- Liquid is a Bitcoin L2/sidechain, launched by Blockstream in 2018. 4,000 BTC from their bridge was taken by a whitehat yesterday (and then mostly returned).
- You can think of the Liquid network as running a fork of Bitcoin Core (called Elements). Elements added new features such as confidential transactions, other assets, BTC peg in/out, and new opcodes.
- The bug seems not to be a cryptography one but in integration logic. Bug A was there for years, was recently patched, and the patch likely introduced Bug B, which was exploited.
- I’m glad this was a whitehat, and most of the funds have been returned. Could’ve been much worse if an actual attacker.
Learnings:
- There should’ve been rate limits in place both at the swap service and peg out. There likely were some limits that didn’t trigger. Such rate limits and time delays can drastically reduce the potential damage.
- It’s clear that we’re in the age of AI-driven security wars. The new capability of these models is forcing us to discover bugs that went undetected for years. Overall, this will be a net positive, even if short-term painful.
- Both the earlier Zcash bug and this Liquid one reinforce how keeping Bitcoin simple and hardened is the right call. If anything, we should be pushing for Bitcoin ossification.
Stacks security:
- I got several questions about Stacks. We also have a bridge for sBTC. The exact Elements bug isn't applicable here, as Stacks doesn’t use Elements. For any bridges or DeFi apps, security should be priority #1. Stacks devs actively run frontier AI models (both open-source and from frontier labs) on our repos. We also have active bug bounty programs with Immunefi and others. Our regular security audit reports are also available publicly.
- Even with the emphasis on security, AI model testing, audits, etc, for over a year, Stacks devs have been pushing in the long-term direction of self-custodial solutions. The Bitcoin bonds/staking upgrade keeps the BTC deployed fully self-custodial (no bridge or smart contract risk). Further, new approaches to self-custodial lending and other areas are in the R&D stage right now.
Summary:
Running the absolute latest AI models on sensitive repos is job #1 for crypto devs. We’ll see a short-term increase in discovered bugs but get hardened systems and healthy practices in the long term.
Stacks is now heavily focusing on self-custodial solutions for bitcoin capital markets, while relentlessly doing defensive security testing/audits on existing infra.
The Liquid incident should be a wake-up call to take AI threats extremely seriously, even at Bitcoin Core (we’ve done some work on this). We should ossify Bitcoin Core and keep it as simple as possible; all new bitcoin functionality can be built on layers like Stacks. Forward!
75·AShort
n
news9/7news
Busy August
ethereum:0xf939e0a03fb07f59a73314e73794be0e57ac1b4e minting nearly doubled, the peg stayed within 6.1 bps, and LlamaLend V2 borrowing rose 45%. @ResupplyFi got more $sreUSD capacity, @twinfinance_ launched FX markets in collaboration with @DAMM_Capita, and yRisk was selected as DAO risk provider.
Busy August
ethereum:0xf939e0a03fb07f59a73314e73794be0e57ac1b4e minting nearly doubled, the peg stayed within 6.1 bps, and LlamaLend V2 borrowing rose 45%.
@ResupplyFi got more $sreUSD capacity, @twinfinance_ launched FX markets in collaboration with @DAMM_Capita, and yRisk was
65·B+Long
n
news9/7news
⚠️ Exploit breakdown:
Sept 6: @Liquid_BTC got hit through an Elements consensus / asset-validation bug. Attacker minted ~4,000 unbacked L-BTC, then used SideSwap’s normal peg-out flow to cash out 3,996.01834922 BTC from the Liquid Federation reserve.
They called it whitehat and said funds come back after every node is patched. Still sitting. No return.
📌 IOCs
Attacker:
https://mempool.space/address/bc1qgslsydz56d0ed6827hdemfmk5w2f6ldyc6wt7p
Collection wallet:
https://mempool.space/address/bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte
Hit reserve:
https://mempool.space/address/bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr
🔍 How it played out
1. Phantom L-BTC
Liquid block 4,050,336 (2026-09-06 21:53:10 CST) was accepted by Federation / Blockstream nodes. http://mempool.space’s independent Liquid node rejected it and stalled on the prior block. Clean consensus split.
Suspect mint:
https://blockstream.info/liquid/tx/c652a1047ff549698b09242a66e20f6e9a044d5c972419342fa552b0856ba674
2. Peg-out via SideSwap
3,996.01834922 BTC paid to bc1qgsls...c6wt7p
https://blockstream.info/liquid/tx/ce4caece413cd9d444ce7ed9f54e5b328b3da5e4af301aff59a3571f76e988f2
Blockstream later said the L-BTC came from an Elements bug. SideSwap PAK + infra were not compromised.
https://x.com/side_swap/status/2096709838310928674
3. Federation pays on Bitcoin L1
https://mempool.space/tx/8db751a650ae2f12006b7e8c69a75e4df360e8afd6b9e05ae0b9fa6458a7b140
4. Funds swept
https://mempool.space/tx/85d2ca15bea33a592e73ed40c6a5da887feecf1e77f58ec7f580e00841645043
5. On-chain note
OP_RETURN: “we are whitehats. contact us on chain.”
Also told Liquid to patch first, then they’d return funds — and even sent the project fix details. Comedy/taunt meter is maxed. Whitehat claim is shaky. Reads more like buying time.
https://mempool.space/tx/83825b2135dd0abac12c9dfe17f29ab81b3427e1ae864947b0bebce5e47c3c4b
🧠 Impact
▪️ Hit: Liquid Network / Federation BTC reserve
▪️ Loss: 3,996.01834922 BTC (~$320M at the time)
▪️ Reserve left: ~197.4719 BTC. ~95% of the stack walked
▪️ Bitcoin L1: not exploited. Mainnet just executed a Federation-signed payout
▪️ SideSwap: used as the peg-out rail. Official word is PAK + systems were not breached
▪️ Other Liquid assets: USDT, DePix, RWAs were not weirdly minted, but the pause still froze transfers + liquidity
▪️ Recovery: principal still sits on the collection address. No CEX, no mixer, no bridge. Better recovery odds than a washed drain — until it’s actually returned, treat it as unrealized loss
▪️ Attacker label: self-claimed whitehat, unknown actor. Parking nine figures and then asking to talk is not standard responsible disclosure.
70·B+Short
m
meme9/6meme
reply Liquid Network confirmed a security incident, saying the funds were withdrawn via SideSwap’s Peg-out Authorization Key (PAK), while the key itself and other keys were not compromised. Exchanges have been notified and have paused or will pause LBTC deposits and withdrawals. Other Liquid assets, including USDT, DePix and RWAs, are unaffected. Liquid has temporarily disabled bridge nodes, effectively pausing the sidechain while federation members work to resolve the issue and restore normal network activity.
0·-Neutral
n
news9/6news
Liquid Network confirmed a security incident, saying the funds were withdrawn via SideSwap’s Peg-out Authorization Key (PAK), while the key itself and other keys were not compromised. Exchanges have been notified and have paused or will pause LBTC deposits and withdrawals. Other Liquid assets, including USDT, DePix and RWAs, are unaffected. Liquid has temporarily disabled bridge nodes, effectively pausing the sidechain while federation members work to resolve the issue and restore normal network activity.
75·AShort
m
meme9/6meme
We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.
What we know so far is that the funds were withdrawn via the SideSwap PAK (Peg-out Authorization Key), but that key was not compromised, nor were any others.
Exchanges have been notified and have already paused (or will pause) LBTC deposits and withdrawals. Other Liquid assets such as USDT, DePix, and RWAs are unaffected by this security incident.
Bridge nodes have been temporarily disabled, so no new transactions can be submitted to the network. Effectively, the Liquid sidechain is paused until this issue is resolved.
Liquid wallets will be impacted, and we're sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity.
You can monitor the situation via @mempool's https://t.co/M46Zhn8nlY site below:
https://t.co/B8j9u4j6i4