Software bug drains 3,996 BTC from Liquid Network federation reserves

Editorial illustration: Copper-colored blocks spill from a transparent blue compartmented structure into a shallow tray. Rails connect the central structure to five black boxes.

In brief

  • Software bug drained 3,996 BTC (95% of reserves) from Liquid's federation wallet on September 6
  • Withdrawn funds remain unreturned; on-chain messages claimed white-hat security researcher involvement
  • Reserves fell from ~4,200 BTC to ~197 BTC, eliminating safe peg-out buffer

The withdrawal and response

The peg-out transaction processed around 14:28 UTC on September 6. Minutes earlier, at 14:05 UTC, SideSwap, a decentralized exchange on Liquid, facilitated a customer submission of 4,000 L-BTC. The sequence triggered the bug.

Both Blockstream and SideSwap attributed the withdrawal to a bug in the Elements node software, the open-source codebase underlying Liquid. It wasn't a compromised key or external hack. The vulnerability sat in the infrastructure layer itself—not in the cryptographic signing process or federation model.

The federation moved fast. The federation paused all bridge nodes and alerted exchanges to halt L-BTC deposits and withdrawals immediately after. On-chain messages from the recipient address claimed the actors were white hats, security researchers who exploit vulnerabilities to expose them. As of the latest available reports, zero BTC has been returned.

Peg stability at risk

The technical backing of L-BTC remains intact. The remaining L-BTC in circulation should still be backed 1:1 by BTC because a corresponding volume of L-BTC was burned before the Bitcoin left the reserves. But the practical risk is severe.

"With only about 197 BTC sitting in federation reserves, the network has almost no buffer to handle redemption demand if peg-outs reopen." — Crypto Briefing

If users rush to exit L-BTC for Bitcoin before confidence returns, the federation won't have enough reserves to honor redemptions without triggering a discount. That discount erodes trust in the peg itself.

Scope and implications

Other assets on the Liquid Network, including USDT and tokenized securities, appear unaffected by the bug. The vulnerability was specific to the bridge layer. Liquid has been operational since 2018, yet a node-level bug still bypassed 6+ years of assumed battle-testing.

The incident underscores a critical weakness in federated sidechains: even robust governance models can't protect against flawed software. The 11-of-15 federation worked as designed. The Elements node didn't.