Data Analytic Investments
RIPPLE book coverRIPPLE — the book·numbered first edition·$9.99Buy now
Crypto

Liquid Network, 6–7 September 2026: 4,000 BTC left the federation wallet — what is on record

About 4,000 of the 4,200 bitcoin held by the Liquid Federation moved out on 6 September through an approved peg-out. Blockstream says no key was compromised and that a bug in the Elements software created the L-BTC involved. Self-described "white hats" are talking to Blockstream through on-chain messages and say they will return most of it once every node is patched. As of the morning of 8 September, no return is confirmed by Liquid itself.

D
DAI Research Desk
5 min read
Liquid Network, 6–7 September 2026: 4,000 BTC left the federation wallet — what is on record

On Saturday, 6 September 2026, roughly 4,000 bitcoin — about 95% of the reserve behind the Liquid sidechain — left the Liquid Federation's wallet in a single, valid-looking withdrawal. This entry records what the operator has said, what the people holding the coins have said, and what is still unconfirmed on the morning of 8 September. It is a documentary record, not an assessment of any asset.

Adam Back, co-founder and CEO of Blockstream, the company behind Liquid, in 2014 (photo: Joi Ito, CC BY 2.0, Wikimedia Commons)

Adam Back, co-founder and CEO of Blockstream, the company that built and maintains Liquid — photo: Joi Ito, 2014, CC BY 2.0, Wikimedia Commons.

What Liquid is

Liquid is a Bitcoin sidechain launched by Blockstream in 2018. Users lock bitcoin and receive L-BTC, a token that moves on the sidechain faster and with confidential amounts; a federation of exchanges, infrastructure firms and asset managers — Liquid says more than 80 members — holds the underlying bitcoin and signs the withdrawals ("peg-outs") back to the Bitcoin base layer. Peg-outs go through approved services holding a Peg-out Authorization Key (PAK).

What the operator has said (primary source)

On 6 September the Liquid Network account wrote on X that it was "aware of a security incident," that "purported white-hat hackers have withdrawn 4,000 BTC ($320 million) from the Liquid Federation wallet," and that Blockstream was contacting them on-chain with a signed message. The same statement said the withdrawal went through SideSwap's PAK, that "that key was not compromised, nor were any others," and that Blockstream had established the L-BTC in the order "was created through a bug in the Elements software." Bridge nodes were temporarily disabled, exchanges were asked to pause L-BTC deposits and withdrawals, and other Liquid assets (USDT, DePix, real-world assets) were described as unaffected.

SideSwap, the peg-out service used, posted its own statement: a customer sent 4,000 L-BTC to its peg-out service at 14:05 UTC, the order was processed "like any other," the L-BTC was burned with a valid authorisation, and at 14:28 UTC the federation paid out 3,996 BTC.

What the holders of the coins have said

According to a reconstruction published by Galaxy Research's Alex Thorn and reported by crypto.news and CoinDesk, the parties exchanged messages in Bitcoin OP_RETURN outputs. The first transaction from the withdrawing side carried "we are whitehats. contact us on chain." Blockstream answered at block 965,822 with a 1,000-satoshi transaction directing them to its security team, plus PGP-signed material. At block 965,869 the holders asked whether returning "most" of the bitcoin would be acceptable, and a later message said: "Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix."

What is not confirmed

As of the morning of 8 September, the Liquid Network account has not posted a confirmation that any bitcoin has been returned, has not published a patch version, a reopening time, or a technical post-mortem. Several secondary outlets report that a large part of the coins has since moved back to the federation and that a smaller amount was retained; we could not verify that against a statement by Liquid or Blockstream and do not record it as fact here. "Most" has not been defined by the holders. The "white hat" description is theirs; Liquid itself uses the word "purported."

Why it matters, plainly

Liquid exists to let exchanges settle bitcoin faster than the base layer allows. Its security model rests on the federation's custody of the reserve and on the rule that L-BTC can only exist against locked bitcoin. The operator's own account of this incident — a valid peg-out of L-BTC that a software bug had created — points to the second rule, not to stolen keys. That distinction is the one fact that separates this event from most of the year's exchange and bridge losses, and it is the one to watch when the post-mortem is published.

Why this is on our site

Data Analytic System documents primary-source events in the crypto infrastructure it reports on. A sidechain pause, an operator statement and an on-chain negotiation are dated, checkable records — the kind we anchor to. We will add the outcome from Liquid's or Blockstream's own release when it exists.

What this entry does not claim

It does not say whether the coins will be returned, how much, or when. It does not say what the bug is; Blockstream has not published it. It does not say what any asset will do. It does not evaluate the motives of the people holding the coins.

Sources:

Educational content. Not investment advice.

Explore Topics

#Liquid Network#Blockstream#Bitcoin#sidechain#security incident#Elements#documentary record
D

Written by

DAI Research Desk

Content creator and writer sharing insights and stories.

Share · Megosztás:XFacebookLinkedInWhatsAppTelegramE-mail

Related Research

Moscow Exchange lists perpetual futures on five crypto indices from 22 September: what the exchange notice says, and what it does not
Research

Moscow Exchange lists perpetual futures on five crypto indices from 22 September: what the exchange notice says, and what it does not

On 16 September 2026 Moscow Exchange announced five perpetual futures with daily auto-rollover on its own Bitcoin, Ether, Solana, XRP and Tron indices, launching 22 September, cash-settled in roubles, for qualified investors only. This article documents the notice line by line: the contracts, the settlement design, the funding parameters, the exchange's own usage figures since 2025, and the questions the notice leaves open.

5 min readDAI Research Desk
#Moscow Exchange#MOEX#perpetual futures
Symbiosis Bitcoin bridge exploit: 46 billion fake syBTC minted, 336 thousand dollars taken, 15 BTC recovered — what the record shows
Research

Symbiosis Bitcoin bridge exploit: 46 billion fake syBTC minted, 336 thousand dollars taken, 15 BTC recovered — what the record shows

On 11 September 2026 a flaw in Symbiosis's BridgeV2 contract on BNB Chain let an attacker mint roughly 46 billion unbacked syBTC. The realised damage was about 336 thousand dollars; the protocol says it recovered about 15 BTC and offered a 20 percent bounty. This is a dated record of what happened, what was recovered, and what is still paused.

5 min readDAI Research Desk
#Symbiosis#bridge exploit#Bitcoin
Revolut handed customer passports and Bitcoin transaction histories to a fake government request: what is confirmed, what is not
Research

Revolut handed customer passports and Bitcoin transaction histories to a fake government request: what is confirmed, what is not

On 12 September 2026 Revolut confirmed that an unauthorised third party used a legitimate government agency email domain to submit fraudulent data requests, and that the company answered them. Identity documents, selfies, addresses, account statements and Bitcoin transaction histories of a 'limited' number of customers were handed over. This is a documentary record of what Revolut said, what the researcher who first reported it said, and what remains unknown.

5 min readDAI Research Desk
#Revolut#data breach#Bitcoin