Satoshi Gazette
POLICY

Liquid Holders Kept Their Keys. The Federation Controlled the Exit.

SideSwap said users retained their keys. Its services still stopped. A 3,400 BTC return and a planned restart expose the difference between controlling a token and controlling its redemption.

An intact brass key rests on folded paper in front of a closed institutional doorway behind a red barrier.
IMAGE: Satoshi Gazette · AI-generated editorial illustration

On Sunday, SideSwap told its users that their assets remained under their own keys. In the same statement, it said swaps, peg-ins and peg-outs were paused until Liquid resumed. Both statements can be true. That is the distinction this incident makes impossible to ignore.

Holding the keys to L-BTC lets you authorize spending a token on Liquid. It does not let you spend the bitcoin held by the federation on the Bitcoin network, or restart the system that processes redemption. A secure wallet is not the same thing as an available exit.

Three boxes distinguish a user’s L-BTC wallet key, the federation and service processing a redemption, and BTC received in a Bitcoin wallet after a completed peg-out. Arrows show dependencies, not direct user control of federation funds.
A user can retain a token’s private key while the path to redeem that token is unavailable.Satoshi Gazette explanatory diagram · Data as of 2026-09-08Sources: 1 · 2
Method

Conceptual dependency diagram derived from SideSwap’s published pause statement and Blockstream’s description of peg-out authorization and federation signatures. It is not a complete protocol flow or a claim that all ways to sell L-BTC require a peg-out.

The withdrawal used the normal door

SideSwap says a customer sent 4,000 L-BTC to its peg-out service at 14:05 UTC on September 6. It processed the order with a valid authorization and burned the tokens. At about 14:28 UTC, the federation paid roughly 3,996 BTC to the customer’s Bitcoin address. SideSwap says Blockstream subsequently traced the tokens to an Elements software bug, and says neither its systems nor its authorization key was compromised. That is the operator’s account, not an exploit SG has independently reproduced.

The Bitcoin transaction confirms a large payment; it does not, by itself, establish why Liquid accepted the tokens. The customer output is approximately 3,996.018 BTC. The transaction also has other outputs, so the customer payment must not be confused with the net movement out of the tracked federation address.

Blockstream’s documentation describes a federation whose functionaries check the authorized destination and corresponding L-BTC burn before signing a peg-out using an 11-of-15 multisig. This is an additional trust boundary, not the same arrangement as holding spendable BTC in your own Bitcoin wallet. The incident’s exact software failure remains a separate technical question.

Liquid’s initial statement said no keys had been compromised and that bridge nodes were disabled. It also said other Liquid assets were unaffected by the security incident. That last assurance is not a claim that those assets could move normally while the network was paused.

Money returned. The obligations still need explaining.

A transaction confirmed at 16:09 UTC on September 7 paid exactly 3,400 BTC to the tracked federation address and approximately 598.50 BTC back to the actors’ address. When SG checked both mempool.space and Blockstream’s Bitcoin explorer on September 8, the addresses held about 3,597.47 BTC and 598.50 BTC respectively. , ,

Step chart showing the tracked federation address near 4,205 BTC before the September 6 peg-out, near 197.47 BTC that evening, and 3,597.47 BTC after the September 7 return.
The address recovered 3,400 BTC. These balances do not establish a system-wide backing ratio or the eventual loss borne by holders.Satoshi Gazette chart · public Bitcoin explorer data · Data as of 2026-09-08Sources: 1 · 2
Method

Replots every recorded confirmed-transaction balance from the September 7 preserved explorer series, including routine transfers, with a carried-forward opening balance at September 5 00:00 UTC. Block-header times, UTC. Ends September 7 18:00 UTC. One address only; no total reserve or liability audit. Net address change is not the customer payment.

Those are address balances, not a comprehensive reserve audit. They do not establish the total of all federation-controlled outputs, a synchronized outstanding L-BTC liability, or the eventual loss borne by individual holders. A system-wide backing percentage would require that reconciliation; these address figures cannot supply it.

The return is substantial. It is not evidence that the retained amount was an agreed bounty, nor that holders have been made whole. Those conclusions require terms or evidence that the transactions themselves do not contain.

At 04:00 Istanbul on September 8, Blockstream said updated software had been deployed and federation members were preparing a coordinated restart. Its statement did not give a completed restart time, a technical post-mortem, or terms explaining who bears the retained amount. A restart being prepared is not a restart completed.

What self-custody does—and does not—promise

There is a legitimate distinction in SideSwap’s defense. A wallet operator need not possess a customer’s private keys for the service to stop working. Liquid users can control their token keys while depending on federation software and signers to move between that token and BTC.

The lesson is not that private keys are useless. It is that the asset those keys control matters. A holder could protect an L-BTC key perfectly and still be unable to complete a redemption through a paused system. Describing that wallet as non-custodial does not remove the dependency.

The next useful disclosures are therefore practical: what failed, what version fixes it, when transfers and redemption actually resume, and how any unrecovered amount is accounted for. A software deployment answers only part of that list.

The federation can restore services. It cannot make the distinction disappear: controlling a token and controlling the bitcoin it represents are different things.

Reporting method: SG re-read the Liquid, SideSwap and Blockstream posts in a signed-in browser and queried public Bitcoin explorer APIs. SG did not operate a Liquid node, reproduce the bug, audit all federation reserves, test redemption or contact the companies. Statements about software and key compromise are attributed to their issuers. Status checked on 8 September 2026 at approximately 07:25 UTC.