Roughly 4,000 BTC left Blockstream’s Liquid Federation wallet on Sunday afternoon in an incident Protos described as a hack. The report valued the bitcoin at about $320 million.
According to Protos, 11 of the federation’s 15 keys signed the transaction, even though the Liquid Network tokens used to redeem the BTC should never have existed.
On-chain messages and immediate responses
By Monday morning, the attacker’s address still held 3,998 BTC and had published an OP_RETURN message that read, “we are whitehats. contact us on chain.”
An hour later, a second address replied, “Please contact security@blockstream.com.” A later message from the hacker allegedly included a Signal handle for further communication.
SideSwap, whose peg-out service processed the order, blamed the incident on faulty Liquid Bitcoin, or LBTC, originating from a third-party “Elements bug.” It denied responsibility on the part of “any SideSwap system.”
Liquid sidechain paused as dashboards diverge
Liquid Network confirmed the incident shortly after 4:25 p.m. New York time. It said, “Effectively, the Liquid sidechain is paused until this issue is resolved,” while bridge nodes were disabled and exchanges suspended LBTC deposits and withdrawals.
Mempool.space, itself a member of the Liquid federation, recorded “an unauthorized -4019 BTC withdrawal” in its real-time audit of federation holdings.
Protos said Liquid.net, the official Liquid Network dashboard, did not immediately reflect the loss. Mempool.space’s Liquid.network showed the reduction much sooner.
Bitcoin Core contributor Antoine Poinsot backed Mempool.space’s view, writing, “Liquid block 4’050’336 was rejected by @mempool but accepted by @Blockstream. This is the block that contains the peg-out transaction.”
How the transaction was executed
Protos reported that all 83 inputs to the drain transaction were spent with exactly 11 valid signatures on the federation’s 11-of-15 branch.
The network’s emergency path, which required two of three backup keys plus a wait of 8,064 blocks, or roughly 56 days, was not used.
Instead, the attacker used a regular peg-out request. Because enough signatures were present, the transaction went through.
The coins exited through SideSwap’s peg-out authorization key, or PAK. Liquid Network said it “was not compromised, nor were any others.”
Focus turns to Elements validation logic
Liquid runs its PAK check in Elements, an open-source fork of Bitcoin Core maintained largely by Blockstream.
Its public commit history shows a series of validation fixes in the first week of September. One commit, authored on the morning of September 1, was titled “Validation: always validate and retain dynafed header block_height.”
The commit message said that before the “always validate” change, “a dynafed header with a mismatched height could be accepted.” Protos said it could not establish that this was the bug used in the attack.
The report also noted that others blamed AI. Three days before the 4,000 BTC drain, OpenAI released GPT-6 Astra. Protos wrote that OpenAI described it as its first model able to find unknown vulnerabilities and exploits without assistance.
Reserve discrepancies resurface
Mempool.space operates Liquid.network, which showed 4,205 ostensibly BTC-backed LBTC outstanding against only 197 BTC in actual reserves, putting backing below 5%.
Protos said the two dashboards had diverged before. In January, liquid.network briefly showed 3,463 BTC backing 4,199 LBTC, and Adam Back blamed mempool.space for stale node software.
This time, according to Protos, mempool.space was more accurate than Liquid Network’s official Liquid.net dashboard.
Code maintenance draws criticism
Casa security chief Jameson Lopp posted, “Looks like the Liquid functionary codebase hasn’t been touched in two years, which isn’t a good sign.”
The article added that the public repository for that code last received a commit on April 19, 2024. In Protos’ framing, that was two years and four months before 95% of the BTC it guarded left the wallet.

