Seems like the hackers have refunded 3,600 BTC. The rest might be a "negotiated" finder's fee. It will be interesting to follow in the days to come.
Someone printed $320 million of Bitcoin that didn't exist.
Nobody could tell it was fake. The system was built not to be able to.
On Saturday, the wallet backing Liquid's Bitcoin token went from roughly 4,200 BTC to 197.
A flaw in the software allowed previously verified cryptographic proofs to be reused, minting L-BTC that was backed by nothing. The attacker took 4,000 of those tokens to SideSwap and requested a peg-out, the ordinary process for converting the token back into real Bitcoin.
SideSwap processed it. Burned the tokens and instructed the federation to release around 3,996 BTC.
SideSwap wasn't breached. Its key wasn't compromised. In its own words, it could not distinguish those coins from ordinary L-BTC.
Nobody could.
Liquid uses confidential transactions, which hide amounts. That is the network's flagship feature, and it is the reason the counterfeit was undetectable.
You cannot audit a supply you have deliberately made unobservable.
No key compromised.
No system breached.
Contracts operated exactly as written.
Structures don't fail when someone breaks the rules. They fail when someone follows them.
Sep 7, 2026 · 5:13 PM UTC
56
