ZeroHour
Story · 1 source · 1 articlefirst updated ()

Hackers Drain ~4,000 BTC ($320M) From Liquid Network, Then Return Most of It After Patch

highExploit / PoCexploited in the wildimportance 78
What's new: First merged summary of this story. Attack disclosed by Blockstream on Sunday; bridge nodes patched; attackers returned 3,400 BTC (~$262.6M) on Monday; ~598 BTC still outstanding and network still paused pending security work and safe restart.
Merged summary · glm-5.3 · rewritten as coverage arrives

Attackers exploited an Elements code bug to withdraw ~4,000 BTC (~$320M) from Liquid Network's federation wallet without stealing keys, then returned 3,400 BTC (~$263M) after Blockstream patched the affected bridge nodes; ~598 BTC (~$47M) remains outstanding…

On September 6, an attacker drained roughly 4,000 of the ~4,200 BTC (~$320M) held in Bitcoin's Liquid Network federation wallet — about 95% of the L-BTC collateral pool in a single transaction — by exploiting a bug in Elements, the open-source code powering the sidechain. The bug allowed the creation of unbacked L-BTC tokens that were redeemed for real Bitcoin through SideSwap's authorized peg-out mechanism (the Peg-out Authorization Key); no keys were stolen or compromised. Blockstream disclosed the incident on Sunday, disabled nodes, and suspended transactions. The self-described white-hat attackers negotiated publicly via OP_RETURN on-chain messages, demanding the bug be patched before returning funds. On Monday they returned 3,400 BTC (~$262.6M), leaving ~598 BTC (~$47M) outstanding. Blockstream confirmed the affected bridge nodes have been patched, but the network remains paused while federation members complete security work and prepare a safe restart. Experts continue to debate whether the attackers' conduct legally constitutes extortion, and the incident has damaged trust in L-BTC backing.

  • ~4,000 BTC (~$320M) drained from the Liquid Network federation wallet, which held ~4,200 BTC (~95% of the L-BTC collateral pool) in one transaction
  • Attack occurred on September 6, exploiting a bug in Elements, the open-source code powering the Liquid sidechain
  • Funds were withdrawn via SideSwap's authorized peg-out mechanism (Peg-out Authorization Key) without any key being compromised
  • Attackers negotiated publicly on-chain using OP_RETURN messages, demanding the bug be patched
  • 3,400 BTC (~$262.6M) returned on Monday; ~598 BTC (~$47M) remains outstanding
  • Blockstream disclosed the heist on Sunday, disabled nodes, suspended transactions, and has confirmed the affected bridge nodes are patched
  • Liquid Network remains paused while federation members complete security work and prepare a safe restart
  • Experts debate whether the attackers' behavior legally constitutes extortion; trust in L-BTC backing has been damaged

Coverage timeline

  1. · 7d ago
    SecurityWeek· 70
    Hackers Return $263 Million Stolen From Liquid Network

    Hackers drain roughly 4,000 BTC (~$320M) from Liquid Network federation wallet, then return 3,400 BTC with ~598 BTC still outstanding.