On 6 September, a customer submitted 4,000 Liquid Bitcoin, or LBTC, to SideSwap’s withdrawal service. Twenty-three minutes later, Liquid’s federation paid about 3,996 bitcoin, worth roughly $320 million at the time. SideSwap later said Blockstream established that the tokens had been created through a bug in Elements, the software behind the sidechain. They were unbacked, and valid signatures still released real BTC without proving those tokens were entitled to it.

That is the security implication of selling a federated, BTC-backed token as if it inherited Bitcoin’s independence from middlemen. Bitcoin’s whitepaper set out electronic cash that would pass from one party to another without a trusted intermediary. Raising capacity on a separate federation does not raise Bitcoin’s base-layer capacity. The open question is whether payment capacity can grow at the network level without adding reserve managers.
Liquid said no keys were stolen. Bitcoin mining was not compromised, and ordinary self-custody bitcoin wallets were not the target. The failure sat in the claim being redeemed, not in the Bitcoin keys that paid it out.
Unbacked tokens were exchanged for real bitcoin
At 14:05 UTC on 6 September, the 4,000 LBTC entered SideSwap. LBTC is intended to represent bitcoin held in reserve at a one-to-one ratio. SideSwap burned the tokens on Liquid with valid withdrawal authorisation. At 14:28 UTC, the federation paid approximately 3,996 BTC to the customer’s Bitcoin address. SideSwap said neither its systems nor its withdrawal authorisation key had been compromised.
The Bitcoin transaction confirms the payout. Protos reported that it carried the required 11-of-15 federation signatures. Those signatures authorised the spend. They did not establish that the tokens being redeemed had legitimate backing.
Bridge nodes were disabled and new submissions stopped, while SideSwap paused its services. Bitcoin developer Antoine Poinsot reported that nodes operated by Mempool and Blockstream disagreed over the Liquid block containing the withdrawal. By then, the reserve payout had already occurred on Bitcoin.
On 7 September, a return transaction sent 3,400 BTC to the federation. Another output of approximately 598.5 BTC went to an address linked to the attacker. That figure is not a final accounting of losses.
Adding middlemen does not raise Bitcoin's base-layer capacity
Liquid offers faster settlement, confidential transaction amounts and token issuance. Users can hold their own LBTC keys and run validating nodes. Its technical documentation describes a separate sidechain operated by a selected federation, with different rules and security arrangements from Bitcoin.
The bitcoin backing LBTC sits in federation-controlled addresses. Under Liquid’s redemption rules, ordinary holders cannot independently withdraw from that reserve. They need an authorised participant or a swap service to complete the process. Holding an LBTC private key gives control over the token. Access to the underlying bitcoin still depends on the reserve and the federation’s withdrawal machinery.
Bitcoin checks whether a reserve transaction satisfies its spending conditions. It does not verify Liquid’s assessment of the tokens presented for redemption. More LBTC activity can look like more bitcoin payment capacity. It is capacity for BTC-denominated activity on a federated sidechain. It does not increase the number of transactions Bitcoin itself can include.
Self-custodial Lightning channels are a different design. They are funded with bitcoin and enforced through Bitcoin spend rules with unilateral exit, rather than reserve-backed tokens.
Liquidity has to be committed to channels. Sending needs outgoing balance. Receiving needs incoming capacity. A wallet balance alone does not ensure a usable route with enough liquidity. Opening and closing channels uses Bitcoin transactions and fees. Existing channels can support many off-chain payments, but on-chain capacity and fee constraints remain for funding and exits. If a peer is offline or a force close begins, funds can stay unavailable while on-chain settlement and timelocks complete. Monitoring and backups remain responsibilities that software and services can help handle.
Custodial Lightning wallets hide that complexity by letting an operator control funds, which adds middleman risk. Not every Lightning wallet is custodial, and routing nodes are not necessarily custodians. Those dependencies mean Lightning is not a complete answer to unrestricted self-custodial payment scaling. It enables off-chain payments. It does not remove those tradeoffs.
Raising payment capacity without selected operators
Bitcoin's base chain remains constrained even when activity moves elsewhere. Under current consensus it aims for a new block about every ten minutes, and each block has limited space (Bitcoin Developer Guide). Extra demand does not enlarge that slot. Lightning and Liquid can shift some payments off the chain or spread several of them across fewer on-chain events. They cannot change those rules. Relieving pressure is not the same as removing the limit.
When a Lightning channel has to open or close, liquidity is still locked or released on Bitcoin, and a dispute still settles there. Those steps inherit the same interval and the same scarce block space.
Bitcoin kept that limited design on purpose. The same peer-to-peer money principles can sit on a base network built to carry ordinary payments without a reserve committee and without assembling a route first. Kaspa is a separate proof-of-work layer one that raises payment capacity while anyone can still mine and independently check the rules without joining a federation. Open mining and independent validation keep decentralisation and security in the protocol rather than handing consensus to selected operators. Senders move KAS, a native currency of that distinct network rather than a redeemable bitcoin claim. It is not a Bitcoin layer two.
Bitcoin miners also find blocks at the same time. Blocks that fall outside the winning chain are not part of Bitcoin's final ledger, though the transactions in them can still be mined into another block. Kaspa GHOSTDAG is a scalable generalisation of Nakamoto consensus, the approach used by Bitcoin, adapted to order those parallel blocks rather than retain only the winning chain.
Supporters and Kaspians use "Bitcoin 2.0" or "Bitcoin on steroids" as nicknames for carrying Bitcoin peer-to-peer proof-of-work principles into a faster base network.
The live network runs at 10 blocks per second (kaspa.org). Kaspa enables near-instant native KAS payments on its own base network. There is no channel to fund, no incoming liquidity to source, and no reserve token to redeem.
Restart plans and the remaining shortfall
In its 01:00 UTC update on 8 September, Blockstream said patched software had been deployed as federation members prepared a coordinated restart. The statement described preparation, not a completed restart, and did not specify who would cover the unrecovered funds.


