Liquid Network Loses Nearly 4,000 BTC in Breach; Blockstream Seeks On-Chain Contact With Hackers
Key Takeaways
- •Nearly 4,000 BTC, valued at approximately $320 million, was moved out of the Liquid Federation's Bitcoin wallet on September 6 through an unauthorized peg-out transaction.
- •The actors responsible embedded an on-chain OP_RETURN message describing themselves as white-hat hackers and requesting contact, and Blockstream is responding with a signed on-chain message.
- •The Liquid Federation stated the withdrawal used SideSwap's Peg-out Authorization Key but that the key itself was not compromised, leaving unresolved how the transaction passed authorization.
- •No evidence beyond the on-chain message supports the white-hat claim, and there are no indications the funds have reached exchanges or been sold.
- •The breach is among the largest involving Bitcoin-linked infrastructure and intensifies scrutiny of federated bridge security, an area Blockstream aims to improve with initiatives like the BitVM 1-of-n bridge.

Liquid Network Loses Nearly 4,000 BTC in Breach; Blockstream Seeks On-Chain Contact With Hackers
Liquid Network, a Bitcoin sidechain developed by Blockstream to enable faster Bitcoin transactions, confirmed a major security breach on Sunday, September 6. Nearly 4,000 BTC, worth approximately $320 million, were transferred out of the Bitcoin wallet of the Liquid Federation without standard authorization. The scale of the loss places the incident among the largest exploits to date involving Bitcoin-linked infrastructure, a category that has historically seen fewer but far costlier breaches than smart-contract protocols.
Unauthorized peg-out and hacker communication
The transfer was carried out through a process known as a peg-out, which moves Bitcoin from the Liquid sidechain back to the main Bitcoin network. The Liquid Federation stated that the transaction was not authorized through its usual process.
The party responsible for the withdrawal left an on-chain message using the OP_RETURN function, which read, “we are whitehats. contact us on chain.” The message was embedded in Bitcoin transaction c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19. The Liquid Federation described those behind the event as “purported white-hat hackers” and reported that Blockstream was attempting to establish contact with them via a signed on-chain response. Blockstream is trying to reach the individuals who removed the funds using a signed message, following a withdrawal conducted outside the regular authorization pathway.
Blockchain analyst ErgoBTC identified the major payout as transaction 8db751…a7b140, which sent roughly 3,996 BTC to the address bc1qgs…c6wt7p. The transaction was confirmed in Bitcoin block 965,783 at 14:28:56 UTC on September 6. On the Liquid sidechain, Blockstream’s explorer recorded the correlated transaction ce4cae…e988f2, reflecting a 3,996.01834922-LBTC peg-out.
The Liquid Federation indicated that the withdrawal used SideSwap’s Peg-out Authorization Key (PAK), yet claimed the key itself was not compromised. This distinction remains essential to understanding the breach, because the PAK list is the mechanism designed to stop exactly this kind of out-of-process withdrawal.
Mini dictionary: Liquid Network — a Bitcoin sidechain developed by Blockstream, designed to offer faster and more confidential transactions for traders, exchanges, and financial institutions.
Peg-out Authorization Key in focus
The Liquid Network uses a two-way peg that allows users to lock BTC in order to create Liquid Bitcoin (LBTC) on the sidechain. Users can later destroy LBTC in exchange for redeeming the locked BTC. Peg-out transactions are safeguarded by a Peg-out Authorization Key, which is intended to prevent compromised functionaries from moving user funds to malicious addresses.
According to project documentation, even if some of the block signers were compromised, the PAK system is meant to block unauthorized transfers. Liquid’s “Strong Federation” structure requires at least two-thirds of block signers to validate blocks and an even higher proportion of watchmen to approve BTC spending.
The Liquid Federation stated there were no signs that the key itself was breached. The focus now centers on how the transaction was approved with a valid, uncompromised authorization key — a question that goes to the heart of how much trust users must place in federation members and their operational security, since funds on Liquid depend on this collective custody model rather than on individual Bitcoin keys.
White-hat claims under scrutiny
The individuals responsible described themselves as “white hats,” but no evidence has been provided to support this claim beyond the on-chain message. In previous incidents, such as the hack of the TAC protocol, the events were only recognized as white-hat operations after the attackers returned most of the funds.
As long as the almost 4,000 BTC remain unrecovered, the “white hat” status asserted by the actors should be considered a claim rather than a conclusion. There is currently no indication that the funds have reached exchanges or been sold, so any immediate market impact is uncertain. On-chain movement does not guarantee selling pressure unless the assets are deposited for trading.
Confidence in federated bridges at stake
A report from TRM Labs covering crypto hacks in early 2026 found that issues with infrastructure and operations caused only about 15% of incidents, but accounted for an estimated 76% of total monetary losses. This indicates that breaches affecting custody and bridges often inflict far greater damage than smaller exploits.
Research by Heritage Falodun and Samson Ojo in July 2026 highlighted that only 0.8% of circulating Bitcoin is used in decentralized finance, compared with about 30% for Ethereum. The study cited trust in infrastructure as a leading reason why capital remains on the Bitcoin base layer rather than being integrated into DeFi activities.
Blockstream, the firm leading Liquid’s development, published a roadmap in May addressing the need to minimize reliance on trusted third parties in bridge schemes. One ongoing initiative is the development of the BitVM 1-of-n bridge, designed to enhance trustlessness and security. If federated bridge models continue to experience incidents like this, such innovations may become increasingly critical.
It remains unclear how the hackers will respond to Blockstream and whether the stolen BTC will be returned, left dormant, or transferred to exchanges. Key questions to watch include whether the federation discloses how a valid PAK-authorized withdrawal was executed outside the normal process, and whether additional safeguards are added before users regain confidence in pegging funds in and out of the network. The episode now stands as a major test not only of Liquid’s security, but also of the broader confidence that Bitcoin users place in federated bridging solutions.