Morning Edition · Monday, September 7, 2026Published at 1:46 AM EDT · New York
Blockstream says no keys were stolen. The federation's signing hardware approved the withdrawal because the software judged the counterfeit tokens valid.

Blockstream paused the Liquid Network on Sept. 6 after roughly 4,000 bitcoin left the federation wallet that backs L-BTC, the pegged bitcoin token that circulates on the sidechain. CoinDesk valued the withdrawal at about $320 million and reported that the settlement layer, used by exchanges and traders to move bitcoin faster than the base chain allows, stopped processing transactions. Bridge nodes were disabled and exchanges were asked to suspend L-BTC deposits and withdrawals, Bitcoin Magazine reported.
The attack path was not a stolen key. Preliminary accounts point to an inflation defect in Elements, the open-source software Liquid runs, which allowed the creation of more than 4,000 L-BTC that no bitcoin backed. Those tokens were then redeemed through an ordinary peg-out. Because the redemption satisfied the consensus rules as the software implemented them, the hardware security modules held by federation members signed the bitcoin transaction. Blockstream's public proof-of-reserves page showed federation holdings falling from more than 4,200 bitcoin to just over 200.
The people holding the coins have communicated in public. They moved funds and attached messages in the arbitrary-data field of bitcoin transactions, first stating that they are ethical hackers and asking to be contacted on-chain, then supplying a Signal handle. A reply transaction, presumed to come from Blockstream, carried a contact address. Watcher Guru reported that the group intends to return the bitcoin once the vulnerability is fixed, and Cointelegraph reported that Liquid described the withdrawal as the work of people claiming to be ethical hackers. No return has been confirmed.
Two interpretations of these facts are possible, and neither can yet be ruled out. If the group is genuine, the on-chain messages are the cheapest way to open negotiation and secure a fee. If it is not, the same messages delay a reckoning while the market decides what unbacked L-BTC is worth. What this incident makes clear is the trust model underneath it: L-BTC holders were never exposed to Bitcoin's consensus, they were exposed to a federation's software and its signing policy, and one defect in that software converted a claim on 4,200 bitcoin into a claim on roughly 200.
Part of a tracked trend
Losses Move to Components That Worked as Designed
A growing share of DeFi losses will come not from buggy contract code but from components behaving exactly as specified — oracle forwarders, validator signature sets, governance votes and other trusted off-contract inputs — so audits and bug bounties scoped to on-chain code keep missing the failure surface, and protocols will be repeatedly forced to extend review, scope and monitoring to their privileged operational infrastructure.
Start a discussion in Townsquare.
More from this edition
The people holding roughly 4,000 bitcoin gain the most from the ethical-hacker framing, since it converts a theft into a bounty negotiation, while Blockstream gains from an explanation that locates the failure in Elements software rather than in custody of federation keys.
The mechanism is well corroborated across outlets and the proof-of-reserves drop is visible on-chain, but the motive is asserted only by the party holding the coins, and Ledger chief technology officer Charles Guillemet argues that draining nearly all reserves before making contact departs from white-hat practice.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Every wrapped or pegged bitcoin token is a credit claim on the operator of the peg, and this incident shows the claim can fail without any key being compromised. The exposed parties are L-BTC holders, the exchanges and trading desks that used Liquid for fast settlement, and Blockstream, which must decide whether to fully compensate holders from its own balance sheet if the coins are not returned. The broader channel runs through every federated or multi-signature bridge: audits scoped to signing security do not catch a mint defect that makes a fraudulent withdrawal look legitimate to the signers.
What to watch
Observations to monitor, not financial advice.
Synthesized from: CoinDesk · Bitcoin Magazine · Polylog editors
Comments
0No comments yet.