On September 6, a software vulnerability on the Liquid Bitcoin sidechain enabled attackers to create approximately 4,000 units of L-BTC without any corresponding bitcoin backing them, according to a technical analysis by CertiK, a blockchain security firm. The attackers then swapped these tokens for actual bitcoin using Liquid’s peg-out withdrawal mechanism, removing about 95% of the total bitcoin held within the sidechain. The incident resulted in the sidechain’s operations being frozen that same day.
How Liquid’s peg-out system works
Liquid operates as a federated Bitcoin sidechain, developed and managed by a consortium of exchanges and companies that collectively maintain the custody of real bitcoin in a multi-signature wallet. The sidechain’s native token, L-BTC, is fully backed by these reserves, and moving funds out from Liquid—the process known as “peg-out”—requires a specific Peg-out Authorization Key (PAK). Only users with registered PAK entries can directly unlock bitcoin from the main Bitcoin network, while the majority of users are required to engage with a federation member or a participating exchange.
The system is designed with strict controls so that even if certain federation members are compromised, unauthorized transfers to malicious addresses are prevented. However, attackers managed to exploit a loophole in this process.
Alex Thorn, head of firmwide research at Galaxy Digital, discussed the incident on Unchained’s Uneasy Money podcast. Thorn explained that, although the protocol is supposed to restrict direct peg-outs, platforms such as SideSwap facilitate easier withdrawals by relaying customer requests and forwarding BTC to any address provided. Thorn characterized this process as effectively circumventing the intended access list, noting, “SideSwap will just let anyone show up with an address and withdraw from Liquid and just auto-forward it.” He went on to say, “I don’t know why or why this was allowed.”
SideSwap will just let anyone show up with an address and withdraw from Liquid and just auto-forward it to whatever address the customer supplies. Doing an end run around the allow list—why this was allowed remains unclear.
Liquid’s official documentation confirms that everyday users typically go through either a federation member or third-party exchanges like Bitfinex and SideSwap for peg-outs. Customers deliver L-BTC and specify a Bitcoin address, receiving BTC in return once the network’s processes are complete.
Technical cause and asset impact
CertiK attributed the exploit to an “ambiguous cache-key encoding in the rangeproof verification cache,” which allowed an attacker to prime the cache and pass a forged transaction through verification without full validation. This process led to the minting of 3,998.5 unbacked L-BTC, which CertiK valued at roughly $318.7 million at the time of the incident.
Liquid and SideSwap both stated that their key infrastructure remained uncompromised and the withdrawal system itself functioned as intended from a technical perspective. SideSwap reported that the tokens were processed with valid authorization, and the service was unable to differentiate the counterfeit L-BTC from legitimate ones. In the wake of negotiations, the attackers, identified as self-described white-hat hackers, have returned 3,400 BTC and retained 598.5 BTC.
| Asset | Created/Taken | Returned | Retained by Attackers |
|---|---|---|---|
| L-BTC minted unbacked | 3,998.5 | — | — |
| BTC withdrawn from Liquid | 3,998.5 | 3,400 | 598.5 |
Mini dictionary: Liquid is a Bitcoin sidechain built and operated by Blockstream and a federation of exchanges. It enables fast, confidential, and interoperable transfers of bitcoin (as L-BTC tokens) between participating platforms. SideSwap is a non-custodial swap provider that functions as a member of the Liquid federation, offering atomic swaps and peg-out services to users on the Liquid network.
While the sidechain remains paused, the exploited bug and subsequent asset recovery draw attention to the complexities involved in cross-chain custody and security frameworks for federated blockchains. The Liquid federation has announced ongoing efforts to address the vulnerability and review the procedures that enabled the withdrawal.




