Bitcoin Bridge Hack Sees $270 Million Returned, But Not All of It
Blockstream's Liquid Federation wallet, which normally holds around 4,200 BTC, was almost entirely emptied after attackers exploited a bug in Elements, the open-source software underpinning the Liquid network. Roughly 4,000 BTC was taken, and the attackers, who identified themselves as white-hat hackers, later returned about 3,400 BTC after Blockstream confirmed the vulnerability had been patched. Communication with the attackers was carried out through signed messages embedded in Bitcoin transactions.
Investigators traced the root cause to a flaw in Elements itself, not to a compromised key as first suspected. Both Liquid and SideSwap confirmed that SideSwap's Peg-out Authorization Key, initially linked to the incident, was not actually compromised. This points to a software-level weakness that evaded normal review processes, rather than a key management failure.
Blockstream is now rolling out patches across the network and coordinating with federation members to ensure every node runs the updated software before restarting operations, a process complicated by an ongoing chain split resolution. In the meantime, JAN3 CEO Samson Mow has warned users not to send funds to Liquid peg-in addresses until the network is confirmed fully operational, to avoid having funds stuck with no clear recovery path.