Liquid Network Hack Explained: What Happened to $320M in Bitcoin?
2026-09-08
On September 6, 2026, the Liquid Network hack drained roughly 4,000 Bitcoin, about $320 million, from the federated Bitcoin sidechain after a software bug in Elements allowed unbacked L-BTC to be minted and redeemed for real BTC.
Most of the funds were returned within 24 hours by actors claiming to be white hats, turning what looked like a catastrophic Bitcoin sidechain exploit into an unusual on-chain negotiation and partial recovery.
Here is a full breakdown of what happened, how the exploit worked, and where things stand now.
Key Takeaways
On September 6, 2026, roughly 4,000 of the 4,200 BTC held in Liquid Network's federation wallet were withdrawn in a single transaction, draining close to 95% of its Bitcoin reserves.
The attackers did not steal a private key. A software bug in Elements, the open-source code that powers Liquid, allowed L-BTC to be created without being properly backed by real Bitcoin, and that L-BTC was then redeemed through SideSwap, an authorized withdrawal platform.
The people behind the exploit called themselves white hats, negotiated with Blockstream through public on-chain messages, and returned 3,400 BTC (about $268 million) after the vulnerability was patched, keeping 598.5 BTC (roughly $47 million) as what analysts describe as an informal bounty.
What a Liquid Network Hack Actually Means
Liquid Network is a Bitcoin sidechain launched by Blockstream in 2018. Think of it as an express lane running alongside the main Bitcoin highway. Users lock up real BTC with a federation, a group of more than 80 exchanges, market makers, and infrastructure firms, and in exchange they receive L-BTC, a token that moves faster and offers more privacy on the sidechain.
When someone wants their Bitcoin back, they peg out, burning L-BTC so the federation releases an equivalent amount of real BTC.
That peg-out step is exactly where this incident happened. Someone found a way to make the system believe more L-BTC existed than it should have, then cashed that phantom L-BTC out for real Bitcoin. The Liquid Federation Peg-out Authorization Key itself was never compromised. The flaw sat inside the software logic, not the cryptography protecting the keys.
How the Liquid Bitcoin Hack Unfolded, Step by Step
The Withdrawal
On Sunday, September 6, at 14:28:56 UTC, a transaction landed in Bitcoin block 965,783 sending roughly 3,996 BTC to a single address. Liquid's federation wallet balance dropped from about 4,200 BTC to just over 207 BTC almost instantly.
Liquid confirmed the incident on X shortly after, describing the actors as "purported white-hat hackers" and announcing that it had halted all new transactions while federation members investigated.
The Mechanism
According to SideSwap, a settlement platform authorized to process Liquid withdrawals, a customer sent 4,000 L-BTC to its peg-out service. The tokens were burned through what looked like a valid authorization, and the federation paid out 3,996 BTC in return.
It was only afterward that Blockstream traced the problem to Elements, the open-source framework underlying Liquid's confidential transactions and federation logic.
A bug in that code had allowed L-BTC to be minted without the Bitcoin backing it, meaning SideSwap could not distinguish the fabricated tokens from legitimate ones and processed the withdrawal as usual.
The Fallout
Liquid paused bridge nodes within hours, and several exchanges suspended L-BTC deposits and withdrawals as a precaution. Other assets living on the same sidechain, including USDT, DePix, and various tokenized real-world assets, were unaffected since the bug was specific to how Bitcoin-backed L-BTC gets minted and burned.
Stay informed on major crypto security events and explore secure trading options. Register on Bitrue today to access a wide range of digital assets.
Blockstream Exploit: The On-Chain Negotiation
What happened next is where this Blockstream exploit stopped looking like a typical crypto theft. Instead of going silent, the wallet holding the stolen Bitcoin stayed active and unmoved for hours, which security researchers flagged as unusual behavior for a malicious actor.
Blockstream reached out the same evening, sending a small transaction with an OP_RETURN message reading "Please contact security@blockstream.com." The attackers responded in kind, embedding messages directly into public Bitcoin transactions rather than communicating off-chain.

Blockstream sent encrypted follow-up messages early the next morning, and the attackers eventually replied in the clear, writing that they intended to send most of the funds back once they had confirmation the underlying bug had been patched.
Blockstream later confirmed the bridge nodes had been fixed, telling the attackers on-chain it was "safe to return the funds."
The Return: 3,400 BTC Back, 598.5 BTC Kept
On Monday, September 7, the address responsible for the withdrawal broadcast a transaction sending 3,400 BTC, worth roughly $268 million, back to Liquid's federation wallet.
The remaining 598.5 BTC, worth close to $47 million and equal to about 15% of the total withdrawn, stayed at the attacker's address. Security firm CertiK flagged the retained amount as a possible informal bounty, though no formal agreement between Liquid and the attackers confirming that arrangement has been made public.
As of this writing, Liquid's last official public statement remains its initial Sunday announcement, and bridge node functionality was still reported as disabled while the network worked toward restoring normal service. The bulk of Bitcoin is back where it started, but the sidechain has not yet fully reopened for ordinary users.
Interpretation Cheat Sheet
Stolen key vs. software bug: Most crypto hacks this year trace back to compromised private keys or credentials. This one didn't. The Liquid Bitcoin hack came from a logic flaw in code, which is a different and in some ways harder category of risk to prevent.
"White hat" is a claim, not a certified status: The attackers labeled themselves white hats and behaved consistently with that label by returning most of the funds, but there was no formal bug bounty agreement in place beforehand.
Partial return is not full resolution: Returning 85% of the funds fixes most of the balance sheet damage, but it doesn't undo the operational disruption of halted withdrawals and paused bridge nodes.
Isolated to L-BTC: Other assets on Liquid, including stablecoins and tokenized assets, were untouched, which matters for anyone assessing broader platform risk.
Part of a bigger pattern: Crypto platforms lost an estimated $136 million across roughly 50 separate breaches in August 2026 alone, so this incident lands in a year already marked by frequent security failures.
Read Also: Supply Chain Attacks in Crypto: What You Need to Know
Summary
The Liquid Network hack stands out less for its size and more for how it was resolved. A near-total drain of a Bitcoin sidechain's reserves is normally a worst-case scenario, and for a few hours on September 6 it looked exactly like one.
What followed, a public on-chain negotiation between an infrastructure provider and an anonymous actor holding $320 million, and a return of most of the funds within 24 hours, is unusual even by crypto's standards.
It doesn't erase the underlying question of how a bug in Elements went unnoticed until someone exploited it at scale, but it does mean the financial damage to Liquid and its users turned out to be far smaller than the initial headline figure suggested.
Disclaimer: The views expressed belong exclusively to the author and do not reflect the views of this platform. This platform and its affiliates disclaim any responsibility for the accuracy or suitability of the information provided. It is for informational purposes only and not intended as financial or investment advice.
FAQ
What happened in the Liquid Network hack?
On September 6, 2026, attackers exploited a software bug in Elements, the code underlying Liquid Network, to withdraw roughly 4,000 BTC (about $320 million) from the network's federation wallet through SideSwap, an authorized withdrawal platform.
Was the Liquid Bitcoin hack caused by a stolen private key?
No. Liquid confirmed that the Peg-out Authorization Key used in the process was not compromised. The exploit stemmed from a flaw in Elements that allowed L-BTC to be created without being properly backed by real Bitcoin.
Has the stolen money been returned?
Most of it. The attackers returned 3,400 BTC, worth about $268 million, to Liquid's federation wallet on September 7 after Blockstream patched the vulnerability. They kept 598.5 BTC, around $47 million, which analysts have described as a possible informal bounty.
Is Liquid Network back to normal now?
Not fully. As of the most recent updates, bridge nodes remained disabled and several exchanges had paused L-BTC deposits and withdrawals while Blockstream worked to restore full network functionality.
Were other assets on Liquid Network affected?
No. The exploit was specific to L-BTC. Other assets hosted on the sidechain, including USDT, DePix, and tokenized real-world assets, were not impacted.
Disclaimer: The views expressed belong exclusively to the author and do not reflect the views of this platform. This platform and its affiliates disclaim any responsibility for the accuracy or suitability of the information provided. It is for informational purposes only and not intended as financial or investment advice.
Disclaimer: The content of this article does not constitute financial or investment advice.




