Hackers Exploit Elements Bug to Drain ~4,000 BTC From Liquid Network, Return 3,400 BTC but Still Hold ~598.5 BTC
Attackers exploited a bug in Elements, the software behind Blockstream's Liquid Network sidechain, to mint unbacked L-BTC and withdraw ~4,000 BTC (~$320M, ~95% of reserves) via SideSwap's Peg-out Authorization Key. After Blockstream patched the affected…
On September 6, 2026, attackers exploited a bug in Elements, the open-source software powering Blockstream's Liquid Network Bitcoin sidechain, allowing them to create unbacked L-BTC tokens that were redeemed for real Bitcoin through SideSwap's Peg-out Authorization Key (PAK). They withdrew roughly 4,000 BTC (~$320 million) from the federation wallet, which held approximately 4,200 BTC — about 95% of Liquid's reported reserves. Blockstream disabled nodes and suspended transactions after disclosing the heist on Sunday, September 6. The self-described white-hat attackers negotiated publicly via on-chain OP_RETURN messages and PGP-encrypted communications, demanding the bridge nodes be patched before returning funds. On Monday, September 7, they returned 3,400 BTC to the federation address (valued at ~$262.6M–$265M across reports, with The Hacker News citing ~$78,000 per BTC), while retaining about 598.5 BTC (~$47 million). Blockstream states the peg-out authorization key and other keys were not compromised, affected bridge nodes have been patched, and updated software is deployed; the network remains paused pending a coordinated restart and users have been warned against peg-ins. Ledger CTO Charles Guillemet characterized the arrangement as extortion, and experts continue to debate whether the act legally constitutes extortion. Trust in L-BTC backing has been damaged.
- ~4,000 BTC (~$320M) drained from Liquid Network's federation wallet, which held ~4,200 BTC — roughly 95% of reported reserves, moved in one transaction
- Attack vector was a bug in Elements, the open-source software powering the Liquid sidechain; attackers minted unbacked L-BTC and redeemed it via SideSwap's authorized peg-out mechanism
- SideSwap's Peg-out Authorization Key was used but Blockstream says the PAK and other keys were not compromised
- Drain occurred September 6, 2026; return of 3,400 BTC followed on September 7 after patches were demanded and applied
- 3,400 BTC returned (valued ~$262.6M–$265M depending on report; The Hacker News cites ~$78,000/BTC)
- ~598.5 BTC (~$47M) still held by the attackers
- Negotiation conducted on-chain via OP_RETURN messages and PGP-encrypted communications
- Blockstream patched affected bridge nodes and deployed updated software; network remains paused pending a coordinated restart, with users warned against peg-ins
Coverage timelineoldest first · each row is one article
- · 7d agoLiquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
The Hacker News· 70
Hackers exploited an Elements bug to take ~4,000 BTC from Liquid Network, returned 3,400 BTC (~$265M), and still hold ~598.5 BTC (~$47M).