The supplied evidence does not name the affected bridge component, the scope of the patch, a software version, or a completion time. Those details are absent from the available material rather than confirmed as resolved, and the patch assertion should not be read as proof that the sidechain has reopened.
Blockstream is reported to have told a hacker that its bridge nodes are patched in an on-chain message, following a security incident on the Bitcoin sidechain Liquid Network that saw roughly 4,000 BTC leave the Liquid Federation wallet. The core patched-nodes claim remains unverified, and the available evidence establishes only the underlying incident and Blockstream’s stated intent to make contact on-chain.
What to Know
- Blockstream says its bridge nodes are patched.
- The claim appears in an on-chain message directed at a hacker.
Blockstream says bridge nodes are patched
According to unconfirmed reports, Blockstream says that bridge nodes are patched and has conveyed that status in an on-chain message addressed to a hacker. No fetched primary message, patch release, or official announcement independently establishes this specific update. For related coverage, see Blockstream Researchers Propose SHRINCS, a Quantum-Resistant Bitcoin Signature Scheme.
The supplied evidence does not name the affected bridge component, the scope of the patch, a software version, or a completion time. Those details are absent from the available material rather than confirmed as resolved, and the patch assertion should not be read as proof that the sidechain has reopened. For related coverage, see AINext Awards & Conference Dubai 2026: Where AI Leaders, Innovators and Decision-Makers Shape the Future of Artificial Intelligence.
What is documented is the incident that preceded any such message. In a September 6, 2026 statement, Liquid Network reported that purported white-hat hackers withdrew approximately 4,000 BTC, valued by the network at around US$320 million, from the Liquid Federation wallet.
Reported Liquid Federation withdrawal
~4,000 BTC
Liquid Network said the withdrawal used the SideSwap Peg-out Authorization Key, and stated that this key and the network’s other keys were not compromised. It also said bridge nodes were temporarily disabled, preventing submission of new transactions and effectively pausing the sidechain until resolution. Our earlier coverage detailed the purported white-hat withdrawal as first disclosed.
The on-chain message to the hacker
The patch status was communicated in an on-chain message directed at the hacker, as described by the headline. Liquid Network’s own statement said the Blockstream team was working on contacting the parties on-chain with a signed message, which is a statement of intended contact rather than confirmation of the later patched-nodes message.
We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.
What we know so far is that the funds…
— Liquid Network 🌊 (@Liquid_BTC) September 6, 2026
Source: @Liquid_BTC on X
No message text, transaction reference, timestamp, or recipient address is available in the supplied material. Reports that the message carries a verified PGP signature attributable to Blockstream remain unconfirmed, with no signed payload, key fingerprint, or cryptographic verification established. The available evidence does not indicate any negotiation, bounty, or reply.
What remains unconfirmed about the bridge nodes
The available material does not establish the affected bridge, the patch’s scope, or any independent verification, and it does not confirm that funds have been returned or that normal bridge operations have resumed. These gaps reflect what is absent from the supplied evidence, not necessarily what has or has not been disclosed publicly elsewhere.
Liquid Network said exchanges had paused or would pause LBTC deposits and withdrawals, and described other Liquid assets, including USDT, DePix and real-world assets, as unaffected by the incident. In Bloomberg reporting published by The Straits Times, FailSafe chief executive Aneirin Flynn offered a preliminary assessment that a bug allowed L-BTC minting and exposed weaknesses in Liquid’s validation and backing model; Flynn said the incident, with reserves drained and the network paused, revealed a critical weakness in that model.
The Liquid episode arrives alongside other recent Bitcoin bridging strains, including the fallout after Boltz halted its non-custodial bridge and Blockstream’s response through its Swaps beta launch. A patch assertion or a request to return funds should not be treated as completed recovery until on-chain evidence and an official reopening statement confirm it.
Additional source references: source document 1.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.