Blockstream's Liquid sidechain federation signed off on a $320M unauthorized BTC peg-out despite all keys remaining intact, exposing governance-layer vulnerability.
Security & Exploits ·
On September 6, 2026, Blockstream's Liquid sidechain federation authorized a withdrawal of 3,996 BTC—approximately $320 million—despite no cryptographic keys being compromised. The transaction originated through SideSwap, a whitelisted peg-out partner, and received signatures from eleven of the fifteen federation members who jointly control Liquid's Bitcoin reserves. Both SideSwap and Blockstream confirmed that no key material was breached, yet the federation processed the peg-out anyway, draining the federation wallet from roughly 4,200 BTC to 197 BTC.
The incident hinges on a distinction between key compromise and authorization failure. Liquid's governance model relies on an 11-of-15 multisig arrangement where functionaries must approve withdrawals to whitelisted destinations. The SideSwap key remained on the authorization whitelist and the signatures were cryptographically valid. However, SideSwap attributed the L-BTC being redeemed to a bug in Elements, Liquid's underlying codebase, rather than to legitimate user deposits. The recipient, identifying as a whitehat, froze the 3,998.5 BTC and signaled contact via Bitcoin's blockchain.
What remains unclear is the precise Elements vulnerability that allowed unauthorized L-BTC to exist in the first place, whether the funds will be recovered, and how losses to L-BTC holders will be addressed if restoration fails. Blockstream has not yet disclosed technical details of the bug or recovery plans.