What happened on September 6
SideSwap said a customer sent 4,000 L-BTC to its peg-out service at 14:05 UTC. The request appeared normal: the tokens were burned with valid peg-out authorization, and the federation paid the customer about 3,996 BTC at 14:28 UTC. The Bitcoin transaction confirms that 3,995.99999857 BTC reached the linked address in block 965,783.
Blockstream later established that the L-BTC used in the order had been created through a bug in Elements, the software underlying Liquid. SideSwap said neither its systems nor its Peg-out Authorization Key had been breached. Liquid likewise said no other keys were compromised. The failure therefore concerned validation of the asset before payment, not the cryptographic security of the reserve keys themselves.
Why valid signatures were not enough
A normal peg-in locks BTC in the federation wallet and creates an equal amount of L-BTC. A peg-out burns L-BTC and releases BTC. Federation devices verify the request, and 11 of 15 participants must sign the payment. This protects against a single stolen key, but it assumes the sidechain state and the tokens presented for destruction were validated correctly.
Here, the signatures could be authentic while the economic basis for payment was false: unbacked L-BTC passed software validation as legitimate. Independent technical reconstructions point to the caching of range-proof checks in Elements, but Blockstream has not published a complete post-mortem or formally identified the root cause. The implementation details therefore remain an attributed reconstruction rather than a final official finding.
The blockchain confirms a 3,400 BTC return
On September 7 at 16:09:25 UTC, transaction a6d697a2...49a46d returned exactly 3,400 BTC to Liquid's published federation address. Its second output sent 598.49955894 BTC back to the address linked to the original recipient. Roughly 85% of the withdrawn amount therefore came back, but the return was not complete.
The actors called themselves white hats in an OP_RETURN message and negotiated with Blockstream through blockchain messages. That self-description does not establish authorized testing. Neither side has disclosed a public bounty agreement or consent for the actors to retain nearly 598.5 BTC, so the accurate description is unidentified actors and undisclosed repayment terms.
Liquid paused its bridge, not Bitcoin
Liquid disabled its public bridge nodes and asked exchanges to pause L-BTC deposits and withdrawals. Blockstream's official status page still marked the incident active and Public Bridge Nodes as a major outage when checked on September 10. SideSwap also paused swaps, peg-ins and peg-outs until the network resumes.
The Bitcoin base network continued to operate normally. The flaw occurred in a separate federated sidechain system and its L-BTC issuance and redemption process. Liquid said other assets issued on the network, including USDT, DePix and tokenized real-world assets, were not directly affected. Those assets still require L-BTC for transaction fees, however, so the network pause also limits their practical availability.
An 85% return does not restore the peg by itself
The return transaction proves that 3,400 BTC arrived, but it is not a complete reconciliation of Liquid's reserves and liabilities. Until the current L-BTC supply, reserve addresses and restart conditions are published, observers cannot conclude that one-to-one backing has been fully restored. About 598.5 BTC remains an unresolved part of the incident.
This is the boundary between observable and asserted data. Bitcoin's ledger shows the amounts and destinations of the two large transactions. It does not reveal Liquid's full liabilities, the content of encrypted negotiations or who will ultimately cover any shortfall. A promise to return funds and a confirmed payment are also different events.
What L-BTC users should verify
Until an official restart is announced, users should not send BTC to peg-in addresses or attempt peg-outs through third-party instructions. Check the status of the specific wallet or exchange, preserve transaction IDs for unfinished operations and contact only the official support channel of the service that accepted the request. Any demand for a seed phrase, private key or additional payment is a scam signal.
After a restart, three separate confirmations matter: public bridge nodes are operational, the relevant exchange has resumed L-BTC service, and the federation has published a verifiable backing reconciliation. The incident shows that multisignature protects keys but cannot replace correct software-state validation. Sidechain risk includes issuance rules, peg-out logic and emergency governance as well as key custody.