On September 7, 2026, Bitcoin Layer-2 protocol Liquid Network suffered a major security breach, draining 4,000 BTC ($320M). A validation bug involving SideSwap's Peg-out Authorization Key allowed white-hat actors to extract ~95% of the federation wallet before 3,400 BTC was safely returned.
In early September 2026, the Bitcoin ecosystem was rocked when 4,000 BTC (valued at roughly $320 million) was unexpectedly drained from the primary Liquid Federation storage wallet.
The incident represents one of the largest sidechain breaches in Bitcoin history. However, fast action by network operators and a white-hat resolution helped avert complete structural collapse.
Anatomy of the Incident
The Attack Vector: The drain was executed via SideSwap’s Peg-out Authorization Key (PAK). While initial concerns pointed to compromised private keys, investigations confirmed that neither the PAK nor individual federation keys were stolen. Instead, a logic/validation flaw allowed the attackers to manipulate peg-out parameters, tricking the 11-of-15 multisig federation nodes into signing off on unauthorized withdrawals.
Network Shutdown: As the anomaly was detected, Liquid Federation members immediately disabled bridge nodes, effectively pausing block production and cross-chain pegging activity to prevent further depletion of funds.
Scope of Exposure: While ~95% of Liquid Bitcoin (L-BTC) reserves were extracted from the main vault, non-BTC assets on Liquid (such as USDt, DePix, and RWAs) remained completely unaffected.
Negotiation & White-Hat Fund Recovery
Immediately after the exploit, Blockstream and federation engineers issued signed on-chain messages to contact the extractors.
3,400 BTC Returned: The parties behind the withdrawal declared themselves white-hat hackers and returned 3,400 BTC (approx. $270 million) to federation-controlled custody after Blockstream deployed a hotfix.
Outstanding Treasury Balance: Negotiations remain ongoing regarding the remaining ~600 BTC as the team prepares to safely unpause and restart the network.
How to Protect Your Assets During Sidechain Incidents
When Layer-2 bridges or sidechains encounter severe consensus/bridge bugs:
Pause L-BTC Transfers: Avoid interacting with unpegged L-BTC or executing DEX swaps until the federation officially restores standard operations.
Monitor Peg-In / Peg-Out Status: Track official Blockstream and Liquid announcements for patch verification before depositing mainnet BTC.
Isolate On-Chain Risks: Ensure your long-term Bitcoin holdings reside in cold storage on the main Bitcoin settlement layer rather than high-velocity L2 bridges.