Close to 4,000 BTC has been drained from the peg that backs Blockstream's Liquid sidechain, according to a report circulated on September 6, 2026, with the people responsible describing themselves as "whitehats." At Bitcoin's price of roughly $79,825 as of September 6, 2026, that figure works out to more than $300 million in BTC, based on the reported coin count and current market price (our own calculation, not a figure from the source).
The claim that the actors are whitehats, security researchers who exploit a flaw to prove it exists rather than to steal, does not change the mechanics of what happened. A large slice of the Bitcoin that anchors Liquid moved out of the federation's control. Whether those coins come back depends entirely on the people who now hold them.
The peg is the whole ballgame for a sidechain
Liquid is a Bitcoin sidechain. Its central promise is that every Liquid Bitcoin (L-BTC) circulating on the sidechain is backed one-to-one by real BTC locked on the main Bitcoin chain. That lock is the "peg." When you move BTC onto Liquid, it gets deposited into an address controlled by a federation of functionaries, and you receive L-BTC in return. To exit, you burn L-BTC and the federation signs a transaction releasing your BTC.
That design means the backing reserve is not secured by a single private key or by Bitcoin's own proof-of-work. It is secured by a multi-signature setup run by the federation members. If enough of those signers, or the software coordinating them, can be compromised or coerced, the reserve is exposed. A drain of nearly 4,000 BTC points at exactly that kind of failure in the peg's custody layer, not at a break in Bitcoin's base protocol.
"Whitehat" is a claim, not a guarantee
Labeling a drain as whitehat activity has become a familiar move after large exploits. The actors signal that they intend to return funds, often in exchange for a bounty or an agreement that no legal action follows. Sometimes that plays out. Sometimes the "whitehat" framing is cover that buys time while funds are moved and laundered.
For anyone holding L-BTC right now, the label matters less than the reserve math. If the coins are returned in full, the peg can be made whole and L-BTC holders are unaffected. If they are not, the backing behind L-BTC is short by the drained amount, and holders face a claim on a reserve that no longer fully exists. Until the funds are back in federation control, that gap is real regardless of what the attackers call themselves.
Custody risk does not disappear on a sidechain
The lesson here is the same one that shows up after every reserve breach: when you hold a claim on assets rather than the assets themselves, you inherit the security of whoever holds the real thing. L-BTC is a claim on BTC held by the Liquid federation. Wrapped tokens, exchange balances, and card-linked custodial wallets carry the same structure in different clothing. The user holds an IOU; someone else holds the coins and the keys.
This is why self-custody options keep coming up in the wake of custody failures. Spending directly from a wallet you control removes the federation, the bridge, and the counterparty from the equation. It does not remove all risk, phishing and device compromise still exist, but it eliminates the specific failure mode where someone else's signers lose your funds. For people who use crypto payment cards, the same question applies: is the balance behind the card sitting in your wallet, or in a custodian's reserve that could be drained without your involvement?
None of this makes bridges or sidechains inherently unusable. Liquid has run for years and serves real use cases in faster settlement and confidential transactions. But a peg concentrates value behind a defined set of signers, and that concentration is a target. A drain of nearly 4,000 BTC is a direct demonstration of the size of that target.
The open questions
Several facts are not yet settled from the initial report. The exact mechanism of the drain, whether it exploited the federation's multisig, a software bug, or a coordination flaw, has not been detailed in the source. The identities and true intentions of the "whitehats" are unconfirmed. And there is no confirmed timeline for whether the funds will be returned. Treat all three as open until Blockstream or the actors publish specifics.
What is clear is the shape of the event: a large, custody-layer drain on one of Bitcoin's longest-running sidechains, framed by the perpetrators as a security demonstration. The dollar value moves with Bitcoin's price, but the structural point holds at any price. A sidechain peg is a promise backed by signers, and this week that promise was tested in the most direct way possible.
Overview
Nearly 4,000 BTC, worth over $300 million at a BTC price of about $79,825 as of September 6, 2026, was drained from Blockstream's Liquid sidechain peg by actors claiming to be whitehats. The peg backs L-BTC one-to-one with real Bitcoin held under a federation multisig, so the drain is a custody-layer failure, not a break in Bitcoin itself. Whether L-BTC holders are affected depends on if the funds are returned. The mechanism, the actors' true intent, and the return timeline all remain unconfirmed.



