Abstract illustration of the Liquid Network hack showing Bitcoin draining from a digital vault
🔴 Cybersecurity · Crypto Exploit

Liquid Network Hack Drains $320M,
Hackers Return Most of It

Self-declared “white hats” emptied 95% of a Bitcoin sidechain’s reserve, then demanded a bug fix before they’d give most of it back.

📅 September 2026 ⏱ 8 min read
$320M drained from Liquid Network
$263M returned after a bug fix
$47M kept as a self-appointed “bounty”
Returned
After Bug Fix
263 M
Kept as “Bounty”
By the Hackers
47 M
Reserve Wiped
Federation Wallet
95 %

The Liquid Network hack didn’t look like a typical crypto heist from the moment it started, and it got stranger from there. On September 6, roughly 4,000 of the 4,200 Bitcoin held in the federation wallet backing Blockstream’s Liquid sidechain vanished in a single transaction that cost about 21 cents in fees. Liquid immediately disabled its bridge nodes, paused all transactions, and told exchanges to freeze L-BTC deposits and withdrawals.

Here’s where it gets unusual: no private key was compromised. The funds moved out through SideSwap, a normal, approved trading platform, after a software bug in Liquid’s underlying Elements codebase let a transaction create more L-BTC than the network actually had backing for. And instead of disappearing, the attackers left an on-chain message identifying themselves as “whitehats” and asked Blockstream to fix the bug before they’d send the money back.

This piece breaks down exactly how the bug worked, what the hackers demanded, how much came back, and why security researchers are still arguing over whether to call this a rescue or a ransom.

📋 What the Liquid Network Hack Boils Down To
What

What Broke Inside Liquid Network

A range-proof verification bug in Elements let a transaction mint more L-BTC than the network’s Bitcoin reserves could back.

How

How Liquid Network Funds Left

Through SideSwap, an approved trading platform — not a stolen private key or compromised federation signer.

The Demand

Fix It, Then We Pay

The attackers refused to return funds until Blockstream confirmed every node was patched against the same bug.

The Debate

Rescue or Ransom?

Security figures are split on whether keeping $47M as an unsolicited “bounty” counts as ethical disclosure or extortion.

Inside the Liquid Network Hack
01

September 6: Liquid Network Loses 4,000 Bitcoin

The Drain

Liquid’s federation wallet held about 4,200 BTC backing the network’s L-BTC token, used by exchanges for faster Bitcoin settlement. In a single transaction costing roughly 21 cents in fees, close to 4,000 of that Bitcoin moved out, leaving the reserve at approximately 197 BTC — about 5% of what it started with.

💡 Immediate response. Liquid disabled bridge nodes and paused the network within hours, and asked exchanges to freeze L-BTC deposits and withdrawals while other Liquid assets like USDT and DePix stayed unaffected.
02

The Bug That Made It Possible

Root Cause

Liquid said the SideSwap Peg-out Authorization Key used to move the funds was not itself compromised. Instead, Blockstream traced the issue to a range-proof verification bug in Elements, the open-source software powering Liquid, which allowed certain nodes to accept a transaction that effectively created L-BTC the network didn’t actually have backing for.

💡 Why it’s more alarming than a stolen key. A key compromise is fixed by rotating that key. A logic bug in consensus code means every node running the flawed version was exposed, not just one point of failure.
03

“Fix the Bug First, Then We Pay You Back”

The Demand

After consolidating the funds, the attackers left an on-chain message identifying themselves as “whitehats” and initiated contact with Blockstream through PGP-signed messages. Their condition was blunt: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”

💡 Blockstream’s move. The company patched the vulnerability and confirmed the fix to the group, who then began returning funds.
04

White Hats or Extortionists?

The Debate

The group returned about 3,400 of the 4,000 BTC (roughly $262.6 million) but kept around 598 BTC (about $47 million) as a self-appointed bounty. Ledger CTO Charles Guillemet wrote on X that the attackers “don’t seem to be white hats, and they don’t seem to be the usual criminals either.” Others were less ambiguous — Gart founder Alena Vránová called it extortion outright, arguing that exploiting a bug and holding funds hostage for a fix isn’t the same as responsible disclosure.

💡 Wider criticism. Some Bitcoin developers argue the incident exposed how a single software update could effectively drain the network, calling the federation model “decentralization theater.”

They returned 85% of the money
and still call it a bounty, not a ransom.

The $47M Question
🔒 If You Hold L-BTC or Use Liquid Network
  • Don’t attempt deposits or withdrawals until Liquid and its federation members confirm the network has fully resumed normal operation.
  • Check official channels only — Blockstream and Liquid’s own accounts, not third-party threads, for the latest reserve and restart status.
  • Review any exchange holding L-BTC for its own statement on whether your balance is fully backed again.
  • Treat “white hat” claims with skepticism — a group returning funds after a demand doesn’t automatically make the original exploit legal.

⚠️ Why the Liquid Network Story Isn’t Over

1. Returning funds doesn’t erase the exploit. Legal experts note that draining a wallet and demanding conditions before repayment can still meet the legal definition of extortion, regardless of the attacker’s stated intent.

2. The $47M “bounty” was never offered. Blockstream didn’t agree to pay that amount — the attackers simply kept it, which is a meaningfully different situation than a negotiated bug bounty program.

3. The underlying trust model took a hit. A federation built on 15 members required only a single flawed code update to put the entire reserve at risk, raising questions about how “decentralized” the security actually is.

✅ Final Verdict

The Liquid Network Hack, What to Remember

1
$320M drained from Liquid Network’s federation wallet on September 6, 2026
2
No private key was compromised — a bug in the Elements codebase let the transaction through
3
Attackers demanded a fix first, then returned funds through PGP-signed negotiation
4
$263M returned, but roughly $47M was kept as a self-appointed bounty
5
Security researchers remain split on whether this counts as ethical disclosure or extortion
🔗 CoinDesk has ongoing coverage of the negotiation and fund returns — read the full timeline at CoinDesk.
💬 Frequently Asked Questions
Q. Was this actually a hack, or a legitimate bug bounty?
It’s genuinely disputed. The attackers exploited a real bug rather than stealing credentials, and returned most of the funds — but they set the terms unilaterally and kept roughly $47 million without it being offered as a reward, which several security figures say crosses into extortion.
Q. Is my Bitcoin or L-BTC safe right now?
Liquid paused the network and disabled bridge nodes specifically to prevent further exposure. If you hold L-BTC, check official Liquid and Blockstream channels before attempting any transaction.
Q. How did the attackers create Bitcoin the network didn’t have?
Through a range-proof verification bug in Liquid’s Elements software, which allowed a transaction to pass validation even though it effectively minted more L-BTC than the actual Bitcoin reserves backing it.
Q. Will the remaining $47 million ever be returned?
Unclear. As of this writing, Blockstream says it continues to engage with the group, but the attackers have given no firm commitment on the remaining balance.
Editor’s Note. This article draws on reporting from CoinDesk, SecurityWeek, Gizmodo, Tom’s Hardware, and EM360Tech, along with public statements from Liquid Network and Blockstream, all published between September 6 and September 9, 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top