Industry News

Liquid Network Bitcoin Sidechain Hit by $320M Exploit, Most Funds Returned

Crypto Briefing · 8 Sept 2026
Key Takeaway Businesses relying on blockchain or fintech platforms should confirm that vendors have independently audited their transaction validation logic, not just their key management or multisig security.

Blockstream's Liquid Network, a Bitcoin sidechain used by institutional traders, lost around 4,000 BTC (about $320 million) on September 6 after attackers exploited a flaw in its underlying Elements software. The bug, a range-proof verification cache issue, let hackers create fake Liquid Bitcoin (L-BTC) tokens that the system wrongly accepted as genuine, which were then converted into real BTC withdrawals through a partner exchange's payout system.

The attackers identified themselves as white-hat hackers and returned roughly 3,400 BTC once Blockstream confirmed the vulnerability was patched, keeping around 598 BTC (about $47 million) as a self-declared bounty. Notably, the network's multi-party security system, which requires 11 of 15 parties to approve transactions, was never compromised; the flaw was in the software validating transactions before they reached that stage. Other assets on the network, such as USDT and tokenized real-world assets, were unaffected.

Despite the partial recovery, all L-BTC activity remains suspended across exchanges with no confirmed restart date, marking a significant setback for a platform that has operated since 2018.

Summarised by CISO AI from Crypto Briefing. We link back to every original so you can read it yourself.