The Liquid Network, the Bitcoin sidechain operated by a federation of exchanges and custodians on software written by Blockstream, has been paused since Sunday afternoon after 3,996 BTC — about $321 million at Sunday’s Bitstamp close of $80,338.98, and roughly 95% of the bitcoin the federation held — was withdrawn to a single Bitcoin address by a party that later described itself, in a message written into the Bitcoin blockchain, as “whitehats.” Liquid’s statement on X, as reported by The Block at 5:14 pm EDT on Sunday, said approximately 4,000 BTC had been withdrawn from the federation wallet, that the withdrawal passed through the SideSwap peg-out authorisation key (PAK) but that neither that key nor any other had been compromised, that bridge nodes had been disabled so that no new transactions could be submitted, and that exchanges had been asked to suspend deposits and withdrawals of L-BTC, the token that represents bitcoin on the sidechain. “Effectively, the Liquid sidechain is paused until this issue is resolved,” the statement said. Other assets issued on Liquid — Tether’s USDT, DePix and tokenised real-world assets — were said to be unaffected, though wallets would be disrupted.

The mechanism, as far as it has been described, came from SideSwap, the Liquid swap service whose peg-out key was used. In a post on X quoted verbatim by Bitcoin.com News: “Today at 14:05 UTC, a customer sent 4,000 L-BTC to the SideSwap peg-out service. Our service processed it like any other order: the L-BTC was burned on Liquid with a valid peg-out authorisation, and at 14:28 UTC, the Liquid Federation paid 3,996 BTC to the customer’s Bitcoin address. Blockstream has since established that the L-BTC in that order was created through a bug in the Elements software.” Read carefully, that is the whole incident in three sentences. The peg-out itself was legitimate: a valid authorisation, a real burn, a real payment by the federation. What was not legitimate was the L-BTC being burned. Elements is the open-source codebase Liquid runs on; a bug in it allowed someone to create 4,000 L-BTC that no bitcoin had ever been deposited against, and the federation, which holds the real bitcoin, paid out against the counterfeit exactly as it would against the genuine article. Samson Mow, whose JAN3 makes the Liquid-based Aqua wallet, wrote on X (again per Bitcoin.com) that “The working theory is that the vulnerability is with Liquid’s Confidential Transactions, but devs cannot confirm at this time. The vulnerability is a node level isue and is not related to PAKs or HSMs.” Blockstream itself has not said what the bug is.

What the blockchain says, hour by hour

Because the coins left the sidechain for Bitcoin proper, everything that has happened since is public, timestamped and verifiable, and the desk pulled it directly from mempool.space at 06:13 UTC on Monday rather than from anyone’s summary of it. All times are UTC. At 14:01:57 on Sunday, in block 965,780, the receiving address — bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte — received 2.4975 BTC from a three-input transaction, twenty-seven minutes before the peg-out arrived; whoever did this prepared the address first. At 14:28:56, in block 965,783, the peg-out transaction paid it 3,995.99999857 BTC from a single input of 3,996.01834922 BTC, with 0.01834922 BTC going to change; the funding address of that input has two transactions in its history and now holds nothing. Four hours later, at 18:30:10 in block 965,818, the whole balance was consolidated in a transaction carrying an OP_RETURN output — the field in which a Bitcoin transaction can carry arbitrary text — that read: “we are whitehats. contact us on chain”. The same transaction sent 1,000 satoshis to a second address, bc1qdlld6…suhwxxr, which becomes important below.

Blockstream replied the same way. At 19:31:47, block 965,822, an address beginning bc1qn8mg wrote “Please contact security@blockstream.com” into a transaction to the whitehat address. At 20:38:14, block 965,829, a transaction to the whitehat address read “Please contact us on Signal @m671aw.70” — and this is the first place the desk’s own reading of the chain diverges from the weekend commentary. That message did not come from the address holding the coins; it was sent from a third address, bc1q7le6…, that appears nowhere else in the sequence. Ledger’s chief technology officer, Charles Guillemet, wrote on X (per Bitcoin.com) that “They now ask to be contacted on Signal. It doesn’t look like usual white hats practices,” and that was a fair reading on Sunday evening; but the chain does not show that request coming from the party with the money. Anyone can pay a few hundred satoshis to write a line into a transaction addressed to a famous address, and by Monday morning twenty-nine transactions from strangers had been sent to it, most of them advertisements: a wallet, a memecoin, two swap services, a bitcoin seller, and a lawyer offering “pro bono counsel for a clean return.” The Signal line should be read as one of those until someone shows otherwise.

Two signed messages from Blockstream, verified

At 01:49:49 on Monday, block 965,865, the bc1qn8mg address sent a longer message: an encrypted note “to the key behind bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte” using Electrum’s ECIES scheme — that is, readable only by whoever holds the private key that controls the 3,998 BTC — followed by a detached PGP signature described as “by security@blockstream.com” with the fingerprint 1176 542D A98E 71E1 3372 2EF7 4AC8 CC88 6844 A2D6 and instructions to verify it against the key at blockstream.com/pgp.txt. The desk did that: we fetched the key from Blockstream’s site, imported it, and ran the verification on the exact bytes in the transaction. The signature is good; it was made at 01:14:19 UTC by the key whose user ID is “Blockstream Security Reporting <security@blockstream.com>”. Whoever is talking to the whitehats from bc1qn8mg controls Blockstream’s published security key. That is as close to confirmation of identity as an on-chain conversation allows, and it is more than any of the weekend’s reports offered.

The whitehats answered at 02:20:18, block 965,869, spending the full 3,998.4985 BTC back to themselves with the note “sending most back to bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr, is that ok” — the same address they had tagged with 1,000 satoshis in their first message eight hours earlier. That address is a pay-to-witness-script-hash address, the kind a multisignature wallet uses; at our pull it held 197.47 BTC across 568 transactions. We have not found a Blockstream statement identifying it as federation-controlled and do not assert that it is; what can be said is that the whitehats chose it before Blockstream had said anything at all. Then, at 03:30:05, block 965,875, two messages landed in the same block. From bc1qn8mg, a PGP-signed “Yes, thank you.” — the desk verified this one too; the signature is good, made at 03:16:04 UTC by the same key. And from the whitehat address, the message that sets the terms: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix. The detail is as follows (encrypted using https://blockstream.com/pgp.txt).” A PGP-encrypted block follows, readable only by Blockstream. Galaxy Digital’s head of research, Alex Thorn, described this as encrypted technical details being sent, per Cointelegraph. Note the word “most” in the 02:20 message: the whitehats have said they will return most of the money, not all of it, and Blockstream’s signed reply was “Yes, thank you.” Whether a fee is being negotiated, and how large, is not in the public text.

What has not happened

As of 06:13:45 UTC on Monday, at block height 965,891, the whitehat address held 3,998.49853728 BTC, nothing had been broadcast from it to the mempool, and Liquid remained paused. The 3,996 BTC that left the federation is worth $321.0 million at Sunday’s Bitstamp close and $318.8 million at Monday’s 06:10 partial print of $79,768.43; The Block’s “$320 million” and Bitcoin.com’s “$319 million” are both fair roundings. The federation’s remaining bitcoin, on The Block’s figure of approximately 4,200 BTC before the incident, is on the order of 200 BTC — which is why the network cannot simply reopen: until the coins come back, the L-BTC in circulation is backed by about five cents on the dollar, and any peg-out queue would be a run. The number of L-BTC that were counterfeited is not known to be exactly 4,000; SideSwap’s post describes one order, and Blockstream has not published a reconciliation of L-BTC issued against BTC held. That reconciliation is the document to wait for.

Two things about this incident are unusual for a Bitcoin-adjacent failure and worth stating plainly. First, no key was stolen and no signer was tricked: the federation’s hardware security modules did what they were built to do, and the failure was in the sidechain’s accounting of how many L-BTC exist — a consensus bug, not a custody bug. That is why Mow’s “not related to PAKs or HSMs” matters, and why yesterday’s Trezor story and last month’s Coldcard theft are different animals from this one: those were failures at the edge, where a user holds a device; this one is at the centre, where a federation holds everyone’s coins. Second, the base layer was not involved. Bitcoin itself processed a valid transaction paying 3,996 BTC to an address that presented a valid authorisation, and then processed six text messages between the parties; it neither prevented the withdrawal nor could reverse it, and it was not asked to. Bitcoin’s price, for what it is worth, closed Sunday up 0.637% and was down 0.710% at Monday’s 06:10 print — the markers piece has the rest of the weekend’s numbers.

The marker

As standing practice we mark one falsifiable claim. T1: by 00:00 UTC on Monday 14 September 2026, at least 3,500 BTC has moved from bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte to bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr or to another address that Blockstream or Liquid publicly identifies as federation-controlled, per mempool.space. The reasoning for expecting it: the party with the coins has said in writing that it will return “most” of them after a patch, has named the destination unprompted, has been answered by a verified Blockstream key, and has behaved throughout as if it wants to be believed. The reasoning against: “after confirming the fix” puts the timing in the whitehats’ hands, a fix across every federation node is not a weekend job, and 3,500 is our threshold for “most” where the whitehats have not given one. A companion guide, How to Read a Sidechain Peg Incident, published today as Field Guide #44, explains what a federation, a PAK and a peg-out are and how to check each of the figures above yourself.

Sources: The Block, 6 September, 5:14 pm EDT, updated 6:32 pm, for Liquid’s statement and the reserve figure; Bitcoin.com News, 6 September, 8:30 pm EDT, for the SideSwap, Guillemet and Mow quotations; Cointelegraph, 7 September, 05:40 UTC, for the Thorn attribution; mempool.space for every transaction, timestamp, block height and balance, pulled at 06:13 UTC on 7 September; blockstream.com/pgp.txt for the key against which both signatures were verified. We have not fetched the X posts themselves; the quotations are as carried by the outlets named.

Disclaimer: This article is for informational purposes only and does not constitute investment advice. Cryptocurrencies are volatile and you can lose money. Nothing here is a recommendation to buy or sell any security, digital asset or exchange-traded fund, including MSTR, PURR or HYPE. Do your own research and consult a licensed financial advisor before making investment decisions.