Liquid sidechain stays frozen after 3,400 of 4,000 BTC returns
Blockstream's Liquid sidechain has not signed a block since 04:49 UTC on September 7. The white hats returned 3,400 BTC; 598.5 BTC and the peg stay open.

Blockstream’s Liquid sidechain has not produced a block since 04:49 UTC on September 7, 2026. Twenty-seven hours later it still had not produced one. That is the detail no statement covers: Blockstream’s own Liquid explorer shows the chain tip frozen at block 4,051,232 on a network that had been minting a block every 60 seconds without a gap. Roughly 4,000 Bitcoin (BTC) left the Liquid Federation wallet, about 3,400 BTC has since come back, and the chain is still stopped.
The Blockstream status page logged the incident at 12:14 AM on September 7 and has not been updated since, even though the returned funds landed later the same day. Its wording is unchanged: “Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet.” It adds that the funds moved via the SideSwap Peg-out Authorization Key (PAK), but that the key “was not compromised, nor were any others,” that exchanges were notified and have paused LBTC deposits and withdrawals, and that Tether’s USDT, DePix and Real-World Asset (RWA) issuances on Liquid are unaffected. As of 08:00 UTC on September 8 the page still lists Liquid and Public Bridge Nodes as a major outage. Kraken’s public status page carried no LBTC notice at that hour.
The central technical claim deserves precision, because “no key was compromised” is true and still catastrophic. A Liquid peg-out burns LBTC on the sidechain, and the federation’s watchmen then release the matching BTC on Bitcoin to a destination whitelisted by a PAK entry. Per Liquid’s technical documentation, spending federation funds needs a greater-than-two-thirds multisig threshold and PAK list changes take three days to take effect. Nothing in that chain broke. Protos reports that all 83 inputs carried 11 valid signatures against the 11-of-15 multisig, and that the emergency path — two of three backup keys plus 8,064 blocks, roughly 56 days — was never touched. SideSwap says the LBTC presented for redemption had been created by a bug in Elements, the open-source software Liquid runs on. The signatures were valid, the authorisation was valid, and the tokens were not. The federation paid out real BTC against LBTC that should never have existed.
That is a different failure class from the validator-key compromise that cost AFX Trade $24m or the repeat flaw that hit Allbridge for $1.65m, and it is harder to defend against. Key custody worked exactly as designed. Issuance accounting did not. Jameson Lopp, chief security officer at Casa, told Protos: “Looks like the Liquid functionary codebase hasn’t been touched in two years, which isn’t a good sign.”
The peg arithmetic explains why bridge nodes are still down. Cumulative peg-ins on the explorer stand at 18,356.93 BTC across 117,335 transactions against 18,149.60 BTC of peg-outs and 10.03 BTC burned, netting to 197.30 BTC. Protos puts roughly 4,205 LBTC outstanding against that 197 BTC — under 5% backing at the trough. Add back the 3,400 BTC returned at 16:09 UTC on September 7, per Bitcoin Magazine’s reconstruction of the on-chain exchange, and backing recovers to about 3,597 BTC, or 86%. The 598.5 BTC the counterparties kept — about $46.9m at Coinbase’s $78,383 spot on September 8 — is the shortfall. Reopening peg-outs into that gap is what would produce a visible LBTC discount, which is presumably why nobody has.
Charles Guillemet, chief technology officer at Ledger, told Cointelegraph the retained sum looked “more like extortion than white-hat hacking” if it represented a negotiated reward. The Block reports Blockstream sent a PGP-signed message reading “Bridge nodes are patched, safe to return the funds” before the 3,400 BTC moved.
For anyone building on Liquid, the exposure is not the BTC leg. Liquid carries about $5 billion in Total Value Locked (TVL), most of it MIFIEL promissory notes and BMN2, plus roughly 97.6 million USDT. Those assets are intact, and every one of them is also unmovable while blocks are not being signed. That is the lesson for the tokenisation stack — the same stack behind deals like the LSE’s tokenised equity distribution arrangement, and the custody infrastructure Blockstream has funded through its stake in Komainu. A federated peg has one halt switch, and it halts everything on the chain, not just the asset that was attacked.
What to watch: the first block after 4,051,232, the roughly 270 transactions sitting in Liquid’s mempool when it resumes, whether Blockstream publishes an Elements post-mortem naming the validation defect, and whether LBTC trades at par when exchanges reopen withdrawals. Until blocks are signed again, every claim about the peg is unfalsifiable.
This article is informational analysis only and is not financial, investment, or trading advice. Cryptocurrencies are highly volatile and can lose substantial value rapidly. Past performance and historical patterns do not guarantee future results. Do your own research and consult a regulated financial adviser before making any investment decision.
Reporting by Karthik Subramanian. Filed 8 September 2026, 13:38 GMT.




