Threat Intelligence

Liquid Network Hackers Return Most of $320M in Bitcoin After Elements Bug Exploit

The Hacker News · 9 Sept 2026
Key Takeaway Businesses relying on blockchain bridges or sidechains should ensure vendors have clear, tested incident response and patching processes, since a single software bug can put large sums at risk almost instantly.

A hacker or group of hackers claiming to be white hats exploited a bug in Elements, the software behind Bitcoin sidechain Liquid Network, to withdraw nearly 4,000 bitcoin (roughly $320 million) from the network's federation wallet on September 6. The withdrawal drained about 95% of Liquid's reported bitcoin reserves and forced the network to pause, leaving holders of its L-BTC token unable to convert it back to real bitcoin.

The following day, 3,400 bitcoin (about $265 million) was sent back to a Liquid Federation address, roughly 85% of the amount taken. The remaining 598.5 bitcoin (about $47 million) is described as change from the same transaction and has not been returned as of September 8. Blockstream, which provides Liquid's underlying technology, said the funds were moved using SideSwap's Peg-out Authorization Key, but confirmed that key and others were not compromised. Instead, the bug in Elements allowed the attacker to create L-BTC that could then be redeemed for real bitcoin.

Communication between the parties reportedly took place directly on the Bitcoin blockchain, with the attackers asking that the flaw be fixed and all nodes patched before returning funds. Blockstream responded with a signed message confirming its bridge nodes had been patched. Neither party has publicly confirmed whether the remaining bitcoin is part of any agreement.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.