Liquid Network Recovers 3,400 BTC from White-Hat Hackers, $47M Still Pending

iconCryptoBriefing
Share
AI summary iconSummary
BTC news today, Liquid Network recovered 3,400 BTC from white-hat hackers after a September 6 exploit drained 4,000 BTC from its federation wallet. Around 598.5 BTC, valued at $47 million, remains outstanding. Attackers used Bitcoin’s OP_RETURN field and PGP-encrypted messages to communicate. Blockstream patched the affected bridge nodes on September 7, but the sidechain is paused, with exchanges told to stop L-BTC deposits and withdrawals. BTC update: the incident highlights ongoing security challenges in the crypto space.

On September 6, 2026, roughly 4,000 BTC walked out of the Liquid Network’s federation wallet through a vulnerability that, on the surface, looked like a perfectly normal transaction. No alarms, no broken keys, no obvious intrusion. Just a peg-out processed by SideSwap that quietly drained what was then worth around $320 million.

By the following day, 3,400 of those Bitcoin had come back. About 598.5 BTC, worth roughly $47 million, have not.

What actually happened

The flaw lived inside Elements, the open-source software that Liquid runs on and that itself descends from Bitcoin Core. The vulnerability allowed someone to generate unbacked L-BTC tokens, essentially printing claims on Bitcoin that had no real collateral behind them. Critically, none of the federation’s private keys were touched, and SideSwap’s infrastructure showed no signs of compromise. The withdrawal moved through standard authorization channels, which is precisely what made it so hard to catch in real time.

The actors who executed the drain subsequently identified themselves as white-hat hackers. They chose an appropriately on-brand communication method: Bitcoin’s OP_RETURN field, a data-carrying component of Bitcoin transactions typically used for small messages, combined with PGP-encrypted text.

Advertisement

Blockstream confirmed it patched the affected bridge nodes on September 7. Shortly after that confirmation, 3,400 BTC landed back at the federation address. The remaining 598.5 BTC stayed put, with negotiations described as ongoing.

Bounty or extortion

The question hanging over the recovery is not subtle. Returning 85% of a haul while keeping $47 million pending further talks sits in ambiguous territory.

Charles Guillemet, CTO at Ledger, publicly flagged the tension between the actors’ white-hat framing and the size of what they retained.

For now, the Liquid Network remains paused. Exchanges that support L-BTC have been instructed to halt both deposits and withdrawals, leaving users who hold the sidechain asset in a holding pattern with no clear timeline for resumption.

Why Liquid’s architecture made this possible

Liquid is a federated sidechain, meaning its security model rests on a consortium of functionaries rather than a decentralized validator set. Assets move between Bitcoin’s main chain and Liquid through a two-way peg: deposit BTC, receive L-BTC on the sidechain; redeem L-BTC, receive BTC back on mainchain. The federation collectively controls the keys that authorize those redemptions.

The September 6 incident demonstrated that the peg mechanism’s authorization logic was vulnerable at the software level, even when the cryptographic keys themselves remained intact.

Blockstream has not disclosed the precise nature of the Elements vulnerability. The bridge nodes are patched, per Blockstream’s statement, but the sidechain has not resumed operations.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.