ZeroHour
Story · 1 source · 1 articlefirst updated ()1

Hackers drain ~4,000 BTC (~$320M) from Blockstream's Liquid Network via an Elements bug, then return 3,400 BTC; ~598 BTC still held and network paused

highExploit / PoCexploited in the wildimportance 78
What's new: ['Added the theft date (September 6) and that the drain occurred in a single transaction (Security Affairs).', 'Specified the on-chain negotiation channel as OP_RETURN messages (Security Affairs); the prior summary cited on-chain messaging only generally.', 'Clarified the mechanism: the Elements bug allowed creation of unbacked L-BTC tokens redeemed for real Bitcoin through SideSwap''s authorized…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Attackers exploited a bug in Elements, the software behind Blockstream's Liquid Network Bitcoin sidechain, to create unbacked L-BTC and withdraw roughly 4,000 BTC — about $320 million per most sources, about $340 million per TechCrunch — some 95% of the…

Attackers withdrew about 4,000 BTC — valued at roughly $320 million by The Register, DataBreaches.net, The Hacker News, SecurityWeek and Security Affairs, and about $340 million by TechCrunch — from the federation wallet backing Liquid Network, the Blockstream-developed Bitcoin sidechain and settlement service launched in 2018 and used by cryptocurrency exchanges and financial institutions. Security Affairs dates the drain to September 6 and says it was done in one transaction; the wallet held approximately 4,200 BTC (SecurityWeek, Security Affairs), so the withdrawal equaled about 95% of Liquid's reported BTC reserves and L-BTC collateral pool, leaving roughly 5% of prior holdings (The Register). Later reporting (The Hacker News, TechCrunch, Security Affairs) attributes the theft to a bug in Elements, the open-source software behind Liquid, which let the attackers create unbacked L-BTC tokens and redeem them for real Bitcoin through SideSwap's authorized peg-out mechanism using the Peg-out Authorization Key (PAK); The Register's initial report had said the exact mechanism remained under investigation. Blockstream states the PAK and other keys were not compromised. The perpetrators embedded on-chain messages — OP_RETURN messages per Security Affairs — identifying themselves as white hats or 'the good guys', negotiated via on-chain and PGP-encrypted messages (The Hacker News), and demanded that federation/bridge nodes be patched before any funds were returned. Ledger CTO Charles Guillemet characterized the arrangement as extortion, and Security Affairs reports that experts debate whether it legally constitutes extortion; DataBreaches.net offers no attribution or recovery details beyond the hackers' public claim. Blockstream disclosed the heist on Sunday (DataBreaches.net, SecurityWeek), disabled bridge nodes, paused the network and asked exchanges to suspend L-BTC deposits and withdrawals; users were warned against peg-ins (The Hacker News). Per The Register, other Liquid assets and the Bitcoin network were unaffected. Blockstream later confirmed the affected bridge nodes were patched (Security Affairs) and that updated software is deployed (The Hacker News), but the network remains paused pending a coordinated, safe restart. On September 7 — described as Monday by SecurityWeek — the hackers returned 3,400 BTC to the federation address, valued at about $262.6 million by SecurityWeek, about $265 million (about $78,000 per BTC) by The Hacker News, and about…

  • About 4,000 BTC was withdrawn from Liquid Network's federation wallet on September 6 (Security Affairs) in a single transaction, valued at ~$320M by The Register, DataBreaches.net, The Hacker News, SecurityWeek and Security Affairs;…
  • The federation wallet held ~4,200 BTC (SecurityWeek, Security Affairs); the withdrawal was ~95% of reported reserves / the L-BTC collateral pool, leaving ~5% of prior holdings.
  • A bug in Elements, the open-source software behind Liquid, allowed creation of unbacked L-BTC that was redeemed for real Bitcoin via SideSwap's authorized peg-out using the Peg-out Authorization Key (PAK); The Register's initial report…
  • Blockstream states the PAK and other keys were not compromised.
  • The hackers called themselves white hats / 'the good guys' via on-chain OP_RETURN messages and negotiated through on-chain and PGP-encrypted messages, demanding bridge/federation nodes be patched before returning funds.
  • Ledger CTO Charles Guillemet characterized the arrangement as extortion; Security Affairs reports experts debate whether it legally constitutes extortion.
  • Blockstream disclosed the heist on Sunday (DataBreaches.net, SecurityWeek), disabled bridge nodes, paused the network, asked exchanges to suspend L-BTC deposits and withdrawals, and warned users against peg-ins; affected bridge nodes were…
  • 3,400 BTC was returned to the federation address on September 7 (The Hacker News; SecurityWeek describes it as Monday): ~$262.6M per SecurityWeek, ~$265M (~$78,000 per BTC) per The Hacker News, ~$293M per TechCrunch citing former…

Coverage timeline

  1. · 8d ago
    The Register · Security· 78
    Hackers drain $320M in Bitcoin from Liquid Network, claim they're the good guys

    Attackers withdrew about 4,000 BTC (~$320M) from Liquid Network's federation wallet via a SideSwap peg-out, claiming whitehat status.