Blockstream announced on September 7 that its Liquid Network bridge nodes have been patched and secured, clearing the way for the return of approximately 4,000 BTC, worth around $320 million, that were fraudulently drained from the Liquid Federation wallet a day earlier.
The exploit, which stemmed from a bug in the Elements software underpinning the Liquid sidechain, allowed an attacker to trigger a valid peg-out using invalid L-BTC. The federation’s automated systems couldn’t tell the difference.
What happened on September 6
The attacker exploited a vulnerability in the Elements code to abuse SideSwap’s Peg-out Authorization Key, or PAK. That key is part of the mechanism that converts L-BTC (the Liquid sidechain’s wrapped Bitcoin) back into native BTC on the main Bitcoin blockchain.
The result was catastrophic for the federation’s reserves. Before the exploit, the Liquid Federation wallet held more than 4,200 BTC. After it, that figure cratered to roughly 197 BTC.
That math means L-BTC was suddenly, dramatically under-collateralized. For every L-BTC token circulating on the Liquid Network, there was supposed to be one real BTC backing it. After the exploit, less than 5% of that backing remained in the wallet.
Blockstream moved quickly. Bridge nodes were disabled, network activity was paused, and exchanges were instructed to suspend all L-BTC deposits and withdrawals to prevent further damage.
One important clarification from Blockstream: no PAKs or federation keys were actually compromised. The exploit was entirely a software bug, not a breach of the cryptographic keys that govern the network’s multi-signature security model.
A very unusual negotiation channel
Perhaps the most striking detail of this incident is how the two sides communicated. Blockstream and the exploiter exchanged messages via PGP-signed OP_RETURN transactions on the Bitcoin blockchain itself.
For the non-technical: OP_RETURN is a Bitcoin transaction field that lets you embed a small amount of arbitrary data. In this case, it became a secure, public, and cryptographically verified messaging system between a major blockchain company and the person who just drained its reserves.
The attacker, through these on-chain messages, indicated an intention to return the majority of the stolen funds once the systems were confirmed patched.
On September 7, Blockstream confirmed via the same channel that the patches were in place and encouraged the prompt return of funds.
As of that date, roughly 3,998.5 BTC had not moved from the recipient address. The slight difference from the original 4,000 BTC likely reflects transaction fees incurred during the exploit itself.
Collateral damage and what was spared
While the exploit devastated the BTC reserves backing L-BTC, other assets on the Liquid Network appear to have escaped unscathed. USDT and DePix, a Brazilian real-denominated stablecoin, both operate on Liquid but were reported to be unaffected by the incident.
The vulnerability was specific to the peg-out mechanism for L-BTC, not a broad breach of the sidechain’s transaction processing.
What comes next
The immediate priority is the return of the roughly 3,998.5 BTC. If the exploiter follows through on the stated intention, Blockstream can restore L-BTC’s collateral ratio and resume normal Liquid Network operations.
Exchanges that suspended L-BTC trading will likely keep those suspensions in place until the situation is fully resolved.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
15








English (US) ·