Highlights
- SideSwap refunded roughly 4 BTC in fees it collected during Liquid Network's September 6 exploit, taking responsibility for its own risk-control gap.
- The exploit used a range-proof cache bug in Blockstream's Elements software to mint about 4,000 unbacked L-BTC, draining roughly 95% of Liquid's reserves in 23 minutes.
- The attacker returned 3,400 BTC but kept 598.5 BTC, worth about $47 million, as a self-declared “bounty” — a claim Blockstream has publicly doubted.
- SideSwap has paused its peg-in and peg-out services until Liquid's federation rolls out a new security architecture.
SideSwap Returns the Fees It Never Should Have Earned
Crypto exchange SideSwap said on September 10, 2026 that it has fully refunded roughly 4 BTC in fees it collected during the September 6 exploit of Blockstream's Liquid Network, a Bitcoin sidechain. The exploit stemmed from a bug in Liquid's underlying Elements software that let an unknown actor mint approximately 4,000 unbacked L-BTC and then swap most of it out for real Bitcoin through SideSwap's trading service. SideSwap said it takes full responsibility for its own risk-control shortfall in the episode and has paused its peg-in and peg-out services until the Liquid federation's new security architecture is ready.
How a Cache Bug Drained 95% of Liquid's Reserves
The underlying flaw was a range-proof verification cache bug in Elements that allowed the attacker to create unbacked L-BTC without the network's usual collateral checks catching the discrepancy.
According to CoinDesk reporting, the exploit drained roughly 95% of Liquid's Bitcoin reserves — an amount CoinDesk pegged at around $320 million — in a rapid, 23-minute window on September 6, with the bulk of the unbacked L-BTC converted into real BTC through SideSwap's peg-out service. SideSwap's own 0.1% service fee on that flow came to roughly 3.996 BTC, the approximately 4 BTC it has now returned to the federation. SideSwap's refund makes it the first counterparty in the episode to voluntarily return funds tied to the exploit, rather than negotiate a cut, as the on-chain attacker has done. The attacker, who has since engaged in on-chain negotiation over OP_RETURN messages framing the action as a “whitehat” disclosure, returned 3,400 BTC to Liquid but kept 598.5 BTC — worth roughly $47 million — as a self-assigned bounty, a claim Blockstream and outside observers have publicly doubted. Blockstream has attributed the root cause to a software bug in Elements rather than any compromise of private keys or federation signers.
A Narrow Piece of Accountability in a Murky Episode
SideSwap's move is a narrow but symbolically important piece of accountability inside an exploit that has otherwise been defined by an attacker effectively naming their own price for returning stolen funds. By refunding fees it earned unwittingly facilitating the exploit, SideSwap draws a line between platforms that processed the bad transactions in good faith and the party that engineered the bug in the first place — a distinction that matters for how exchanges and liquidity providers connected to Liquid are treated going forward.
Related: Alby Confirms Critical Bug in Old Lightning Hub Versions, Urges Upgrade
For the sidechain itself, the episode is a reminder that federated Bitcoin sidechains carry their own software risk distinct from Bitcoin's base layer; Liquid's reserves were drained not through a key compromise but through a verification logic flaw that let value be created without matching collateral, a category of bug that audits are generally designed to catch. With peg-in and peg-out services still paused pending a new security architecture, exchanges, market makers and OTC desks that route liquidity through Liquid are left waiting on Blockstream's fix before normal settlement resumes, an operational drag on a network used heavily for stablecoin and Bitcoin settlement between exchanges. The pause also revives a broader debate about whether sidechains that rely on a federation of signers, rather than Bitcoin's own proof-of-work security, can offer institutional users the same assurances as the base chain.
What Comes Next
The next milestone is Blockstream's rollout of Liquid's revamped security architecture, which the federation has said must be in place before SideSwap and other services resume peg-in and peg-out functionality — no firm date has been given. Separately, scrutiny is likely to continue around the attacker's retained 598.5 BTC, since Blockstream and other observers have already publicly rejected the framing of the theft as a legitimate whitehat rescue. Any law-enforcement or on-chain tracing effort aimed at the remaining funds, along with confirmation of exactly when Liquid's peg services reopen, are the two concrete developments worth watching next. How other exchanges connected to Liquid respond — whether any follow SideSwap in voluntarily returning fees — will also shape how the incident is remembered industry-wide.
FAQ
What caused the Liquid Network exploit?
A range-proof verification cache bug in Blockstream's Elements software let an unknown actor mint roughly 4,000 unbacked L-BTC without triggering the network's usual collateral checks, draining about 95% of Liquid's reserves on September 6, 2026.
How much is SideSwap refunding, and why?
SideSwap is returning roughly 4 BTC, the 0.1% fee it collected on the peg-out transactions used to convert the unbacked L-BTC into real Bitcoin, saying it takes full responsibility for its own risk-control shortfall.
Did the attacker return the stolen funds?
Partially. The attacker returned 3,400 BTC to the Liquid federation but kept 598.5 BTC, worth roughly $47 million, framing it as a self-declared “bounty” — a characterization Blockstream and outside observers have publicly doubted.
Is Liquid Network still operating normally?
No. SideSwap's peg-in and peg-out services remain paused until Blockstream's federation completes a new security architecture; no firm reopening date has been announced.
