Liquid Network recovers 3,400 Bitcoin from white-hat hackers as talks continue over remaining $47M

1 hour ago 19

On September 6, 2026, roughly 4,000 BTC walked out of the Liquid Network’s federation wallet through a vulnerability that, on the surface, looked like a perfectly normal transaction. No alarms, no broken keys, no obvious intrusion. Just a peg-out processed by SideSwap that quietly drained what was then worth around $320 million.

By the following day, 3,400 of those Bitcoin had come back. About 598.5 BTC, worth roughly $47 million, have not.

What actually happened

The flaw lived inside Elements, the open-source software that Liquid runs on and that itself descends from Bitcoin Core. The vulnerability allowed someone to generate unbacked L-BTC tokens, essentially printing claims on Bitcoin that had no real collateral behind them. Critically, none of the federation’s private keys were touched, and SideSwap’s infrastructure showed no signs of compromise. The withdrawal moved through standard authorization channels, which is precisely what made it so hard to catch in real time.

The actors who executed the drain subsequently identified themselves as white-hat hackers. They chose an appropriately on-brand communication method: Bitcoin’s OP_RETURN field, a data-carrying component of Bitcoin transactions typically used for small messages, combined with PGP-encrypted text.

Blockstream confirmed it patched the affected bridge nodes on September 7. Shortly after that confirmation, 3,400 BTC landed back at the federation address. The remaining 598.5 BTC stayed put, with negotiations described as ongoing.

Bounty or extortion

The question hanging over the recovery is not subtle. Returning 85% of a haul while keeping $47 million pending further talks sits in ambiguous territory.

Charles Guillemet, CTO at Ledger, publicly flagged the tension between the actors’ white-hat framing and the size of what they retained.

For now, the Liquid Network remains paused. Exchanges that support L-BTC have been instructed to halt both deposits and withdrawals, leaving users who hold the sidechain asset in a holding pattern with no clear timeline for resumption.

Why Liquid’s architecture made this possible

Liquid is a federated sidechain, meaning its security model rests on a consortium of functionaries rather than a decentralized validator set. Assets move between Bitcoin’s main chain and Liquid through a two-way peg: deposit BTC, receive L-BTC on the sidechain; redeem L-BTC, receive BTC back on mainchain. The federation collectively controls the keys that authorize those redemptions.

The September 6 incident demonstrated that the peg mechanism’s authorization logic was vulnerable at the software level, even when the cryptographic keys themselves remained intact.

Blockstream has not disclosed the precise nature of the Elements vulnerability. The bridge nodes are patched, per Blockstream’s statement, but the sidechain has not resumed operations.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article