The Liquid Hack: Do Drivechains Fix This?

Updated: 3 days ago
Liquid Network Hack Explained: Federated Sidechains vs Drivechains (BIP 300)
On September 6, 2026, someone drained about 4,000 BTC from Blockstream's Liquid Network. That is roughly $320 million, the largest crypto theft of the year.
Bitcoin itself was fine. The bug was not in Bitcoin. It was in a sidechain built on top of Bitcoin.
So the obvious question: would a drivechain have stopped this?
The honest answer is partly. A drivechain would not have prevented the bug. The same code flaw would have fired on a drivechain too. What a drivechain changes is what happens after the bug — who holds the coins, how fast an attacker can leave, and how many people get to say no.
This article walks through exactly what happened, then replays the same attack on a drivechain, step by step.
Part 1: What Happened to Liquid
The exploit
Liquid is a Bitcoin sidechain launched by Blockstream in 2018. Users lock real BTC with a group of signers, and the network issues them L-BTC on the sidechain in return. One L-BTC is supposed to equal one real BTC, always.
On September 6, 2026, at 15:53:10 UTC, that broke.
Blockstream's incident report points to a flaw in how Liquid nodes cached range proof verifications. The flaw lived in Elements — the open-source software Liquid runs on.
The attacker used it to mint roughly 4,000 L-BTC that had no bitcoin backing them at all. Then they cashed the fake coins out for real BTC.
The money left in minutes
The cash-out ran through SideSwap, a Liquid federation member that holds one of the keys authorizing withdrawals off the sidechain.
Because the validation failure happened before the withdrawal request was even submitted, SideSwap's node and the federation treated the transaction as legitimate. In SideSwap's own account, it received 4,000 L-BTC and the federation paid out roughly 23 minutes later.
The reserve backing every L-BTC in circulation fell from about 4,205 BTC to 197 BTC.
At Bitcoin's price that day of around $79,750, the haul was worth approximately $320 million.
The shutdown
Blockstream reacted fast. Within hours it disabled the network's bridge nodes and paused the sidechain entirely. Exchanges suspended L-BTC deposits and withdrawals.
Block production stopped. Nobody could transact on Liquid at all.
Hold that thought. We come back to it.
The on-chain negotiation
Hours after the drain, the attacker left a message on the Bitcoin mainchain. Using the OP_RETURN field of a transaction, they identified themselves as white hats and invited Blockstream to make contact on chain.
They then negotiated with Blockstream through encrypted on-chain messaging, promising to return funds once every node had patched the bug they used.
Blockstream patched the bridge nodes on September 7 at 01:09 UTC.
85% came back
On September 7 at 16:09:25 UTC, the attacker returned 3,400 BTC — around $272 million — to the Liquid federation's wallet.
About 598.5 BTC is still gone. That is roughly $47 million, or 15% of the total.
There was no bug bounty program, no contract, and no agreement beforehand. The retained 15% appears to be a self-declared finder's fee. Whether that is a bounty or a theft depends on who you ask.
Nobody has verified the white hat claim.
Where it stands now
On September 9, Blockstream shipped an emergency release, Elements v23.3.4, which hardens the cache keys used for range proofs. Functionary nodes began upgrading immediately.
The restart is planned in three phases: resume block production with peg operations still frozen, replay verified transactions, then reopen the pegs once 1:1 backing is confirmed.
Bitcoin's price moved about 1%. The market read this as a sidechain failure, not a Bitcoin failure. That read is correct.
Part 2: Why the Peg Is the Real Story
Two separate things went wrong. It matters a lot which one you focus on.
Failure one was a software bug. Cached proof verification accepted something it should have rejected. Bugs like this happen in every codebase, in every project, forever.
Failure two was the peg design. Because of failure one, 4,000 BTC could walk out of a shared reserve in under half an hour, on the authorization of a single federation member's key.
You cannot engineer away failure one. Nobody can.
Failure two is a design choice.
What a federated sidechain actually is
Elements uses a model Blockstream calls Strong Federations. Instead of proof of work, a group of mutually distrusting participants called functionaries runs the chain. Members who move funds between Bitcoin and the sidechain are called watchmen.

On Liquid, that means 15 functionaries holding hardware-protected keys in an 11-of-15 multisig.
This is a real trust assumption, and Blockstream has never hidden it. If you hold L-BTC, your bitcoin is in a vault controlled by a known group of companies. You are trusting them to be honest, competent, and secure.
The core multisig was never compromised in this hack. The functionaries did their job. They just did it on a transaction the software told them was valid.
That is the uncomfortable part. The trusted parties can be perfectly trustworthy and you can still lose the money, because they are only as good as the code telling them what is real.
Part 3: What a Drivechain Does Instead
A drivechain is a sidechain where no group of people holds the coins.
Drivechains come from two Bitcoin Improvement Proposals written by Paul Sztorc: BIP 300, which defines the escrow, and BIP 301, which defines blind merged mining. Both are live today on eCash (ECX), the Bitcoin hard fork that activated them from day one.
Here is the mechanism, in plain terms.
Coins sit in a hashrate escrow

When you deposit BTC to a drivechain, it goes into a special escrow output on the main chain. No key controls it. No federation signs for it. There is nobody to hack, bribe, or subpoena.
Withdrawals are slow on purpose
Getting coins out is deliberately, almost absurdly slow.
Individual withdrawal requests are batched into a single "bundle." A miner proposes that bundle's hash. Then miners vote on it, one block at a time, over months.
Per the BIP 300 spec, a bundle needs 13,150 approvals within 26,300 blocks — roughly three to six months. The approval count can go up or down by one each block, so a bundle that starts winning can start losing. If a bundle mathematically cannot reach the threshold, it is dropped immediately.
Bundles are processed in order, first come first served. LayerTwo Labs sums it up: deposit instantly, withdraw in three to six months.
The blast radius shrinks
Each drivechain is its own escrow, in its own numbered slot. A total failure on one drivechain drains that drivechain. It cannot touch the main chain, and it cannot touch the other drivechains.
Part 4: Replaying the Hack on a Drivechain
Now the actual question. Same bug, same attacker, drivechain instead of federation.
Step 1 — The bug still fires. Nothing about BIP 300 inspects sidechain code. A range proof caching flaw would work exactly the same way.
Step 2 — Fake coins still get minted. The attacker still creates thousands of unbacked sidechain BTC. On the sidechain's own ledger, this looks fine.
Step 3 — Here is where it diverges. To convert those fake coins into real BTC, the attacker has to withdraw. That means getting a bundle into the main chain escrow and holding miner approval for months.
Step 4 — Everyone watches it happen. The bundle is public the entire time. Sidechain users can compare it against the real ledger. Anyone can see that the withdrawal is larger than the deposits justify. Miners can flip to rejecting it at any block.
Step 5 — There is no off switch. Nobody can pause a drivechain. That cuts both ways, and it is worth being honest about which way it cuts here.
So: the attack that took 23 minutes on Liquid becomes a three-to-six-month public negotiation with everyone in the world watching.
That is not a security guarantee. It is a time guarantee. Time is what a federation did not have on September 6.

The part that cuts the other way
Blockstream's ability to freeze Liquid within hours contained the damage. A drivechain has no such button.
If a bug mints fake coins on a drivechain and nobody notices, and miners approve the bundle, the coins leave and there is no pause, no rollback, and no support desk. Detection is the whole defense. On Liquid, a company caught it and pulled the plug.
Both models depend on someone paying attention. They differ in how long you have to notice and who has to agree.
Part 5: The Open Question About Drivechains
Drivechains trade one trust assumption for another. They do not remove trust entirely, and the project has never claimed they do.
The tradeoff is straightforward: instead of trusting 15 named companies, you are trusting that a majority of Bitcoin's hashpower will not vote to approve a withdrawal the drivechain's own rules would forbid. This is a live debate among serious people, and it is worth understanding both sides before you form a view.
The criticism
Bitcoin developer Peter Todd argues the case against. BIP 300 has no fraud proofs, so miners decide whether escrowed coins get spent regardless of what the drivechain intended. He characterizes it as transactions signed by hashpower over time — a 13,150-of-26,300 multisig where each block is a signature. His broader worry is that giving miners this power creates a new incentive to attack, and pushes hashrate toward the largest pools.
The BIP does not hide the exposure. It notes that drivechains are vulnerable to one catastrophe per 13,150 blocks — the invalid withdrawal.
The response
Paul Sztorc has answered this for the better part of a decade. His core argument, laid out on the bitcoin-dev mailing list, starts from an observation about the status quo: a 51% miner group is already maximally involved in Bitcoin, since it can create most messages and filter any message. Drivechains do not hand miners a new capability so much as give them a new place to use one they already have.
He also points to revealed behavior. Miners today could coordinate to double-spend exchange deposits and steal from exchanges. They do not, because the fee revenue from behaving is worth more than one-time theft.
Then there is the clock. In his 2023 debate with Todd, Sztorc's position was that a theft requires three to six months of continuous, visible lying, which he considers too impractical to be worth attempting. Todd's reply was blunt: nothing in drivechains actually stops it. Both are on the record and readers can judge for themselves.
Two mechanical details matter here. Sztorc has noted that the three-month figure assumes 100% of hashrate cooperating — at 51%, a bundle takes the full six months or longer. And approvals can be withdrawn: honest miners who spot something wrong can vote a bundle back down, one block at a time, which functions as an alarm the whole network can see.
What neither side can settle yet
Here is the honest state of play. Drivechains have not been tested at scale. They went live on eCash in August 2026. No large escrow has completed a full withdrawal cycle. The miner-theft scenario has never been attempted, and the deterrent has never been proven.
But that argument cuts both ways, and this is the part worth sitting with. Liquid's federated model was battle-tested. It ran in production since 2018 and processed billions in volume. Eight years of real-world operation did not prevent September 6.
Being tested is not the same as being safe. It just means the failure mode is known.
So the real comparison is not safe versus unsafe. It is:
Federated sidechain (Liquid) | Drivechain (BIP 300) | |
Who controls funds | ~15 known functionaries, 11-of-15 multisig | Miner majority, voting per block |
Time to move funds out | Minutes | ~3–6 months |
Attack visible in advance | No | Yes, for months |
Can be paused | Yes | No |
Failure blast radius | Whole network at once | One drivechain slot |
Who you trust | Named companies | Anonymous hashpower |
Pick your poison honestly. A federation is fast, accountable, and has a single point of failure. A drivechain is slow, leaderless, and requires you to believe miners will not spend months publicly stealing in front of everyone.
Part 6: The Same Code Is Running on Both Models Right Now
Here is the detail almost nobody has noticed.
The bug was in Elements — Blockstream's open-source, sidechain-capable blockchain platform, launched in 2015. Liquid is one chain built on it. Elements itself is a codebase, not a network.
And Elements has already been ported to a drivechain.
Developers took Blockstream's Elements — which shipped OP_CAT and exotic signature schemes years ago that Blockstream never deployed anywhere — added CTV, and turned it into a drivechain. It is known as Elements Plus. Paul Sztorc described it as a neatly completable project, precisely because you are building on Blockstream's own work.

As of September 9, 2026, Elements Plus is live and merge-mining in slot 24 on the ECX alphanet.
Same codebase. Same class of bug possible. One chain is paused with $47 million missing and a federation negotiating with an anonymous attacker. The other is producing blocks.
The difference is not the code quality. The difference is who has to sign to get your bitcoin out.
What This Means for eCash (ECX)
eCash is a Bitcoin hard fork from Paul Sztorc and LayerTwo Labs. It activates BIP 300 and BIP 301 from the first block, so drivechains work on day one instead of waiting on a Bitcoin soft fork that never came.
Bitcoin is untouched. Every BTC holder receives ECX 1:1 at the snapshot. The base layer stays boringly simple, and every experiment lives on its own drivechain in its own slot.
Permanent mainnet is targeted for October 31, 2026 — the 18th anniversary of the Bitcoin whitepaper.
The Liquid hack does not prove drivechains are safe. It proves something narrower and more useful: when a sidechain's code fails, the peg design decides how bad it gets.
Frequently Asked Questions
Was Bitcoin hacked in the Liquid Network hack? No. Bitcoin's base layer and proof-of-work consensus were never affected. The exploit hit Liquid, a separate sidechain run by Blockstream, through a bug in the Elements software Liquid uses. Bitcoin's price moved about 1% on the news.
How much was stolen from Liquid Network? Roughly 4,000 BTC, worth about $320 million on September 6, 2026. The attacker returned 3,400 BTC on September 7. Approximately 598.5 BTC — about $47 million, or 15% — has not been returned.
What is a federated sidechain? A federated sidechain is a blockchain pegged to Bitcoin, where a fixed group of known parties holds the real BTC and issues a sidechain token against it. Liquid uses 15 functionaries in an 11-of-15 multisig. Users trust that group not to fail, collude, or be compromised.
What is a drivechain? A drivechain is a Bitcoin sidechain where no person or group holds the deposited coins. BTC sits in a hashrate escrow on the main chain, and withdrawals require miners to approve a batched request across 13,150 blocks within a 26,300-block window — roughly three to six months. Drivechains are defined by BIP 300 and BIP 301 and are live on eCash (ECX).
Could the Liquid hack happen on a drivechain? The bug could, yes. A drivechain does not review sidechain code, so the same flaw would mint the same unbacked coins. What changes is the exit: instead of cashing out in minutes through one federation member, the attacker would need a withdrawal bundle approved by miners over three to six months, in full public view, with the ability for miners to reverse their votes at any block.
Can miners steal from a drivechain? Yes, in theory. BIP 300 has no fraud proofs, so a hashrate majority can approve a withdrawal that the drivechain's own rules would not allow. The BIP acknowledges this exposure directly. The defense is that the theft would be slow, public, and visible for months before any coins moved.
Is Liquid back online? Not fully as of September 9, 2026. Blockstream released Elements v23.3.4 and functionaries began upgrading. The restart plan runs in three phases: resume block production with pegs frozen, replay verified transactions, then reopen pegs once 1:1 backing is confirmed.
Were other Liquid assets affected? Other Liquid-issued assets, including USDT, Depix, and tokenized real-world assets, were not affected by the exploit. The damage was contained to L-BTC and its backing reserve.
Sources: Liquid Network incident report · TRM Labs · Halborn · BIP 300 specification · Peter Todd, Drivechains: A Detailed Analysis · Elements Project · LayerTwo Labs · drivechain.info
Last updated: September 9, 2026. This story is developing — Liquid's restart and the outstanding 598.5 BTC are unresolved.



Comments