Liquid Network Hacked for $320 Million in Bitcoin Sidechain Exploit
A major security incident has rocked the crypto community after a $320 million Bitcoin sidechain exploit on Liquid Network, a federated sidechain built by Blockstream for faster settlement and confidential asset issuance. On September 6, 2026, roughly 4,000 BTC was moved out of the federation wallet that backs Liquid Network through the SideSwap Peg-out Authorization Key (PAK) mechanism.
According to Liquid's own statements, the funds left through a peg-out authorization, but the company claims no evidence of direct compromise of the PAK itself or its other signing keys. However, this incident raises concerns about the design problem in how peg-outs are authorized, which may require a hard fork or protocol patch to fix.
The Liquid Network's security design relies on a federation, not a single custodian, with 15 functionaries operating the block-signing infrastructure at any given time. However, this incident highlights that an attack on the PAK mechanism can bypass the multisig threshold, which is supposed to prevent a lone rogue signer or a stolen key from draining the pool.
The incident has sparked immediate fallout, with exchanges cutting off L-BTC deposits and withdrawals, and Blockstream attempting to reach the entity behind the withdrawal through an on-chain signed message. The broader market impact is contained for now, but this incident highlights the risks associated with sidechains, which carry different risk profiles than the base chain.