On September 6, 2026, roughly 4,000 BTC walked out of the Liquid Network’s federation wallet through a vulnerability that, on the surface, looked like a perfectly normal transaction. No alarms, no broken keys, no obvious intrusion. Just a peg-out processed by SideSwap that quietly drained what was then worth around $320 million.

By the following day, 3,400 of those Bitcoin had come back. About 598.5 BTC, worth roughly $47 million, have not.

What actually happened

The flaw lived inside Elements, the open-source software that Liquid runs on and that itself descends from Bitcoin Core. The vulnerability allowed someone to generate unbacked L-BTC tokens, essentially printing claims on Bitcoin that had no real collateral behind them. Critically, none of the federation’s private keys were touched, and SideSwap’s infrastructure showed no signs of compromise. The withdrawal moved through standard authorization channels, which is precisely what made it so hard to catch in real time.

The actors who executed the drain subsequently identified themselves as white-hat hackers. They chose an appropriately on-brand communication method: Bitcoin’s OP_RETURN field, a data-carrying component of Bitcoin transactions typically used for small messages, combined with PGP-encrypted text.