The short version

  • A bug in Elements software let attackers generate unbacked L-BTC and redeem it for real BTC on September 6, 2026, draining approximately 4,019 BTC worth about $320 million from the Liquid Federation reserve.
  • 3,400 BTC has been returned; 598.5 BTC worth roughly $47 million at September 6 prices remains in the attackers' hands.
  • The attackers call themselves whitehats, but Ledger CTO Charles Guillemet publicly argued the arrangement looks more like extortion; no formal bounty agreement has been published.
  • Samson Mow, CEO of JAN3 and former Blockstream chief strategy officer, says Blockstream is still negotiating; the Liquid Network remains paused.

An Inflation Bug in Elements Created Bitcoin from Thin Air

Liquid Network is a sidechain — a separate blockchain that runs alongside Bitcoin and lets users transfer a token called L-BTC. Each L-BTC is supposed to be backed one-for-one by real bitcoin held in a multi-signature federation wallet controlled by a group of companies called the Liquid Federation. The network runs on open-source software called Elements, and that is where attackers found a critical flaw on September 6, 2026.

The flaw was what engineers call an inflation vulnerability. It let the attackers generate L-BTC that had no real bitcoin behind it — creating value on the Liquid side without any collateral. This exploit operated entirely within Liquid's software layer; Bitcoin's own consensus rules were unaffected. Every bitcoin sitting in the Liquid Federation reserve, however, was exposed to redemption by the fraudulent tokens.

Elements is open-source software, meaning its code is publicly readable by anyone. Blockstream, which developed Elements and maintains Liquid, had not published a detailed post-mortem or official security advisory as of September 9, 2026. Bitcoin Magazine and Crypto Briefing confirmed the bug resided inside Elements, though the specific lines of code responsible have not been publicly identified.

SideSwap's Legitimate Peg-Out Service Was the Exit Door

Once the attackers held unbacked L-BTC, they needed a way to exchange it for real BTC on the Bitcoin base chain. They used SideSwap, a legitimate service that processes peg-outs — the conversion of L-BTC back into BTC on the main Bitcoin network. SideSwap confirmed in a public statement that its own systems were not compromised and that its Peg-out Authorization Key remained intact throughout the incident.

What the attackers did was submit tokens that the protocol accepted as valid, because they were technically valid given the inflation bug. Think of it like redeeming counterfeit vouchers that a store's register reads as genuine — the register is not broken, the vouchers are fraudulent. SideSwap processed the peg-outs correctly by its own design; the flaw was inside Elements, which governs how L-BTC is created and validated.

The peg-out transaction that moved funds out landed in Bitcoin block 965,783 at approximately 14:28 UTC on September 6, 2026, according to sources citing block-explorer data. Bitcoin Magazine's initial reporting put the total amount at approximately 4,019.4 BTC. Several outlets rounded this to "4,000 BTC," which understates the true total by about 19 bitcoin — a difference of roughly $1.5 million at September 6 prices.

BTC Taken vs. Returned in the Liquid Network ExploitTotal taken4,019 BTCReturned to federation3,400 BTCStill outstanding598 BTC
BTC Taken vs. Returned in the Liquid Network Exploit · Bitcoin Magazine, Unchained Crypto; block 965,783, September 6, 2026

3,400 BTC Has Come Back; 598.5 BTC Has Not

On-chain data confirmed that 3,400 BTC arrived back at the Liquid Federation wallet after the attackers initiated a return. At September 6 bitcoin prices, that amounts to roughly $270 million recovered. The remaining 598.5 BTC — worth approximately $47 million at those same prices — had not been returned as of September 9, 2026. Bitcoin Magazine, Unchained Crypto, and Crypto Briefing all reported these figures consistently across their coverage.

The attackers embedded messages in Bitcoin transactions using a feature called OP_RETURN, which lets senders attach a small block of text to an on-chain payment. They used these messages to identify themselves as whitehats and to communicate conditions for returning the remaining funds. Those conditions reportedly include deployment of a security patch to Elements and a negotiated resolution — though no formal agreement has been publicly documented by either side.

Samson Mow, CEO of JAN3 and a former chief strategy officer at Blockstream, posted on X confirming that Blockstream is continuing to engage with the attackers. Mow no longer holds a position at Blockstream, so his posts represent his own public statements rather than official corporate communications. No formal press statement from Blockstream had appeared as of September 9, 2026, and no company blog post had detailed the recovery timeline.

StatusEstimated USD (Sep 6, 2026 prices)
Total taken from reserve~$320 million
Returned to Liquid Federation~$270 million
Still held by attackers~$47 million
Estimated dollar values at September 6, 2026 bitcoin prices; BTC figures from Bitcoin Magazine, Unchained Crypto, and Crypto Briefing

Self-Described Whitehats — A Label That Is Actively Disputed

Calling yourself a whitehat hacker is a self-designation, not a verified or regulated status. Legitimate whitehat security researchers typically disclose a vulnerability to the affected party before — or immediately after — discovery, under a responsible-disclosure agreement that often includes a pre-arranged bounty. The attackers here exploited the vulnerability first, moved roughly $320 million worth of bitcoin, and only afterward identified themselves as whitehats via OP_RETURN messages embedded in on-chain transactions.

Charles Guillemet, chief technology officer of hardware wallet company Ledger, publicly challenged the designation. Writing on X, Guillemet argued that retaining approximately $47 million in bitcoin while negotiating terms looks more like extortion than security research. Without a publicly documented bounty agreement, crypto markets and outside observers have no independent basis to assess whether the arrangement was pre-negotiated or improvised after the fact.

Bitcoin Magazine used "alleged" and "purported" throughout its early coverage — appropriate caution given the disputed facts. The legal and reputational outcome for the attackers could differ sharply depending on which label ultimately applies. A verified whitehat arrangement and an extortion scheme look identical from the outside if no formal documentation is published, and as of September 9, 2026, none had been.

  • Whether a responsible-disclosure agreement was signed before or after the exploit
  • What specific conditions the attackers set for returning the remaining 598.5 BTC
  • Whether any law enforcement agency has been formally notified by Blockstream
  • Whether a negotiated bounty rate was agreed upon before talks began

What Liquid Network Needs Before It Can Reopen

Samson Mow confirmed that the Liquid Network remains paused as of his most recent public update. The pause addresses two separate issues: additional security patches to Elements must be deployed to prevent any repeat, and a chain split — a disagreement between Liquid nodes about the correct version of the chain — must be resolved before the network can safely restart. Neither condition had been publicly declared complete as of September 9, 2026.

The incident highlighted the risk profile of federated sidechains, which depend on the correctness of their software stack. The Bitcoin network processed the peg-out transaction in block 965,783 without issue — every step on the base layer was valid. The exploit lived entirely inside the Liquid layer, which is why this event does not affect the bitcoin supply or compromise any BTC held outside the Liquid reserve.

Liquid Network recovering 3,400 of the approximately 4,019 BTC taken is a meaningful step, but full recovery depends on the remaining 598.5 BTC coming back and the network reopening without incident. Whether the self-described whitehats return those funds — and on what terms — remains the open question as of the reporting date. The outcome will also shape how the broader Bitcoin ecosystem evaluates federated sidechain security going forward.

Sources