BREAKING
Bitcoin’s broader market remained relatively stable at the time of this incident, with BTC price action showing limited immediate reaction to the news. The event unfolded on September 7, 2026, and is being treated by security researchers and the wider crypto community as one of the largest single-event Bitcoin-adjacent security breaches in recent memory. Despite the scale of the drain, early reports indicated no significant BTC movement toward exchanges in the immediate aftermath.
The Security Incident
An unidentified attacker — or group — removed 3,998.5 BTC, valued at approximately $319.5 million, from Liquid Network’s federation wallet in a single on-chain transaction. Notably, the attacker embedded a message within the transaction reading “we are whitehats. contact us on chain” — a claim that, as of reporting, remains entirely unverified by any independent party or Liquid’s team. The withdrawal was routed through SideSwap’s Peg-out Authorization Key (PAK), though Liquid Network stated the key itself was not compromised.
Scale of the Drain
The impact on Liquid Network’s federation wallet was severe and quantifiable:
- The federation wallet balance dropped from approximately 4,200 BTC to just 207.275 BTC following the transaction
- The net outflow of 3,998.5 BTC accounts for the full reported drain figure of $319.5M
- Liquid Network subsequently paused all new transactions and bridge node activity while federation members worked to restore operations
- Assets issued on the Liquid sidechain — including USDT and other tokenized instruments — were reported to be unaffected by the drain
Why This Matters
This incident is widely interpreted as a critical test of federated Bitcoin sidechain security models. Analysts commonly view the routing of a near-total federation wallet drain through a legitimate peg-out mechanism — rather than a direct exploit of private keys — as a particularly complex and concerning attack vector. The white-hat claim, while unconfirmed, introduces an additional layer of ambiguity: if genuine, the funds could theoretically be returned; if not, the $319.5M represents an outright loss from the ecosystem. Blockstream, which backs Liquid Network, was reported to be actively attempting to contact the attacker on-chain via a signed message, a response strategy that underscores the unusual nature of this event. The fact that the PAK was used but not itself compromised raises deeper questions about authorization controls within the federation structure.
The broader crypto security community is monitoring this situation closely. No confirmed movement of the drained 3,998.5 BTC to centralized exchanges had been detected in the initial reporting window, leaving open the possibility — however unconfirmed — that the attacker’s white-hat claim could yet result in a full or partial return of funds. The incident is a stark reminder of the custody and authorization risks inherent in federated sidechain architectures, and will likely prompt a wider review of peg-out controls across similar Bitcoin Layer 2 infrastructure. Community reaction has been one of alarm, with security researchers calling for full transparency from Liquid’s federation members regarding how the authorization sequence was triggered.
CoinsProbe may publish sponsored articles, affiliate links, or promotional collaborations. All sponsored material is clearly labeled to maintain transparency with our audience. Our editorial decisions remain fully independent, and advertising partnerships do not influence reviews, rankings, or published opinions.
Since 2023, CoinsProbe has delivered reliable insights on cryptocurrency, blockchain, and digital assets. Our content is created by experienced researchers and analysts who follow strict editorial standards focused on accuracy, transparency, and credibility. Every article is carefully reviewed and verified using trusted sources and current market data. We provide unbiased analysis and timely updates covering everything from emerging crypto projects to major industry developments.



