Liquid Network Peg Drained: 4,019 BTC Verified On-Chain
Today someone pulled ~4,000 real bitcoin out of the Liquid Network's federation wallet — the reserve that backs every L-BTC in existence — and the whole negotiation is happening in OP_RETURN fields where anyone can read it. Press coverage is still converging, so I did what I do: walked the federation's Bitcoin mainchain wallet transaction by transaction, decoded every message myself, and checked the sidechain's own peg ledger. The receipts below are my queries, not someone's screenshot.
The payout, measured
Liquid's watchman wallet on Bitcoin mainnet is bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr — I pulled its full 565-transaction history from the mempool.space API and rebuilt the flows. For weeks it moved single-digit BTC a day, normal peg-out cadence. Then:
TX 8db751a650ae2f12006b7e8c69a75e4df360e8afd6b9e05ae0b9fa6458a7b140
block 965783 — 2026-09-06 14:28:56 UTC
wallet contributed: 4,019.44426085 BTC
out 3,996.01834922 BTC -> bc1qgslsydz56d0ed6827hdemfmk5w2f6ldyc6wt7p
out 2.65138358 BTC -> bc1qkxwva32eh7mgezq5kladncd3n5wtcjmslh98my
out 3.99601658 BTC -> bc1qk3cvk5599nydy8zwavlxaduke54pgf4vl0ckru
out 10 × 1.67791605 BTC -> change back to watchman
4,019.44 BTC in one transaction. The wallet's confirmed balance went from roughly 4,200.14 BTC to 197.47185268 BTC (75 UTXOs) — which closes the arithmetic exactly: 197.47 + 4,002.67 net outflow = 4,200.14. Within the hour the attacker peeled the funds onward: 3,995.99999857 BTC landed at bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte at 14:28:56, another 2.64987546 BTC moved at 14:46:43. That "…6gyqjlte" suffix is the address Bitcoin Magazine flagged; I confirmed it from the chain, not the article.
At $80,025/BTC (the ticker I pulled while researching), the parked pile is worth $319.9M. It has not moved since.
The peg ledger shows no burn
Here's the part that should worry every L-BTC holder. A legitimate Liquid peg-out burns L-BTC on the sidechain before the federation pays out mainchain BTC, and every peg event is recorded in Liquid's own dashboard API. So I queried it:
# liquid.network (mempool fork) peg ledger
curl -s https://liquid.network/api/v1/liquid/pegs
{"amount": "420501883617", "lastBlockUpdate": 4050335, ...} # 4,205.02 LBTC still "pegged"
curl -s https://liquid.network/api/v1/liquid/pegs/list/0 # newest peg events
# newest entry: 2026-09-06 13:16:32 UTC — 0.55487682 LBTC, txid e806cb59...
# BEFORE the 14:28:56 payout. No event matches it.
The ledger still says 4,205.02 L-BTC is pegged. The reserve actually holds 197.47 BTC. That gap is the signature of what press reports describe as a suspected sidechain inflation bug: mint L-BTC that never existed, request a peg-out through a legitimate PAK-approved path (Blockstream says the SideSwap Peg-out Authorization Key was not compromised), and the federation's HSM signing servers approve a 4,019 BTC mainchain payment because every check they perform says it's valid. The mechanism isn't confirmed yet — Blockstream's 20:25 UTC statement only says the keys weren't compromised — but the missing burn is a fact I verified independently of any newsroom. The ceremony worked exactly as designed on inputs that weren't real.
Blockstream has since disabled bridge nodes — the sidechain is effectively paused for pegs, though it still produces blocks — and exchanges have been pausing L-BTC deposits and withdrawals. USDT, DePix and other issued assets are reportedly unaffected. None of that changes the accounting: until the ~4,000 BTC comes back, every L-BTC in circulation is a claim on a reserve that's 95% gone.
The on-chain negotiation, decoded
At 18:30:10 UTC the attacker consolidated 3,998.49748445 BTC to themselves and, in the same transaction, burned a message into OP_RETURN. I decoded it directly from the scriptPubKey:
TX c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19 — 18:30:10 UTC
IN 3,995.99999857 + 2.49749857 BTC (attacker consolidation)
OUT [OP_RETURN] "we are whitehats. contact us on chain"
OUT 0.00001000 BTC -> watchman wallet (a knock on the door, on-chain)
OUT 3,998.49748445 BTC -> bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte (self)
What followed is a live negotiation nobody had to set up, because Bitcoin's data carrier gives everyone a public channel:
- 19:31 — presumed Blockstream (press flagged it; I can't verify ownership): OP_RETURN "Please contact security@blockstream.com", with 1,000 sats to the attacker's address.
- 20:38 — a third party: "Please contact us on Signal @m671aw.70" — from a different input address than the reply above, which supports the "spam or opportunist" reading.
- 22:31–23:08 — at least four wallet-marketing ads ("Not your keys, not your coins. Get @ApertureApp...") addressed to the heist address, one binary garbage payload, and a lawyer: "LNY lawyer @btclawyerguy. pro bono counsel for a clean return. reply on chain."
Current state, measured: 3,998.49847670 BTC confirmed at the attacker's address, plus ~6.6 BTC split across the peeling chain — unmixed, unmoved, ~9 hours after extraction. The "whitehat" label is a claim, not evidence; a thief who knows the network is watching can park funds and ask for a finder's fee. The Poly Network precedent says returns happen. The chain says nothing has been returned yet.
graph LR W["Federation watchman wallet
197.47 BTC remaining"] -->|"3,996.018 BTC
tx 8db751a6..."| P1["peel address"] W -->|"2.651 + 3.996 BTC"| P2["side outputs"] P1 -->|"3,995.99999857 BTC"| H["attacker consolidation
bc1q…6gyqjlte"] P2 -->|"2.49749857 BTC"| H H -->|"3,998.49847670 BTC
parked, unmixed"| H H -->|"1,000 sats + OP_RETURN note"| W
Bottom line
A federated sidechain is a promise that 15 known companies will guard the bridge. Today that promise held perfectly — the 11-of-15 multisig, the PAK allowlist, the HSM signing ceremony all functioned — and ~4,000 BTC left anyway, because the thing they were validating was minted out of thin air on the other side of the bridge. Trust distributed across fifteen signers is still trust in one consensus implementation. If you hold L-BTC, your balance is currently backed by 197 BTC and a conversation happening in OP_RETURN fields. Watch the attacker's address — bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte — because the next move, refund or ransom, will be published on-chain by both parties before any press release.