Liquid Network Hack Drains $320M, Hackers Keep $47M ‘Bounty’

Related

Liquid Network Hack Drains $320M, Hackers Keep $47M ‘Bounty’

Blockstream’s Liquid Network, one of the oldest and most...

Trezor ERC-7730 signing ends blind signing after $1.5B Bybit hack

Trezor has switched on a long-awaited layer of transaction...

StablecoinX CEO appointment puts Franklin Templeton alum atop 20% ENA stake

StablecoinX, the Nasdaq-listed firm that has built its entire...

Chime Stride Bank Acquisition Seals $590M Full-Bank Ownership

Chime Financial is done renting its banking infrastructure. The...

Tesla Stock Jumps 4% as Dow Drops 600 Points, but $381 Barrier Looms

Tesla stock showed renewed strength on September 8, closing...

Share

Blockstream’s Liquid Network, one of the oldest and most widely used Bitcoin sidechains, lost roughly 4,000 BTC — worth about $320 million — after attackers exploited a software flaw on September 6. The Liquid Network hack drained the federation’s reserves from more than 4,200 BTC down to just around 197 BTC in a matter of hours, instantly ranking among the biggest security incidents to hit Bitcoin-adjacent infrastructure this year.

Key takeaways

  • Liquid Network lost approximately 4,000 BTC (about $320 million) on September 6 due to a bug in the Elements software that powers the sidechain.
  • Attackers who called themselves white-hat hackers returned around 3,400 BTC after Blockstream patched the vulnerability, but kept roughly 598 BTC ($47 million) as a self-declared bounty.
  • No federation multisig keys were compromised — the flaw sat upstream, in the software that validates transactions before they reach the 11-of-15 signing federation.
  • Liquid Network remains paused, with all L-BTC activity suspended across exchanges and no public timeline for resuming normal operations.
  • Other assets on the network, including USDT and tokenized real-world assets, were untouched by the exploit.

What triggered the Liquid Network hack and how much was drained

The breach hit at the core of Liquid’s purpose. Launched in 2018 to give exchanges and institutional traders faster, more private Bitcoin settlement, a federation comprising more than 80 exchanges, infrastructure firms and asset managers provides oversight of the network. On September 6, that trust model was tested when attackers pulled roughly 4,000 of the 4,200 Bitcoin sitting in the federation wallet, according to Blockstream and CoinDesk reporting.

Liquid Network confirmed the disruption directly to users, warning that wallets would be affected while the team worked toward a fix. The network halted new transactions almost immediately, a move that underscored how severe the drain was relative to its total reserves.

Partial fund recovery by white-hat hackers

In an unusual twist, the attackers identified themselves as white-hat hackers and began communicating with Liquid’s maintainers through onchain Bitcoin messages. One message read: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”

True to that message, the hackers returned around 3,400 BTC once Blockstream confirmed the vulnerability had been patched. They kept approximately 598 BTC, worth roughly $47 million, as a self-appointed bounty — a gesture framed as ethical hacking but one that leaves the network still short of its pre-attack reserves.

Inside the Elements software bug behind the exploit

The root cause traces back to Elements software, the open-source codebase that underpins Liquid Network. A range-proof verification cache bug let attackers mint invalid L-BTC tokens that the system mistakenly treated as legitimate. Those fraudulent tokens then moved through SideSwap’s Peg-out Authorization Key, which converted them into genuine BTC withdrawals from the federation wallet.

SideSwap later said it had no way to distinguish the fraudulent tokens from real ones at the time, so it processed them the same way it would any legitimate peg-out request. That detail matters: the exploit didn’t need a compromised platform acting maliciously — it only needed a trusted platform doing exactly what it was designed to do, fed bad data by a flawed validation layer.

Federation multisig held, but the trust model took a hit

Crucially, no federation signing keys were compromised. Liquid runs on an 11-of-15 federation multisig, requiring eleven of fifteen designated entities to approve transactions, and that multisig performed exactly as designed throughout the incident. The failure sat upstream, in the software validating what got sent to the multisig in the first place — not in the multisig itself.

That distinction matters for anyone evaluating Bitcoin sidechain security more broadly. A federated model is only as trustworthy as the code feeding it, and this episode showed how a narrow, deeply technical flaw in token validation can bypass even a well-designed signing structure entirely.

Liquid Network’s suspension and the wider fallout

Liquid Network remains paused. All L-BTC activity has been suspended across exchanges, and there’s still no public timeline for restoring normal operations. For infrastructure that markets itself as a faster, more confidential settlement layer for institutional Bitcoin trading, an open-ended freeze is a real credibility problem, especially for exchanges and custodians that relied on L-BTC liquidity daily.

Other assets on the network fared better. USDT and tokenized real-world assets held on Liquid were unaffected, since the bug was specific to L-BTC token validation rather than the broader sidechain infrastructure. Still, the reserve numbers tell a blunt story: before the attack the federation wallet held over 4,200 BTC; after the partial white-hat return, it sits at roughly 3,600 BTC — still short by the 598 BTC the attackers kept.

The wider implication reaches beyond Liquid itself. The Elements software vulnerability lived in code used by other projects too, meaning any platform built on the same codebase now has to verify the flaw doesn’t exist in its own implementation. That’s a meaningful industry-wide task, not just a Blockstream problem, and it puts pressure on developers across the ecosystem to audit range-proof verification logic they may have assumed was solid.

There’s also an unresolved legal question hanging over the episode. Framing this as a white-hat crypto hack may describe the outcome, but keeping $47 million in unsolicited Bitcoin as a bounty sits in a legal gray zone. Whether regulators or law enforcement ultimately treat that as responsible disclosure or as theft with partial restitution could set a precedent shaping how future incidents involving sidechains and federated custody models get handled.

FAQ

How did the Liquid Network hack occur?

Hackers exploited a range-proof verification cache bug in the Elements software, creating invalid L-BTC tokens that were converted into real BTC withdrawals through SideSwap’s Peg-out Authorization Key.

Were the multisignature federation keys compromised during the hack?

No. The federation multisig keys remained secure throughout the attack; the exploit targeted the upstream token validation software rather than the signing structure itself.

Has Liquid Network resumed normal operations after the hack?

No. Liquid Network remains paused, with all L-BTC activity suspended across exchanges and no public timeline for resuming normal service.

What happened to the stolen Bitcoin after the hack?

About 3,400 BTC were returned by the self-identified white-hat hackers once Blockstream patched the vulnerability, while approximately 598 BTC, worth roughly $47 million, were kept as a self-appointed bounty.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.