September 14, 2026
EXECUTIVE SUMMARY
On 6 September 2026, the Liquid Network suffered a validation failure that allowed unbacked L-BTC to be created and exchanged for Bitcoin held by the federation. Blockstream's incident status said approximately 4,000 BTC was withdrawn through SideSwap's Peg-out Authorization Key path while the key itself was not compromised. Public reporting later described a software validation and caching flaw rather than a signer compromise.
SentinelTX reconstructed the Bitcoin mainnet leg. It confirmed 3,996.01834922 BTC leaving the federation peg wallet, passing through one relay address, and consolidating as 3,995.99999857 BTC in the attacker wallet. On 7 September, that wallet returned 3,400 BTC. At the investigation cutoff of 12 September 2026 at 23:36 UTC, 598.50136349 BTC remained in the same attacker address.
The most important result is a null result: five-hop outbound tracing found no confirmed exchange deposit, mixer exposure, CoinJoin pattern, bridge route, or other cash-out leg for the remaining balance. The retained Bitcoin was visible and dormant rather than dispersed. This leaves a live recovery and enforcement window, but it does not identify the operator.
INCIDENT MECHANICS AND EVIDENCE BOUNDARY
Liquid's normal peg is intended to keep L-BTC backed one-for-one by Bitcoin held by the federation. The incident broke that backing invariant. The exploit did not require movement of federation signing keys; instead, an invalid asset state was accepted by the peg-out path and released real BTC.
The diagram below shows only the Bitcoin mainnet path independently anchored by SentinelTX. Liquid-side issuance details, the precise vulnerable code path, and the disclosure timeline remain dependent on public technical reporting until a complete postmortem is published.

CONFIRMED TRANSACTION ANCHORS
The first anchor is transaction 8db751a650ae2f12006b7e8c69a75e4df360e8afd6b9e05ae0b9fa6458a7b140. It moved 3,996.01834922 BTC from federation peg wallet bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr to relay address bc1qgslsydz56d0ed6827hdemfmk5w2f6ldyc6wt7p.
Transaction 85d2ca15bea33a592e73ed40c6a5da887feecf1e77f58ec7f580e00841645043 then moved 3,995.99999857 BTC from that relay to attacker wallet bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte. On 7 September, transaction a6d697a25266ce3c78774fd1d75f896b7af522ada209b0f6228ea497bc49a46d returned 3,400 BTC to the federation peg wallet.
The evidence ledger below separates confirmed transfers from one unresolved accounting gap. The attacker wallet's observed balance exceeds the simple anchored inflow-minus-return calculation by approximately 1.96304 BTC. That difference may reflect additional inflows, but it must not be assigned to the exploit without transaction-level reconciliation.

CURRENT STATUS OF THE REMAINING 598.5 BTC
SentinelTX traced outbound activity from the attacker wallet across a 60-day window and up to five hops. The only material outbound transaction was the 3,400 BTC return. The remaining 598.50136349 BTC showed no confirmed split, peel chain, CoinJoin, mixer deposit, bridge transfer, or centralized-exchange deposit.
The attacker address and federation peg address were both unlabeled in SentinelTX's internal entity database. Calling the latter the federation wallet relies on public incident materials and transaction context, not an independent database label. This distinction matters because address behavior can confirm a flow without proving real-world ownership.

WHAT THE CHAIN PROVES — AND WHAT IT DOES NOT
The chain proves the withdrawal path, the relay hop, the final consolidation address, the 3,400 BTC return, and the retained balance at the stated cutoff. It also shows that the remaining balance had not entered a known off-ramp or obfuscation service during the observed window.
The chain does not prove that the operator was a good-faith security researcher. Public messages reportedly used white-hat language, but retaining user backing as leverage after partial return fits a coercive, self-appointed bounty pattern. That is an analytical classification, not a legal finding or identity attribution.
Likewise, public claims that a security warning was ignored remain disputed. Bitcoin Red Team co-lead Calle said the parties had agreed to an embargo and accused Blockstream of publishing an incomplete account early. Blockstream-linked voices denied that warnings were ignored. SentinelTX did not independently obtain a complete disclosure record, acknowledgement timestamps, severity triage, patch history, or embargo terms. Until those artifacts are published, the ignored-warning narrative should be treated as an allegation.
INVESTIGATOR PRIORITIES
The clearest intervention opportunity is the first movement from bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte. Exchanges and major service providers can prepare alerts against the confirmed address before a deposit appears. No freeze target exists yet because no exchange deposit leg was observed.
The strongest attribution lead on the public chain is the relay address bc1qgslsydz56d0ed6827hdemfmk5w2f6ldyc6wt7p and its pre-incident history, co-spend relationships, and counterparties. Two shared outputs in the initial federation transaction—bc1qk3cvk5599nydy8zwavlxaduke54pgf4vl0ckru and bc1qkxwva32eh7mgezq5kladncd3n5wtcjmslh98my—also warrant service-attribution review.
The unresolved 1.96304 BTC balance gap should be reconciled before the accounting chain is called complete. Off-chain evidence is equally important: SideSwap request records, account details, IP logs, authentication traces, and federation communications should be preserved.

CONCLUSION
The Liquid exploit is unusual not because the proceeds disappeared quickly, but because most were returned and the remainder stayed visible. At the cutoff, 598.50136349 BTC remained concentrated in one public address with no confirmed laundering or cash-out leg. That creates leverage for recovery negotiations, real-time monitoring, and coordinated exchange response.
The restraint visible on-chain should not be mistaken for authorization or attribution. The defensible conclusion is narrower: a software validation failure released federation BTC; a single attacker cluster returned 3,400 BTC; the remaining balance was dormant; and the next transaction may be the first actionable off-ramp signal.
SOURCES
Blockstream Service Status, "Liquid Security Incident," 7 September 2026: https://status.blockstream.com/
Chainalysis, "How The $320M Exploit of Liquid Network Went Down," 9 September 2026: https://www.chainalysis.com/blog/320m-exploit-liquid-network/
SideSwap, "Statement on the Liquid Network incident of 6 September 2026": https://testnet.sideswap.io/news/statement-on-the-liquid-network-incident-of-6-september-2026/
The Block, "Return the bitcoin: Blockstream refuses ransom demand for remaining 600 BTC from Liquid exploit," 11 September 2026: https://www.theblock.co/news/ecosystems/2026-09-11-return-the-bitcoin-blockstream-refuses-ransom-demand-for-remaining-600-btc-from-liquid-exploit-414247
SentinelTX on-chain investigation completed 13 September 2026. All balances and endpoint observations are time-bound. Wallet association does not by itself identify a person or organization.
4 reads