On the evening of September 6, 2026, a message showed up in a Bitcoin block. Not in a forum post, not in a tweet, but embedded directly in a transaction, in a small field called OP_RETURN that anyone can write into. It read:
we are whitehats. contact us on chain.
Four hours earlier, the wallet that sent it had walked away with roughly 3,996 BTC, worth around $320 million at the time, drained from Liquid Network, the Bitcoin sidechain technically run by Blockstream. What followed was a negotiation between a company and an anonymous attacker that played out entirely in public, one Bitcoin transaction at a time, with real money changing hands based on how it ended.
An independent on-chain investigation by Bitquery Research pieced the whole sequence together from public blocks, and most of what follows can be checked by anyone willing to look at the raw data.
How you don’t need a stolen key to move $320 million
Liquid works by locking bitcoin with a federation of 15 companies, who issue an equivalent amount of L-BTC on their own faster, more private chain. Send the L-BTC back and the federation releases real bitcoin in what’s called a peg-out. Eleven of the fifteen members have to sign off on any payout.
What makes this incident unusual is that nothing about the security model failed in the traditional sense. No private key leaked. No server got breached. Eleven functionaries signed a peg-out request exactly as they were supposed to, following exactly the process that had processed thousands of legitimate transactions before it.
The problem was upstream of all of that. Somebody had found a way to create L-BTC that was never backed by real bitcoin in the first place, and then simply asked the federation, through entirely ordinary channels, to convert it into the real thing.
The setup took two days and left a paper trail
Investigation traced the attacking wallet back to two small peg-ins on September 4, funded by a pile of modest taproot coins, the kind of pattern you’d expect from someone who had been quietly accumulating sats rather than someone withdrawing fresh from an exchange.
Over the following two days, that wallet made 92 transactions on Liquid, cycling through different addresses. Most looked routine. But dozens of them planted an identical cryptographic range proof, the piece of math that shows a hidden amount isn’t negative, over and over across a 14 hour window. The likely purpose, according to the investigation, was to get that specific proof cached across the network’s nodes ahead of time.
Then, on the morning of September 6, three small test peg-outs went through cleanly. The dry run worked.
Four minutes that emptied most of a $300 million wallet
At 13:53 UTC, a single Liquid transaction created about 4,000 L-BTC with no bitcoin behind it. It stands out from every other transaction the wallet ever made because its range proof is a different length than all the rest, the one anomaly in an otherwise careful operation.
The fake L-BTC reached SideSwap, a service authorized to process peg-outs for Liquid users, within seven minutes. SideSwap requested payment from the federation the way it always does. Eleven signatures went through. At 14:28:56 UTC, the federation’s peg wallet sent out more than 4,000 BTC in one transaction, and within the hour its balance had fallen from roughly 4,207 BTC to just 197.
A conversation that only exists on the blockchain
The “we are whitehats” message arrived at 18:30 UTC that evening. Blockstream answered within the hour, first asking for an email address, then switching to PGP-signed messages that anyone can verify against its published key. Over the next day, the two sides traded nine messages this way, each one a real Bitcoin transaction, each one costing real fees.
The attacker’s terms were specific: fix the bug first, confirm every node is patched, and only then would the funds move. Blockstream confirmed its bridge nodes were patched on the morning of September 7, with a signature that checks out against its known key.
It wasn’t a clean back and forth. Twice, someone tried to hijack the exchange by impersonating Blockstream, once asking the attacker to redirect funds to the sender, once offering an alternate “clean” address. Neither message carried a genuine signature, which is exactly how you’d catch the forgery if you were paying attention. Not everyone bought the “white hat” framing either. Ledger’s CTO, Charles Guillemet, pointed out publicly that emptying a bridge first and asking questions later isn’t how responsible disclosure usually works.
A fix that existed four days too late
There’s a detail in Elements’ public code history, the open source software Liquid runs on, that’s hard to look past. A fix addressing exactly the kind of range proof caching issue this attack appears to exploit was merged into the main development branch on September 2, four days before the mint happened. No public release ever shipped it before the attack.
Blockstream has never officially named the specific bug, so this connection is circumstantial rather than confirmed, something the underlying investigation is careful to flag as well. But the timing is an uncomfortable coincidence at best.
What it cost while everyone waited
Liquid stopped producing new blocks altogether around 04:49 UTC on September 8, effectively freezing the chain while the negotiation continued. In the meantime, roughly 4,200 L-BTC still sitting in exchanges and wallets around the world was backed by just 197 real BTC, something like five cents of collateral for every dollar of exposure.
The line worth remembering
Bitcoin’s own ledger never had a bad day here. Every signature that moved money was real. What broke was a piece of code sitting on top of it, in a system that promises to hold bitcoin one for one but, for a few days in September, didn’t.
Relevant Links below
(thanks to bitquery)
Whitehat wallet (3,998.5 BTC): bc1ql4mfu6…yqjlte https://mempool.space/address/bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte
Liquid federation’s peg wallet: bc1qdlld6…suhwxxr https://mempool.space/address/bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr
Blockstream’s message address: bc1qn8mgsm…2mfqym — https://mempool.space/address/bc1qn8mgsmxx42j3fflqfkh0cqhdd6mj4h9q2mfqym
Federation’s 3,996 BTC peg-out, 14:28:56 UTC 6 Sep: 8db751a6…a7b140 https://mempool.space/tx/8db751a650ae2f12006b7e8c69a75e4df360e8afd6b9e05ae0b9fa6458a7b140
SideSwap forwarding 3,995.99999857 BTC to the customer, same block: 85d2ca15…645043 https://mempool.space/tx/85d2ca15bea33a592e73ed40c6a5da887feecf1e77f58ec7f580e00841645043
The 2.4975 BTC dry-run payout, 14:01 UTC: afff7f39…61443b https://mempool.space/tx/afff7f39a98ac31f2bd4c80b60332d5bc6a9335bb587e8a162f46e8b4261443b
Peg-in one, 1.0825 BTC, 4 Sep 03:11 UTC: f156fc7e…1c9a52 https://mempool.space/tx/f156fc7ee2ad863e9b4505f7a2dbb964ed5a7996fc6fe31e05fb87707f1c9a52
Peg-in two, 1.0660 BTC, 4 Sep 16:36 UTC: 4aa0ce4f…f2858e — https://mempool.space/tx/4aa0ce4f15b4613c0ed3115b029d88b0c2efdafa6b7d7089ff87fa2325f2858e
Liquid — peg-in one claimed, 4 Sep 19:47 UTC: 3628cc2c…72b389 https://liquid.network/tx/3628cc2ce266af2d99ff3f3e68fdab1506d898185acacaef2bf4e54a9772b389
Liquid — one of the 68 planted outputs, 6 Sep 12:21 UTC: 3d00b94c…6bd6e8 — https://liquid.network/tx/3d00b94c94633f4c29305bfbbe073f27c81f44c7a933e997b626e0b06f6bd6e8
Liquid — the mint, block 4,050,336, 13:53 UTC: f24a4b17…0a183f https://liquid.network/tx/f24a4b179b5cc7e88b25a763911f7cbdf2bf45d1d1b5ab611e94461cef0a183f
Liquid — SideSwap’s sweep, 14:00 UTC: c6ea588a…d72267 https://liquid.network/tx/c6ea588ac26f5838b6acbb2a444a33b325bbfeb39bf16dfe27b47215ffd72267
Liquid — the 3,996.018 BTC peg-out request, 14:06 UTC: ce4caece…e988f2 https://liquid.network/tx/ce4caece413cd9d444ce7ed9f54e5b328b3da5e4af301aff59a3571f76e988f2
Liquid — SideSwap’s 3.996 BTC fee peg-out, same block: 731f8fdf…e47d8a https://liquid.network/tx/731f8fdf0428c8ef5f2dc48d9347e458b101be2430f22ca6e5f376fd42e47d8a
Blockstream’s PGP key: 1176 542D … 6844 A2D6 https://blockstream.com/pgp.txt


