ZeroHour
Story · 1 source · 1 articlefirst updated ()

Hackers Exploit Elements Bug to Drain ~4,000 BTC From Liquid Network, Return 3,400 BTC but Still Hold ~598.5 BTC

highExploit / PoCexploited in the wildimportance 78
What's new: First merged summary for this story. Establishes the September 6 exploit of an Elements bug that drained ~4,000 BTC (~$320M, ~95% of Liquid's reserves) from the federation wallet, the September 7 return of 3,400 BTC after node patches, the ~598.5 BTC (~$47M) still retained by the attackers, and the ongoing network pause ahead of a coordinated restart.
Merged summary · glm-5.3 · rewritten as coverage arrives

Attackers exploited a bug in Elements, the software behind Blockstream's Liquid Network sidechain, to mint unbacked L-BTC and withdraw ~4,000 BTC (~$320M, ~95% of reserves) via SideSwap's Peg-out Authorization Key. After Blockstream patched the affected…

On September 6, 2026, attackers exploited a bug in Elements, the open-source software powering Blockstream's Liquid Network Bitcoin sidechain, allowing them to create unbacked L-BTC tokens that were redeemed for real Bitcoin through SideSwap's Peg-out Authorization Key (PAK). They withdrew roughly 4,000 BTC (~$320 million) from the federation wallet, which held approximately 4,200 BTC — about 95% of Liquid's reported reserves. Blockstream disabled nodes and suspended transactions after disclosing the heist on Sunday, September 6. The self-described white-hat attackers negotiated publicly via on-chain OP_RETURN messages and PGP-encrypted communications, demanding the bridge nodes be patched before returning funds. On Monday, September 7, they returned 3,400 BTC to the federation address (valued at ~$262.6M–$265M across reports, with The Hacker News citing ~$78,000 per BTC), while retaining about 598.5 BTC (~$47 million). Blockstream states the peg-out authorization key and other keys were not compromised, affected bridge nodes have been patched, and updated software is deployed; the network remains paused pending a coordinated restart and users have been warned against peg-ins. Ledger CTO Charles Guillemet characterized the arrangement as extortion, and experts continue to debate whether the act legally constitutes extortion. Trust in L-BTC backing has been damaged.

  • ~4,000 BTC (~$320M) drained from Liquid Network's federation wallet, which held ~4,200 BTC — roughly 95% of reported reserves, moved in one transaction
  • Attack vector was a bug in Elements, the open-source software powering the Liquid sidechain; attackers minted unbacked L-BTC and redeemed it via SideSwap's authorized peg-out mechanism
  • SideSwap's Peg-out Authorization Key was used but Blockstream says the PAK and other keys were not compromised
  • Drain occurred September 6, 2026; return of 3,400 BTC followed on September 7 after patches were demanded and applied
  • 3,400 BTC returned (valued ~$262.6M–$265M depending on report; The Hacker News cites ~$78,000/BTC)
  • ~598.5 BTC (~$47M) still held by the attackers
  • Negotiation conducted on-chain via OP_RETURN messages and PGP-encrypted communications
  • Blockstream patched affected bridge nodes and deployed updated software; network remains paused pending a coordinated restart, with users warned against peg-ins

Coverage timeline

  1. · 7d ago
    The Hacker News· 70
    Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

    Hackers exploited an Elements bug to take ~4,000 BTC from Liquid Network, returned 3,400 BTC (~$265M), and still hold ~598.5 BTC (~$47M).