Read the past · Failures and decisions
When the Signatures Were Real but the Coins Were Not
On September 6, 2026, about 4,000 L-BTC appeared without a corresponding bitcoin deposit. Bitcoin's base layer did not break its rules: the fault was in an additional system and became a real loss through an automated peg-out.
EDITORIAL OVERVIEW · Prepared by the project editors from the sources listed below.
Value appeared inside Liquid without backing
Liquid is a federated Bitcoin sidechain built on Elements. A flaw involving the verification of confidential amounts allowed a party to create about 4,000 L-BTC without a corresponding BTC deposit.
The L-BTC was then sent to SideSwap for a peg-out. It was burned on Liquid, and the federation signed a transfer of approximately 3,996 BTC from Liquid's real reserve to the supplied Bitcoin address.
Why the keys could remain intact
According to the published statements, neither SideSwap's private keys nor its peg-out authorization key had been stolen. The signatures were valid and the system executed the operation it received.
The failure sat above signature verification. The automated process did not stop an order representing a huge share of all L-BTC and did not establish whether that amount of backing could plausibly exist.
Seventy rehearsals and one payout
SideSwap reported seventy similar transactions before the main event. In its account, they were rehearsals used to refine the construction that later created the unbacked L-BTC.
The operator acknowledged two operational failures: the authorization key was online, and large peg-outs were automated without sufficient volume, velocity, or origin checks. A software fault in Elements became an irreversible Bitcoin payment through the design of the exit process.
A partial return and a new phishing wave
Liquid temporarily stopped operations and exchanges paused L-BTC deposits and withdrawals. Reports as of September 11 said about 3,400 BTC had been returned, while roughly 598.5 BTC remained with the party responsible for the withdrawal.
Impersonators then posed as Blockstream and Liquid support. Blockstream warned that users did not need to enter a seed phrase, move funds to a recovery address, or install software received by email.
Why this was not a Bitcoin base-layer failure
L-BTC represents bitcoin inside a separate system with its own software, federation, keys, and bridge procedures. Users depend not only on Bitcoin's rules, but also on Elements, the federation, and the peg-in and peg-out mechanisms.
The incident produced a rare combination: keys were not stolen, signatures were valid, automation worked, and the outcome was still wrong. Security does not end with cryptography. Sometimes the decisive question is whether a system should automatically execute an operation that is technically accepted but economically impossible.
A cryptographically valid signature proves authorization. It does not prove that an operation makes economic sense.
Sources and verification
This article describes an incident in the federated Liquid sidechain, not a violation of Bitcoin's base-layer rules. Parts of the timeline rely on statements by involved organizations and may be updated.
Unless stated otherwise, the text, conclusions, structure and editorial arrangement were created by the project editors. Facts, quotations and source materials remain attributable to their authors and rights holders.
← Back to the rubric