TechNewsReel
Live

Liquid Network recovers $270 million after software flaw drains Bitcoin reserves

Purported white-hat hackers returned the majority of stolen funds, but roughly 600 BTC remains missing following a structural breach.

TechNewsReel Newsroom · September 8, 2026

The Liquid Network has recovered the bulk of its reserves after a software vulnerability allowed attackers to drain approximately 4,000 BTC from the federation wallet. The breach, which totaled roughly $320 million, has left the sidechain grappling with a remaining loss of about $47 million.

According to reports from Decrypt and The Currency Analytics, the attackers—described as purported white-hat hackers—returned 3,400 BTC (approximately $270 million) to the federation address at Bitcoin block 965,950. Despite this partial recovery, the attackers retained roughly 600 BTC. To contain the breach, the network disabled bridge nodes and halted all L-BTC transactions while preparing for a system restart.

The Mechanics of the Breach

The incident did not stem from a compromise of private keys, but rather a structural software flaw within the L-BTC issuance and redemption process. This vulnerability allowed the attackers to create unbacked L-BTC, which they then used to trigger a "peg-out" process, effectively draining the actual Bitcoin reserves held by the federation.

Liquid operates as a Bitcoin sidechain utilizing a federated peg to maintain a 1:1 relationship between L-BTC and native Bitcoin. In standard operation, L-BTC is only issued when an equivalent amount of BTC is locked in the federation's reserves. By bypassing this requirement through a software exploit, the attackers were able to withdraw native BTC that they had not legitimately deposited.

Industry Implications

This breach underscores a persistent and critical vulnerability in federated peg mechanisms and cross-chain bridges. These architectural components have historically served as the weakest links in decentralized finance (DeFi) and sidechain ecosystems. Because the exploit targeted a structural flaw rather than a security lapse like a leaked key, it suggests a deeper architectural issue that could undermine user trust in the network's operational integrity and the guaranteed 1:1 backing of its assets.

Next Steps

As the network prepares for a restart, the industry is watching to see if the remaining 600 BTC will be returned or if the attackers intend to keep the funds as a reward for exposing the flaw. While the majority of the funds are secure, the event serves as a stark reminder of the risks inherent in centralized federation models for asset bridging. Further technical post-mortems are expected to determine if similar vulnerabilities exist in other Bitcoin-pegged assets.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.