Blockstream Halts Liquid Network After $320M Exits via a 'Whitehat' Claim
A withdrawal equal to roughly 95% of Liquid Network's bitcoin reserves moved through a peg-out authorization key that Blockstream says was never compromised — a gap that matters more than the on-chain "whitehat" message left behind.
Key Takeaways
- Attackers moved 3,998.5 BTC (~$320M) — about 95% of Liquid Network's reserves — through the SideSwap peg-out authorization key (PAK), prompting Blockstream to pause the sidechain.
- Blockstream says the PAK and other federation keys were not compromised, but has not disclosed how the peg-out was authorized — that unexplained gap is the real story, not the attacker's messaging.
- Containment relied on disabling bridge nodes and asking exchanges to freeze LBTC — manual, operational levers, not on-chain circuit breakers.
- An on-chain "we are whitehats" claim is not evidence; only a verified, on-chain return of the full amount should factor into any decision to resume normal operations.
On 6 September 2026, an unauthorized withdrawal of 3,998.5 BTC (~$320 million) drained roughly 95% of the bitcoin backing Blockstream's Liquid Network, a federated bitcoin sidechain used for faster, confidential settlement. The transaction carried an on-chain message: "we are whitehats. contact us on chain." Blockstream paused the network within hours.
What happened
According to The Block, the funds were extracted through the SideSwap PAK (Peg-out Authorization Key) — one of the mechanisms Liquid's federation uses to authorize moving BTC back out to the Bitcoin mainchain. Liquid's reserves stood at roughly 4,200 BTC before the incident, meaning the withdrawal took nearly all of it. Blockstream's containment moves were fast but blunt: it disabled the federation nodes that bridge Liquid to the Bitcoin mainchain, halting new peg-outs and effectively freezing the sidechain, and it asked exchanges to suspend LBTC deposits and withdrawals to close off a second cash-out path. USDT, DePix, and other real-world assets issued on Liquid were reportedly unaffected.
The "whitehat" message doesn't resolve anything
Blockstream said it is "working to contact the parties responsible through an onchain signed message," but as of the incident's disclosure it had not confirmed the attacker's identity, intent, or any commitment to return funds. That distinction matters: a message claiming good intent is free to write and costs an attacker nothing, whereas verified on-chain return of the exact amount taken is costly to fake. Treating the two as equivalent — even provisionally — would be a mistake in any incident-response playbook, crypto or otherwise.
Why this matters beyond one sidechain
- "Not compromised" is a narrow claim. Liquid stated the PAK and other federation keys "had not been compromised, nor had any others," yet a $320M peg-out went through. That leaves open whether the gap was in authorization logic, session or signing-service handling, or some other layer upstream of the key material itself — Blockstream has not published a root cause.
- Federated bridges concentrate trust in a small number of authorization paths. Whatever the underlying flaw, a single key or mechanism controlling access to nearly all of a bridge's reserves is a high-value target regardless of how strong the key custody itself is.
- Reactive controls worked, but they were manual. Disabling bridge nodes and phoning exchanges is a reasonable first response, but it depends on humans reacting quickly — worth pressure-testing as a runbook before an incident, not discovering live during one.
- Attacker framing should never drive re-enablement decisions. The relevant question for any team watching this is not "do we believe them," but "has the full amount been returned and verified on-chain."
What to watch
The outcome hinges on three things: whether Blockstream publishes a technical root cause for how the PAK-based peg-out was authorized, whether any funds are actually returned on-chain, and how long the network stays paused before functionaries are confident enough to re-enable bridging. Until a root cause is public, teams relying on Liquid or similar federated sidechains for settlement should treat this as an open custody-risk question, not a resolved incident.
Frequently Asked Questions
What is Liquid Network?
Liquid Network is a Bitcoin sidechain operated by Blockstream and a federation of member institutions ('functionaries'), designed for faster, more confidential BTC-denominated settlement. It holds its own reserve of bitcoin (as L-BTC) pegged 1:1 to BTC held on the mainchain, moved between the two via the federation's authorization mechanisms.
Was Liquid Network's federation key compromised?
Blockstream stated that the SideSwap PAK (peg-out authorization key) and other federation keys were not compromised. However, it has not yet explained how a peg-out worth roughly $320 million was authorized, so the underlying cause remains undisclosed.
Should the attackers' 'whitehat' claim change how this incident is treated?
No. An on-chain message claiming good intent is unverifiable and costs nothing to send. The only evidence that should matter is whether the full amount is returned on-chain — Blockstream itself has only said it is trying to make contact, not that funds are confirmed recovered.