Hack Drains 4,000 BTC from Blockstream's Liquid Network

A hacker stole 4,000 BTC from Blockstream's Liquid Network by exploiting a fault in the peg-out authorization process.

07/09/2026 12:2814 min read

After a hack on Sunday afternoon, approximately 4,000 BTC, valued at around $320 million, exited the Blockstream Liquid Federation wallet.

The transaction was signed by 11 of the federation's 15 keys, despite the fact that the Liquid Network tokens used to redeem the BTC should never have been created.

By Monday morning, the attacker's address still contained 3,998 BTC and had broadcast an OP_RETURN message stating, "we are whitehats. contact us on chain."

An hour after that, another address replied, "Please contact security@blockstream.com." The hacker reportedly followed up with a message offering a Signal contact for continued dialogue.

SideSwap, the service that handled the peg-out order, attributed the event to defective Liquid Bitcoin (LBTC) that came from a third-party "Elements bug," and said it was not at fault in "any SideSwap system."

At around 4:25 p.m. New York time, Liquid Network confirmed the breach, stating, "Effectively, the Liquid sidechain is paused until this issue is resolved," and noted that bridge nodes had been shut down while exchanges halted LBTC deposits and withdrawals.

Mempool.space, which is also a member of the Liquid federation, recorded "an unauthorized -4019 BTC withdrawal" during its live audit of federation assets.

The official Liquid Network dashboard, Liquid.net, did not update to show the loss right away. Mempool.space's Liquid.network, however, displayed the shortfall soon after.

Bitcoin Core developer Antoine Poinsot backed up Mempool.space's account, observing, "Liquid block 4'050'336 was rejected by @mempool but accepted by @Blockstream."

"This is the block that contains the peg-out transaction."

Further Details on the Liquid Bitcoin Breach

The drain transaction used all 83 inputs, each spent with precisely 11 valid signatures on the federation's 11-of-15 branch.

The emergency route, which requires two of three backup keys plus a waiting period of 8,064 blocks (about 56 days), was completely circumvented.

Rather than trying an emergency override, the attacker submitted an ordinary peg-out request, and since they had sufficient signatures, it went through.

The funds exited via SideSwap's peg-out authorization key (PAK), which Liquid Network asserts "was not compromised, nor were any others."

Liquid performs the PAK verification within Elements, an open-source Bitcoin Core fork primarily maintained by Blockstream. That software's public commit history includes a series of validation fixes dating from early September.

One commit, made on the morning of September 1, is titled "Validation: always validate and retain dynafed header block_height."

The commit message states that before the always validate alteration, "a dynafed header with a mismatched height could be accepted."

Protos was unable to confirm that this particular bug was the one exploited by the attacker.

Some observers pointed the finger at artificial intelligence. Three days prior to the 4,000 BTC theft, OpenAI launched GPT-6 Astra, which it described as its first model capable of independently discovering unknown vulnerabilities and exploits.

Mempool.space operates Liquid.network, which recorded 4,205 supposedly BTC-backed LBTC tokens in circulation versus only 197 BTC in actual reserves, representing less than 5% backing.

The two dashboards previously showed a discrepancy in January.

At that time, liquid.network briefly displayed 3,463 BTC backing 4,199 LBTC, and Adam Back attributed the difference to outdated node software on mempool.space. This time, mempool.space proved more accurate than the official Liquid Network Liquid.net dashboard.

Casa's head of security, Jameson Lopp, wrote, "Looks like the Liquid functionary codebase hasn't been touched in two years, which isn't a good sign."

The public repository for that code saw its last commit on April 19, 2024. That was two years and four months before 95% of the BTC it was supposed to protect was taken.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles