Industry News

Blockstream's Liquid Network Hit by $320M Bug Exploit, Attackers Claim 'White Hat' Intentions

Decrypt · 7 Sept 2026
Key Takeaway Businesses relying on blockchain bridges or sidechains should treat any pause or unusual withdrawal announcement as a signal to halt related transactions immediately and wait for official verified guidance before resuming activity.

Blockstream's Liquid sidechain has been paused after about 4,000 BTC (around $320 million) left the federation wallet backing all L-BTC in circulation. Liquid said no federation keys were compromised; instead, a bug in the underlying Elements software allowed someone to create L-BTC that wasn't actually backed by real bitcoin, then redeem it through what looked like a normal withdrawal via SideSwap, a federation member's peg-out service.

The attackers left an on-chain message identifying themselves as 'white hats' and later offered to return most of the funds, but only on the condition that Blockstream patch the bug and update every node first, since the network remains vulnerable at its current software version. Blockstream reportedly agreed. However, security figures including Ledger's Charles Guillemet have pushed back on the 'white hat' framing, arguing that genuine ethical hackers don't drain funds first and attach conditions afterward, comparing the incident to past bridge hacks like Ronin and Euler.

The wallet held around 4,200 BTC before the incident and about 200 BTC afterward, meaning the vast majority of backing funds are currently in the attackers' hands pending resolution.

Key Takeaway: Businesses relying on blockchain bridges or sidechains should treat any pause or unusual withdrawal announcement as a signal to halt related transactions immediately and wait for official verified guidance before resuming activity.

Summarised by CISO AI from Decrypt. We link back to every original so you can read it yourself.