Industry News

Bitcoin Bridge Hack Sees $270 Million Returned, But Not All of It

The Currency Analytics · 8 Sept 2026
Key Takeaway If a platform you use has suffered a security breach, pause transactions until the provider explicitly confirms the system has been patched and is fully operational.

Blockstream's Liquid Federation wallet, which normally holds around 4,200 BTC, was almost entirely emptied after attackers exploited a bug in Elements, the open-source software underpinning the Liquid network. Roughly 4,000 BTC was taken, and the attackers, who identified themselves as white-hat hackers, later returned about 3,400 BTC after Blockstream confirmed the vulnerability had been patched. Communication with the attackers was carried out through signed messages embedded in Bitcoin transactions.

Investigators traced the root cause to a flaw in Elements itself, not to a compromised key as first suspected. Both Liquid and SideSwap confirmed that SideSwap's Peg-out Authorization Key, initially linked to the incident, was not actually compromised. This points to a software-level weakness that evaded normal review processes, rather than a key management failure.

Blockstream is now rolling out patches across the network and coordinating with federation members to ensure every node runs the updated software before restarting operations, a process complicated by an ongoing chain split resolution. In the meantime, JAN3 CEO Samson Mow has warned users not to send funds to Liquid peg-in addresses until the network is confirmed fully operational, to avoid having funds stuck with no clear recovery path.

Summarised by CISO AI from The Currency Analytics. We link back to every original so you can read it yourself.