Hackers Drained ~4,000 BTC From Liquid Network via Elements Bug, Then Returned Most of It
Attackers exploited a bug in the Elements software behind Blockstream's Liquid Network to mint unbacked L-BTC and withdraw ~4,000 BTC (~$320M–$340M), then returned 3,400 BTC after nodes were patched, still holding ~598.5 BTC (~$47M).
On September 6, 2026, attackers exploited a bug in Elements, the open-source software powering Blockstream's Liquid Network Bitcoin sidechain, to create unbacked L-BTC tokens and redeem them for roughly 4,000 BTC — about 95% of the federation wallet's ~4,200 BTC reserves — via SideSwap's Peg-out Authorization Key. Blockstream says that key and others were not compromised. Reports value the theft differently: ~$320M (The Hacker News, SecurityWeek, Security Affairs) versus ~$340M (TechCrunch), reflecting different BTC prices. Self-described white-hat hackers negotiated publicly via on-chain OP_RETURN messages and PGP-encrypted communications, demanding bridge nodes be patched before returning funds. They returned 3,400 BTC (valued ~$262.6M–$293M depending on the source) to the federation address on September 7, retaining ~598.5 BTC (~$47M) pending further security improvements. Blockstream confirmed affected bridge nodes were patched and updated software is deployed, but the network remains paused pending a coordinated restart, with users warned against peg-ins. Ledger CTO Charles Guillemet characterized the arrangement as extortion — a characterization experts continue to debate — and Rekt's leaderboard ranks the incident among the largest cryptocurrency thefts to date.
- Attackers exploited a bug in Elements, the open-source software behind Blockstream's Liquid Network, to create unbacked L-BTC tokens redeemed for real Bitcoin
- ~4,000 BTC withdrawn in one transaction, draining ~95% of the federation wallet's ~4,200 BTC reserves
- Sources disagree on the theft's value: ~$320M (The Hacker News, SecurityWeek, Security Affairs) vs ~$340M (TechCrunch)
- Funds exited via SideSwap's Peg-out Authorization Key, which Blockstream says was not compromised; no keys were stolen
- Self-described white-hat hackers demanded node patches before returning funds, negotiating via on-chain OP_RETURN messages and PGP-encrypted communications
- 3,400 BTC returned to the federation address on September 7 (valued ~$262.6M–$265M by most sources; TechCrunch cites ~$293M)
- ~598.5 BTC (~$47M) remains under the hackers' control pending further security improvements
- Blockstream patched the affected bridge nodes and deployed updated software; the network remains paused pending a coordinated restart and users are warned against peg-ins
Coverage timelineoldest first · each row is one article
- · 7d agoA hacker stole $340M in a crypto heist, then returned most of it
TechCrunch · Security· 66
A hacker exploited a bug to steal about 4,000 BTC (~$340M) from Blockstream's Liquid Network, then returned roughly 3,400 BTC after the bug was fixed.