use of the SideSwap peg-out authorization mechanism despite no key-level breach. The Bitcoin base layer functioned correctly; the failure occurred upstream, where falsely minted L-$BTC passed through a redemption mechanism designed to release genuine $BTC.
The critical takeaway for users of bridged Bitcoin is that this incident transcends private-key theft. It demonstrates how a software defect can produce a redemption request that appears legitimate while lacking actual reserve collateralization. Even if the remaining bitcoin are eventually returned, the underlying concern persists: Liquid’s peg-out process converted real $BTC into L-$BTC that should never have been considered validly collateralized.

