Industry News

Liquid Network Resumes After $320M Bitcoin Exploit, Hacker Demands Bounty for Remaining Funds

Cryptopolitan · 11 Sept 2026
Key Takeaway Businesses holding or transacting in L-BTC or Liquid-based stablecoins should pause related transfers, watch for official Blockstream updates, and treat any funds tied to the network as at risk until reserves and patches are fully verified.

Blockstream's Liquid sidechain resumed block production on Thursday, four days after someone claiming to be a white hat hacker exploited a flaw in the network's Elements software to withdraw close to 4,000 BTC (roughly $320 million) from its federation wallet. The vulnerability allowed the creation of invalid Liquid Bitcoin (L-BTC) that could be redeemed as if it were fully backed, effectively letting the attacker mint and cash out funds that didn't legitimately exist.

Blockstream released an emergency patch, Elements v23.3.4, hardening the verification process that was exploited. After confirming the patch was live, the attacker returned about 3,400 BTC, but roughly 598.5 BTC (around $46 to $47 million) remains outstanding. Peg operations, which let users move Bitcoin in and out of the Liquid network, are currently suspended while reserves are rebuilt, and blocks are being produced without transactions as a precaution.

The anonymous actor has since publicly criticised Blockstream's security spending and demanded a 10% bug bounty be paid from company funds, threatening that the remaining coins will not be returned otherwise and warning of losses to token holders if the demand isn't met.

Key Takeaway: Businesses holding or transacting in L-BTC or Liquid-based stablecoins should pause related transfers, watch for official Blockstream updates, and treat any funds tied to the network as at risk until reserves and patches are fully verified.

Summarised by CISO AI from Cryptopolitan. We link back to every original so you can read it yourself.