At 14:06:10 UTC on Sunday, September 6, 2026, Liquid block 4,050,349 carried a peg-out transaction that asked the Liquid Federation to release 3,996.01834922 BTC to a fresh Bitcoin address. The request came through SideSwap, a peg-out partner whose Peg-out Authorization Key is on the federation’s whitelist. At 14:28:56 UTC, in Bitcoin block 965,783, eleven or more of the fifteen functionary hardware modules signed an 83-input transaction that paid it. The federation’s Bitcoin wallet, which held about 4,200 BTC that morning, holds 197 at the time of writing.
No key was compromised. Liquid’s own statement says the SideSwap key “was not compromised, nor were any others.” SideSwap’s statement says the peg-out “went through SideSwap’s peg-out service on a customer order” and that “the L-BTC came from an Elements bug, not from any SideSwap system.” Every signature on the withdrawal was legitimate. The coins being redeemed were not.
At 18:30:10 UTC, in Bitcoin block 965,818, the recipient wrote “we are whitehats. contact us on chain” into an OP_RETURN and sent 1,000 satoshis to the federation’s own address to make sure it was read. The 3,998.5 BTC they hold, worth about $320 million at Sunday’s price near $80,000, has not moved since.
This piece reflects what the two chains showed at about 21:30 UTC on September 6, roughly seven hours after the peg-out. Everything below is read from Bitcoin and Liquid transactions, block headers and the two public Liquid explorers, and the identifiers are cited so you can check them. What is not settled is the bug itself. Blockstream has not said what in Elements allowed it, whether the funds will come back, or who makes L-BTC holders whole if they do not.
What Liquid Is
Liquid is Blockstream’s Bitcoin sidechain, live since 2018. You send BTC to a federation address, wait 102 confirmations, and receive Liquid Bitcoin (L-BTC) on a chain that produces a block every minute, supports issued assets like Tether’s USDT, and hides amounts and asset types by default through Confidential Transactions. To get out, you burn L-BTC in a peg-out transaction and the federation pays BTC to your address.
The chain is not proof-of-work. It runs what Blockstream calls a Strong Federation: fifteen functionaries, operated by known companies, take turns proposing blocks, and a block is final once eleven of them have validated and signed it. The same fifteen, in their second role as watchmen, hold the keys to the Bitcoin. Per Blockstream’s help center, “the Liquid Federation uses an 11-of-15 multisig wallet to process peg-ins and peg-outs and secure bitcoin held in the federation wallet,” and “the 15 Liquid functionaries each hold one key, which is stored in their specialized HSM hardware.” Around them sits a wider Liquid Federation of more than 80 members who can peg in and, with a whitelisted key, peg out, but who play no role in securing the chain.
That whitelist is the Peg-out Authorization Key system, and it exists for one reason. If an attacker ever compromised eleven functionaries, PAK is meant to stop them redirecting the Bitcoin to themselves: the watchmen’s hardware will only sign a peg-out whose destination is derived from a registered PAK entry, and changing the list takes three days. Ordinary users have no PAK entry. They peg out by sending L-BTC to a partner that does, and Liquid’s documentation names SideSwap as one of two examples. SideSwap takes the customer’s L-BTC, builds the peg-out from its own wallet with its own PAK proof, and points the Bitcoin at the customer’s address.
That design describes what did and did not fail on Sunday. PAK protects against stolen keys. The multisig protects against stolen keys. The HSM, per Blockstream, “will only sign if the transaction outputs are going back to the federation or to a whitelisted address,” and the functionaries “verify that the peg-out transaction has been sent to a whitelisted address (PAK list) and the corresponding amount of LBTC has been burned.” Every one of those checks asks whether the withdrawal is properly authorized. None of them asks whether the L-BTC being burned should exist. That question is answered upstream, by the Liquid chain’s own consensus rules, and on Sunday the consensus rules gave the wrong answer.
The Block One Explorer Would Not Accept
The first visible anomaly is not on Bitcoin. It is a disagreement between the two public Liquid explorers about what the Liquid chain is.
Blockstream’s explorer shows Liquid block 4,050,336, signed at 13:53:10 UTC, with seven transactions in it. mempool.space’s Liquid explorer does not have that block. Its chain tip is 4,050,335, timestamped one minute earlier, and it lists all seven of block 4,050,336’s transactions as unconfirmed. At the time of writing Blockstream’s chain is 440 blocks further on. Antoine Poinsot, a Bitcoin Core contributor who posts as @darosior, put it plainly: “Liquid block 4’050’336 was rejected by @mempool but accepted by @Blockstream. This is the block that contains the peg-out transaction.” He first read it as a consensus-split double spend, then corrected himself: “Not quite a double spend, but definitely a consensus bug.”
The transaction with the most inputs in that block is c652a104…ba674. It spends 64 inputs, 55 of them from a single Liquid address with nearly a thousand prior incoming outputs, and produces five confidential outputs plus a 479-satoshi fee. Because the outputs are confidential, neither explorer can say what they are worth. Of the five, two were spent in the very same block, by transactions 2817e839…8d07 and efa5e6e6…2e3d, and descendants of both were in outputs SideSwap later spent by 13:58 and 14:01 UTC. SideSwap puts its customer’s 4,000 L-BTC order at 14:05, and the chain cannot say whether those are the same event.
I cannot tell you from the chain which transaction in block 4,050,336 is the invalid one, or what it minted. Confidential Transactions hide exactly the numbers that would settle it, and mempool.space’s explorer, having refused the block, still lists all seven of its transactions as unconfirmed, which is not what a node that had rejected a specific transaction would show. What the chain does show is a block that one full node accepted and another did not, a large confidential transaction at the center of it, and a direct spending path from that transaction to the peg-out. What Liquid and SideSwap say is that the L-BTC came from an Elements bug. What the recipient says is that they are whitehats. Those three statements are consistent with each other, and with a chain that produced L-BTC it should not have.
The Peg-Out

The peg-out itself is ce4caece…88f2, in Liquid block 4,050,349 at 14:06:10 UTC, thirteen minutes after the disputed block. SideSwap’s fuller statement, posted at 21:19 UTC, says that “at 14:05 UTC a customer sent 4,000 L-BTC to the SideSwap peg-out service” and that “our service had no way to tell those coins from any other L-BTC.” The transaction’s structure fits a service wallet. It spends six confidential inputs, and their parents are a mix of SideSwap’s ordinary business: one output from eleven hours earlier, one from block 4,050,333 before the disputed block, the change from a 2.65 BTC peg-out SideSwap ran for someone in block 4,050,344, and inputs that descend from the 64-input transaction through the two same-block children. Its peg-out output carries an explicit amount: 399,601,834,922 satoshis of L-BTC, or 3,996.01834922 BTC, to be paid to bc1qgslsydz56d0ed6827hdemfmk5w2f6ldyc6wt7p on Bitcoin. The fee was 177 satoshis.
The watchmen processed it in the normal way. Bitcoin transaction 8db751a6…b140, in block 965,783 at 14:28:56 UTC, spends 83 outputs from the federation’s address, bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr, totalling 4,019.44426085 BTC. It pays 3,996.01834922 BTC to the address above, 2.65138358 BTC to the recipient of SideSwap’s block 4,050,344 peg-out, 3.99601658 BTC to a third address, and returns 16.7781705 BTC to the federation in ten change outputs. The fee was 34,097 satoshis. When mempool.space’s audit later flagged “an unauthorized -4019 BTC withdrawal,” that 4,019 was this transaction’s total input, not the amount that left. The amount that left the federation to outside addresses was 4,002.67 BTC, of which 3,996.02 went to one place.
One detail in that batch is worth recording. The two amounts stand almost exactly a thousandfold apart: 3.99601658 and 3,996.01834922 BTC differ from a 1,000 to 1 ratio by a few thousand satoshis. SideSwap has confirmed the large one was a 4,000 L-BTC order, so the small one is what a 4 L-BTC order through the same service at the same fee rate would pay out, and a rehearsal is one reason someone would place it. An unrelated customer pegging out 4 L-BTC that afternoon would look the same, and the chain cannot distinguish the two.
The recipient did not wait. In the same Bitcoin block, 85d2ca15…5043 forwarded 3,995.99999857 BTC from the payout address to bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte, a single-signature address that has been the consolidation point ever since. At 14:01:57 UTC, in block 965,780, half an hour before the large payout confirmed, the same address had received 2.49749857 BTC from three unrelated inputs. One of them traces back to a 0.55487682 BTC federation peg-out at 13:16:32 UTC, in block 965,770, before the disputed Liquid block existed. Someone had moved money through the peg-out path and into this address before the large withdrawal was attempted. Whether that was a test of SideSwap’s flow or ordinary funding of the same wallet, the chain shows only the sequence.
The Bridge Kept Running
Nothing tripped. The federation processed another peg-out batch at 16:01:28 UTC, paying 4.14 BTC, and another at 16:48:45 UTC, paying 1.02 BTC. For more than two hours after 95% of the reserve had gone, the watchmen kept signing withdrawals against what was left.
The first public flag came from an independent researcher. @ErgoBTC posted the peg-out transaction ID at 18:23:18 UTC with the caption “Liquid got got?”, crediting a tip. @Rob1Ham posted the OP_RETURN transaction at 18:45:41 UTC and that post, at nearly a thousand likes by 21:00 UTC, is the one most people saw.
The OP_RETURN itself had landed at 18:30:10 UTC in block 965,818. Transaction c103de95…9a19 spends the consolidation address’s two outputs, writes “we are whitehats. contact us on chain” in an OP_RETURN, sends 1,000 satoshis to the federation’s address so the message shows up in the federation’s own wallet history, and returns 3,998.49748445 BTC to the same address. That is the entire visible record of the party’s intent: thirty-seven bytes of text and a thousand satoshis.
Replies arrived on-chain. At 19:31:47 UTC, in block 965,822, an unrelated address sent 1,000 satoshis to the consolidation address with an OP_RETURN reading “Please contact security@blockstream.com”. At 20:38:14 UTC, in block 965,829, another address sent 69,093 satoshis with “Please contact us on Signal @m671aw.70”. Liquid’s statement says “the Blockstream team is working on contacting them on-chain with a signed message.” I have not seen a signature on either message and cannot attribute them from the chain. Between the two, at 19:58:35 UTC, mempool.space posted its audit alert, and at 20:25:20 UTC Liquid published its statement, five hours and fifty-six minutes after the withdrawal confirmed on Bitcoin.
Liquid says bridge nodes have been disabled and “effectively, the Liquid sidechain is paused until this issue is resolved.” Blocks are still being signed every minute on Blockstream’s chain, each carrying a handful of transactions, so paused is doing some work in that sentence. Exchanges were told to halt L-BTC deposits and withdrawals, SideSwap has suspended peg-ins and peg-outs, and Liquid says USDT and other issued assets on the chain are unaffected. That last claim is about the assets themselves; anyone who needs to move them is as stuck as an L-BTC holder until the chain reopens.
The Numbers
| Item | Value | Source |
|---|---|---|
| Disputed Liquid block | 4,050,336 at 13:53:10 UTC, 7 transactions | Blockstream explorer |
| mempool.space Liquid chain tip | 4,050,335 | liquid.network API |
| Peg-out transaction (Liquid) | 3,996.01834922 L-BTC, block 4,050,349, 14:06:10 UTC | Blockstream explorer |
| Federation payout (Bitcoin) | block 965,783, 14:28:56 UTC, 83 inputs, 4,019.44 BTC spent | mempool.space |
| Paid to outside addresses | 4,002.67 BTC across three outputs | mempool.space |
| Returned to federation as change | 16.78 BTC | mempool.space |
| Federation reserve now | 197.47 BTC | mempool.space |
| L-BTC in circulation at block 4,050,335 | 4,205.02 | liquid.network API |
| Held at the recipient’s address | 3,998.50 BTC, unspent | mempool.space |
| Dollar value at $79,930 per BTC | about $319.6 million | CoinGecko |
| Time from Bitcoin payout to first public flag | 3 hours 54 minutes | block timestamps, @ErgoBTC |
| Time from Bitcoin payout to Liquid’s statement | 5 hours 56 minutes | block timestamps, @Liquid_BTC |
| Latest Elements release | 23.3.3, April 13, 2026 | GitHub |
The Explorer Still Says the Peg Is Whole
Ask Blockstream’s own explorer how much L-BTC exists and it will tell you about 197. Its asset page for L-BTC computes supply the only way an explorer can on a confidential chain: total pegged in, 18,356.88 BTC, minus total pegged out, 18,149.60, minus 10.03 burned. That comes to 197.25, and it matches the 197.47 BTC sitting in the federation wallet almost exactly. By the official accounting, Liquid is fully backed.
mempool.space’s figure, frozen at block 4,050,335 because its node stopped there, is 4,205.02 L-BTC. That is the supply as it stood one minute before the disputed block, and unless roughly 4,000 L-BTC of honest holders’ coins were burned on Sunday afternoon, it is also roughly the supply that honest holders still have in their wallets. Two explorers, both correct about what they measure, one showing a solvent peg and one showing 4.7 cents of Bitcoin behind every Liquid Bitcoin.
The gap is not an accounting error. It is what Confidential Transactions do. Every confidential L-BTC output on Liquid is a Pedersen commitment with a range proof; the chain verifies that inputs and outputs balance without anyone learning the amounts. That is the privacy feature Liquid sells, and it means that when the verification is wrong, no observer can see the extra coins. mempool.space runs a live audit of the peg, and it caught the incident, but read the alert again: it caught the Bitcoin leaving. It could not have caught the L-BTC being created. On a transparent chain, the Echo eBTC and KelpDAO rsETH mints in May and April were visible in the token’s total supply within the block. Here the mint, if that is what it was, is invisible by design, and the first number that moved was the reserve.
The Blast Radius
The blast radius is everyone holding L-BTC. The peg’s promise is one Bitcoin per Liquid Bitcoin, redeemable on demand through a partner, and the federation currently holds about 197 BTC against roughly 4,200 claims. If the funds come back, that ratio repairs itself. If they do not, someone has to decide whether Blockstream, the fifteen functionaries, SideSwap, or the holders absorb a $320 million hole, and no statement so far addresses it.
SideSwap sits in an awkward place. It did nothing its documentation does not describe: it accepted L-BTC that the Liquid chain said was valid and pegged it out for the customer who sent it. Its PAK was the instrument, not the fault. But its pre-existing UTXOs were mixed into the peg-out alongside the ones that descend from the disputed block, its change from that transaction descends from both, and its service is closed.
The wider chain is frozen for practical purposes. Aqua, a wallet built on Liquid, reposted the federation’s statement to its users within minutes. Swap services that move between Lightning and L-BTC need a chain that accepts transactions, and Liquid says it is not accepting them. Issued assets, including the USDT that gives Liquid most of its real-world volume, are technically untouched and practically immobile.
And the explorer Blockstream relaunched nine days ago with the line “Check Liquid’s backing yourself, in one dashboard” reports an L-BTC supply that matches the reserve, on a chain where it does not.
The Uncomfortable Questions
What was the bug? SideSwap’s second statement says “Blockstream has since established that the L-BTC in that order was created through a bug in the Elements software.” Neither company has said which bug. One public fact sits close enough to the incident to record, without claiming it is the answer. On August 3, Blockstream engineer Byron Hambly authored a one-file change to Elements titled “fix: range proof cache bind to asset and scriptpubkey”. Before it, a node’s cache of already-verified range proofs was keyed by the proof and the value commitment alone; after it, the asset commitment and the output script are part of the key. The commit landed on the 23.x branch on September 3. A pull request carrying it into the 23.3.x release branch, described as “clean cherry picks from 23.x branch, in preparation for 23.3.4rc2,” was opened on September 4, two days before the incident, and merged on September 6 at 17:21 UTC, less than three hours after the peg-out confirmed on Bitcoin. The current release, 23.3.3, dates from April 13 and does not contain it. A verification cache that ignores part of what a proof commits to is one shape of bug that could produce what darosior observed: nodes running the same code and reaching different verdicts on the same block, depending on what each had verified before. Nobody has publicly connected the fix to the incident, I do not know which Elements version the functionaries run, and Blockstream is the only party that can close this.
Why did the hardware sign? Because it was asked the wrong question. The functionary HSMs check that a peg-out goes to a whitelisted address and that the L-BTC amount burned matches the BTC amount requested. Both were true. The check that failed was whether that L-BTC had a legitimate origin, and no HSM can answer that; it trusts the Liquid chain, which trusts Elements. An 11-of-15 threshold is protection against eleven operators being dishonest or compromised. It is no protection at all when all fifteen run the same validation code and the code is wrong, because fifteen honest signers will unanimously sign the same mistake. Sunday’s withdrawal did not defeat the multisig. It never encountered it.
Why did the bridge run for two more hours? The federation signed two more peg-out batches after the reserve had dropped by 95%. mempool.space, an outside party, was comparing reserves to supply in real time and raised the alarm before Blockstream did. A watchman that refuses to sign when the reserve falls faster than the recorded peg-out volume explains, or that pauses when a batch exceeds some fraction of holdings, would have been a nuisance on any other day and would have saved nothing here, since the damage was one transaction. But it would have kept the federation from signing more withdrawals from a wallet it should already have known was drained, and it would have put the alarm inside the system instead of outside it.
Are they whitehats? Liquid says “purported,” which is the right word. The party holds 3,998.5 BTC and has held it for seven hours. They wrote one sentence, addressed to the federation’s own wallet, and have received two on-chain requests for contact. A whitehat who wanted to prove a bug could have pegged out 4 L-BTC and written the same message. Whoever this is pegged out 4,000, and possibly rehearsed with 4 first. The next transaction from bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte will say more than the label did.
Who pays if it does not come back? This is the question the Kelp piece ended on, and it applies with more force here because there is no protocol to route the decision through: no token, no DAO, no on-chain treasury. There is a company, fifteen functionaries who signed a legitimate transaction, a peg-out partner who followed its own rules, and holders. Liquid’s statement is about restoring the network. It does not mention the holders.
The Multisig Was Never the Perimeter
Every exploit we have covered this year had a privileged actor at the center of it: a role that could mint on Resolv, a single verifier on Kelp’s bridge, a mint permission on Echo, a proposal queue on Term that nobody read. Liquid’s design is a genuine attempt to eliminate that actor. Fifteen known companies, a supermajority threshold, hardware that refuses to pay anyone off a whitelist, a three-day delay on changing the whitelist, and emergency keys behind a 28-day timelock. It is one of the most carefully built custodial bridges in Bitcoin, and it had run since 2018.
It failed anyway, because all of that machinery guards the keys, and the keys were not the target. The target was the sidechain’s definition of what a valid Liquid Bitcoin is, and that definition lives in one codebase, run by all fifteen signers, verified by nobody outside them in a way that could stop a block. When mempool.space’s node disagreed with the functionaries about block 4,050,336, it could refuse to display the block. It could not refuse to let the watchmen pay it.
Confidential Transactions make the lesson sharper. On a transparent chain, a mint that should not exist is a number on a dashboard within seconds. On Liquid it is a Pedersen commitment that looks like every other Pedersen commitment, and the supply figure on the explorer Blockstream relaunched last week is arithmetic over peg-ins and peg-outs that cannot see it. The privacy that makes Liquid useful for Tether and for traders is the same property that let what looks like 4,000 unbacked L-BTC sit on the chain for thirteen minutes without anyone being able to notice, then leave as real Bitcoin.
If you hold L-BTC, the useful facts are the ones the chain shows: the federation wallet holds about 197 BTC, the chain tip is 4,050,335 on one explorer and past 4,050,779 on the other, and the party holding the rest has written one sentence. Everything after that depends on whatever conversation follows two on-chain requests for contact, and on a bug fix whose relationship to the incident nobody has yet confirmed.
