TechNewsReel
Live

Liquid Network Recovers $270 Million After Elements Software Breach

A bug in Elements software allowed actors to withdraw 4,000 BTC from the Liquid federation wallet; 600 BTC remains missing.

TechNewsReel Newsroom · September 7, 2026

The Liquid Network suffered a massive security breach around September 6, 2026, when actors claiming to be "white hat hackers" withdrew approximately 4,000 BTC from the network's federation wallet. The incident underscores the persistent risks associated with sidechain bridge infrastructure.

According to reports, the actors utilized a bug in the Elements open-source software to execute the withdrawal via SideSwap's peg-out service. The breach targeted the federation wallet, which holds the Bitcoin backing L-BTC issued on the sidechain. The 4,000 BTC withdrawn represented roughly 95% of the wallet's 4,200 BTC balance, totaling approximately $320 million. The actors stated they would return the funds only after Blockstream confirmed that all bridge nodes were patched, telling the company, "Please fix the bug first... Make sure every node is patched. Then we will transfer the money back safely."

The Infrastructure Gap

Liquid operates as a Bitcoin-based sidechain designed primarily as a settlement layer for exchanges. To maintain the value of L-BTC, the network relies on a federation of nodes to manage a reserve of native Bitcoin. In this instance, the vulnerability resulted from a fundamental flaw in Elements, the software underpinning the network's architecture, rather than compromised private keys at SideSwap. This distinction highlights a critical systemic risk: even when individual service keys are secure, the underlying protocol software can create single points of failure for millions of dollars in assets.

Implications for Trust

While the actors returned 3,400 BTC—roughly $269.2 million or 85% of the stolen funds—approximately 600 BTC (specifically 598.5 BTC) remains outstanding. This discrepancy has led industry experts to question the ethical motivations of the attackers. Charles Guillemet, CTO of Ledger, suggested the event may have been an extortion attempt rather than a legitimate security disclosure, noting that if the remaining funds were part of a negotiated reward, it "looks more like extortion than white-hat hacking."

What's Next

The industry is now watching to see if the remaining 600 BTC will be recovered or if the actors intend to keep the funds as a "bounty." The incident serves as a warning for other sidechains and wrapped-asset protocols regarding the precarious nature of bridge security. For Liquid, the primary challenge remains restoring full confidence in the L-BTC backing and ensuring that the Elements patch has completely neutralized the vulnerability across all federation nodes.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.