Hackers Drain Up to $340 Million From Liquid Network via Software Exploit
Attackers claiming to be 'white-hats' held 4,000 BTC hostage to force a critical security patch.
A massive software vulnerability in the Liquid Network led to the theft of approximately $320 million to $340 million in Bitcoin in September 2026. The heist forced a temporary shutdown of the Bitcoin sidechain as developers scrambled to secure the infrastructure.
The attackers withdrew roughly 4,000 BTC from the Liquid Network federation wallet by exploiting a bug in Blockstream's Elements software. This flaw allowed the actors to create L-BTC without the necessary reserves, which they then processed through SideSwap's peg-out service to withdraw the funds. While SideSwap's service facilitated the exit, both Liquid and SideSwap explicitly stated that the Peg-out Authorization Key (PAK) was not compromised during the attack.
Infrastructure Under Pressure
The Liquid Network, developed by Blockstream, operates as a federated sidechain designed to provide cryptocurrency exchanges with faster and cheaper settlement options than the main Bitcoin blockchain. Because it serves as a critical layer for liquidity and asset movement, any breach in its reserve system threatens the stability of the exchanges that rely on it. Immediately following the discovery of the drain, the Liquid Network suspended all operations and disabled bridge nodes to prevent further losses.
The 'White-Hat' Ultimatum
In a move becoming increasingly common in decentralized finance (DeFi) and sidechain security, the recipients of the funds identified themselves as "white-hat hackers," according to SideSwap. The attackers pledged to return the stolen assets, but only on the condition that the underlying software vulnerability be patched. This tactic effectively holds systemic funds hostage to force an immediate security upgrade across the network's nodes.
Systemic Implications
This event underscores a critical fragility in the settlement infrastructure used by major industry players. When a sidechain's reserve mechanism is compromised, it exposes the risk inherent in "pegged" assets, where the value of a token on a sidechain depends entirely on the security of the reserves on the main chain. The incident demonstrates that even established federated networks are susceptible to software bugs that can be weaponized for massive scale thefts.
What Remains
Attention now turns to the federation's ability to deploy the necessary patches across all nodes to satisfy the attackers' conditions. While the hackers have expressed a willingness to return the funds, the industry is watching closely to see if the full amount is recovered and how Blockstream intends to harden the Elements software against similar exploits in the future.