TechNewsReel
Live

White-Hat Hackers Drain $320 Million From Liquid Network, Retain $47 Million Reward

A critical software bug in the Bitcoin sidechain allowed attackers to create unbacked tokens and withdraw thousands of BTC from the federation reserve.

TechNewsReel Newsroom · September 7, 2026

Purported white-hat hackers exploited a critical software vulnerability in the Liquid Network to withdraw approximately 4,000 BTC from the federation's reserve. The exploit, which targeted the sidechain's peg-out mechanism, resulted in the temporary removal of roughly $320 million in assets.

The attackers utilized a node-level software bug within 'Elements' to create approximately 4,000 unbacked Liquid Bitcoin (L-BTC). These synthetic tokens were then processed through the SideSwap peg-out service, allowing the hackers to withdraw actual Bitcoin from the federation's multisig wallet. Following the exploit, the attackers contacted Blockstream via PGP-encrypted messages sent through on-chain Bitcoin transactions. They demanded a software patch before returning the funds, stating, "Please fix the bug first. The chain is under risk at latest commit right now," according to CoinDesk.

The Sidechain Model

Liquid is a Bitcoin sidechain developed by Blockstream and operated by a federation of more than 80 members. The network is designed to facilitate faster and more private transactions by issuing L-BTC, which are intended to be backed 1:1 by Bitcoin locked in a federation-controlled multisig wallet. In this instance, the security failure did not stem from compromised private keys, but from a flaw in the underlying code that allowed the creation of tokens without the necessary collateral.

Implications for Decentralization

The incident has sparked a debate over the security and transparency of sidechain models. Because a software bug could enable the theft of the entire reserve, some critics argue the system relies on "decentralization theater." Bitcoin Core contributor Michael Folkson highlighted this risk to Gizmodo, noting that the ability for a developer to push specific code can override the perceived security of multisig signing.

Current Status

Once the vulnerability was patched, the attackers returned 3,400 BTC to the federation. They retained 598.5 BTC, valued at approximately $47 million, as a reward for their discovery. While the majority of the funds have been recovered, the exploit raises significant questions about whether exchanges and institutional users can continue to rely on Liquid for secure settlement.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.