Blockstream Loses 4,000 Bitcoin From Its Liquid Sidechain

Blockstream Liquid sidechain halted, a severed bridge and an emptied bitcoin vault

Roughly 4,000 of the 4,200 bitcoin held in the Liquid federation wallet left the network, worth $320M at the time. Blockstream paused the sidechain overnight on September 7 and switched off its bridge nodes while it works out what happened. The parties behind the withdrawal call themselves white hats and say the coins come back once the flaw is patched. Nothing has come back yet.

Key Takeaways

  • About 4,000 BTC of 4,200 left the Liquid federation wallet, worth $320M.
  • Blockstream blames a software bug in Elements rather than compromised keys.
  • The network sits paused and exchanges have frozen LBTC deposits and withdrawals.

Four Thousand Bitcoin Walk Out of the Federation Wallet

Liquid is a Bitcoin sidechain Blockstream launched in 2018, built for fast confidential transfers and asset issuance between trading venues. Its federation wallet held 4,200 BTC backing the LBTC in circulation. It now holds 197.

Blockstream’s own status page opened an incident titled “Liquid Security Incident” at 12:14 AM on September 7. The wording leaves little room: bridge nodes are temporarily disabled, no new transactions can reach the network, and the sidechain stays paused until this is resolved. The detail sits in the incident page Blockstream maintains itself.

The playbook echoes the call Crypto.com made when it halted its own blockchain after a $75M theft, except the figure here runs four times larger. Killing the network remains the only lever available once the reserve backing a token has been emptied.

Trading venues moved within hours. Liquid notified exchanges, which suspended LBTC deposits and withdrawals or said they were about to. An LBTC that cannot be redeemed for bitcoin is a token with no exit.

One detail matters for holders. Other assets issued on Liquid, including USDT, DePix and tokenized real-world assets, were untouched. The hole sits in the bitcoin reserve, not across every issuance on the chain.

That narrow blast radius creates an awkward position rather than a clean one. A chain whose flagship asset loses its backing while third-party issuances keep clearing ends up half solvent on paper, with one side of the balance sheet intact and the other missing.

Nothing about the exit looked like a break-in. The coins moved through SideSwap, an approved trading venue on the network, which is why no conventional alarm fired. The flow read as ordinary business until someone reconciled the reserve balance against outstanding issuance.


Blockstream
Advertisement – investing involves risk.

A Bug in Elements, Not a Stolen Key

Blockstream ruled out the worst scenario early. The keys were not compromised, and neither was the peg-out authorization key SideSwap uses. The funds left through a route the system considered legitimate.

The company points to a software bug in Elements, the codebase the sidechain runs on. Early evidence describes an inflation flaw on the LBTC side that let someone mint more than 4,000 unbacked tokens and redeem them against the real bitcoin sitting in reserve. The break happened at node level, not in signing hardware.

The distinction is not cosmetic. Stolen keys get revoked and rotated. An internal accounting bug forces an audit of every node on the network plus proof that the displayed balance matches the actual reserve, and that takes far longer.

It also changes who carries the blame. A stolen key points at whoever held it badly. A mint that the software itself authorized points at the design, and at every operator who ran the code without catching the gap between issued tokens and reserve.

Bitcoin’s periphery knows this pattern well. A BTCPay Server flaw drained Lightning nodes back in August, on the same logic of a defect in an adjacent layer rather than in the protocol. Bitcoin itself has nothing to answer for here. Its outbuildings are what keep failing.

The trust model deserves saying plainly. A federated sidechain asks the holder to trust a group of operators and their code, not only the mathematics underneath Bitcoin. That is the price of fast confidential transfers, and it just came due. The same lesson followed the Coldcard flaw that drained $70M in bitcoin in 41 minutes, where the weak link was again a piece of trusted software.

One unknown now sits with the federation operators. An inflation defect that worked once could have worked earlier, in smaller size, without anyone noticing. Reopening the network therefore means auditing the full issuance history, not just patching the current code.


Also on Cryptonomic:


The Takers Want a Patch Before They Give It Back

The withdrawal arrived with a message written into the chain. First a terse “contact us on chain”, then an OP_RETURN spend from the same address pointing to a Signal handle. Blockstream confirmed on September 6 that it was trying to reach the parties through a signed onchain message.

What followed came with a condition attached. The parties want the vulnerability fixed and every node updated before they return most of the bitcoin. No funds have moved back so far, which leaves the promise impossible to verify.

The white hat label deserves handling with tongs. It gets confirmed when coins return, never when the claim is made. Block eventually identified the thief behind the Coldcard hack, and an onchain conversation with an attacker did not stop that investigation from running.

For the coming days an LBTC holder has no lever at all. They wait for the federation to restore the bridges while their token sits frozen on venues that closed the taps. Nothing unlocks before the reserve is rebuilt or the accounting is settled.

Blockstream has published neither a restart date nor an indicative window, which fits an investigation still running but leaves holders without a horizon. Any timeline it gives before the issuance history is checked would be a guess anyway.

Over three to six months the live question is trust in Bitcoin’s adjacent layers. Sidechains and bridge protocols have stacked up incidents, including three DeFi protocols drained of $35M in six hours this summer. Each episode nudges liquidity further toward the layers that are simplest to audit.

The market barely registered any of it. Bitcoin held around $80,000 through the episode, which says $320M stranded on an adjacent chain does not weigh on the main asset. The damage lands on Liquid’s reputation rather than on price.

That indifference is itself a measurement. It sizes the place Liquid actually occupies, useful settlement plumbing for a handful of venues, but not something whose shutdown moves the wider market.

Two outcomes remain open. The coins come back after a patch and the episode becomes a full-scale audit, expensive in credibility but with no realized loss. Or they stay gone, and someone has to say who absorbs the hole between the federation, the issuers and LBTC holders. That allocation has never been settled in public, and it is what decides what a token backed by a federated reserve is really worth.

Follow the story on Cryptonomic.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    Your email address will not be published. Required fields are marked *