SideSwap reopened bitcoin deposits into Liquid on September 11, but the route back remains closed: users can receive L-BTC, while redemption into BTC through the Liquid Federation is still disabled. The service’s own reopening notice warns that the reserve remains below the L-BTC supply. This is a partial recovery from the September 6 exploit, not a return to normal backing and withdrawals. [1]
The distinction follows an unusually revealing failure. An attacker created tokens without depositing the bitcoin meant to support them. SideSwap then treated those tokens as an ordinary redemption order, and its automated payout system sent real bitcoin out of the reserve. No stolen authorization key was needed. [2]
A verification shortcut accepted money that was never deposited
Liquid is a Bitcoin sidechain. Its L-BTC asset normally represents bitcoin deposited with a federation of operators. Moving BTC in is a peg-in; redeeming L-BTC for BTC is a peg-out. The exploit crossed that boundary using a balance that should not have existed.
Liquid hides transaction amounts and uses cryptographic proofs to check that hidden values are valid. Verifying those proofs costs computing time, so software saves successful results in a cache. According to Chainalysis, the attacker made different, invalid data point to an already approved result. Affected nodes reused the approval instead of checking the new data, allowing unbacked L-BTC to be accepted. [3]
The failure was in the infrastructure built around Bitcoin; it did not require breaking Bitcoin’s own transaction rules. Once the fraudulent Liquid balance could be redeemed, however, the consequences landed on the Bitcoin chain.
The payout system supplied the missing exit
SideSwap’s account describes a wallet initially funded with just 0.001 BTC and 70 rehearsal transactions before the minting transaction. A small redemption tested the exit before the much larger order. These details describe preparation for the September 6 attack, not a new attack in progress. [2]
SideSwap identifies two failures in its own operation: it kept the peg-out authorization key online and forwarded payouts automatically; it also lacked order-size, velocity and wallet-history checks. A request for roughly 4,000 L-BTC from a very young wallet therefore reached payout without human review. The service says the large payment initially failed for lack of funds, then went through after the Federation supplied bitcoin. An empty service wallet was a temporary obstacle, not a fraud control.

The diagram separates the two trust decisions: whether the tokens were valid, and whether such an extraordinary redemption should proceed. A correct signature could authorize the second step without making the first step economically legitimate.
Transfers work again; redemption is a separate promise
Liquid announced resumed transactions on September 10. SideSwap’s September 11 notice then reopened its peg-in service, explaining that this direction deposits BTC with the Federation instead of paying BTC out. Its peg-out service remains closed pending the security review. [1] [4]
That notice records 4,229 L-BTC in circulation against 3,627 BTC in reserve on September 11. These are dated figures from the operator’s notice, not live balances. It also cites Blockstream’s commitment to restore one-to-one coverage, without announcing when redemption will resume. The issuing ratio, the available reserve and the ability to redeem are three different facts.
Control of a wallet’s private keys does not resolve a reserve shortfall. Nor does a working swap market guarantee redemption at a fixed value. Anyone checking whether service has recovered needs the status of the specific operation they intend to use, not merely confirmation that blocks are being produced.
A recovery notice is not a request for your seed phrase
Liquid’s official warning reports fraudulent update sites and messages exploiting the incident. It says ordinary users do not need to take proactive recovery steps; its software-update instruction is for Liquid node operators. A message asking a wallet holder to send funds or reveal a seed phrase does not become legitimate because it mentions the real outage. [4]
Obtain status information through the official Liquid, Blockstream and SideSwap channels you navigate to yourself. If an unsolicited message instead pushes a wallet installer, the fake Exodus installer case shows why a familiar wallet name is insufficient proof of origin.
The central lesson of Liquid’s restart is specific: activity can resume before backing and redemption recover. Keep those milestones separate, and do not let an urgent “recovery” message turn a service incident into a second loss.
References
- SideSwap. Peg-ins are open again on SideSwap. September 11, 2026.
- SideSwap. Statement on the Liquid Network incident of 6 September 2026. September 9, 2026.
- Chainalysis. How The $320M Exploit of Liquid Network Went Down. September 9, 2026.
- Liquid Network. Transactions resumed, peg-outs disabled. September 10, 2026, 19:55 UTC.

