NewsCryptoLiquid Network Hack Drains Roughly USD 320 Million in BTC From Blockstream's Bitcoin Sidechain

Liquid Network Hack Drains Roughly USD 320 Million in BTC From Blockstream's Bitcoin Sidechain

Author: Crypto Valley Journal·

Key Takeaways

  • •A flaw in the Elements node's rangeproof cache let attackers mint L-BTC without backing and withdraw roughly 4,000 BTC, about USD 320 million, from the Liquid Network on 6 September 2026.
  • •A fix for the exploited bug was committed by a Blockstream developer on 3 August 2026 but had not shipped in production release 23.3.3 before the attack.
  • •Blockstream and network operators halted bridge nodes and instructed exchanges, including users such as Bitfinex, BTSE, and BitMEX, to pause L-BTC deposits and withdrawals.
  • •The alleged attackers contacted Blockstream on-chain, claiming to be whitehats and offering to return most funds after the flaw is patched, though Ledger's CTO questioned the whitehat framing.
  • •The exploit brings reported 2026 cryptocurrency hack losses to nearly USD 1.5 billion, ranking among the largest exploits on record.
Liquid Network Hack Drains Roughly USD 320 Million in BTC From Blockstream's Bitcoin Sidechain

A hack of the Liquid Network drained roughly 4,000 BTC, worth about USD 320 million, from Blockstream's Bitcoin sidechain. The alleged attackers have since offered to return most of the funds, on the condition that the network first patches the exploited flaw.

Liquid is a sidechain to Bitcoin. Exchanges and trading platforms use it to move BTC between each other quickly and confidentially, avoiding the slower and more expensive Bitcoin mainchain. Users first lock Bitcoin in a federation wallet and receive the token L-BTC on a 1:1 basis in return. That design differs from Bitcoin itself: instead of proof-of-work consensus, a federated group of companies collectively controls the bridge between the two networks, which makes the peg's integrity dependent on both the honesty and the software correctness of that group. Blockstream Corp originally launched Liquid in 2018; the company was co-founded by Adam Back. According to Blockstream, the federation includes more than 80 companies, with fifteen functionaries authorizing payouts through an 11-of-15 multisig.

On 6 September 2026, roughly 4,000 of the approximately 4,200 BTC previously held in that reserve left the network, leaving around 197 BTC behind. The transactions ran through SideSwap, a settlement platform authorized for peg-outs. According to the Liquid Network, SideSwap's key remained intact.

A software bug enabled the attack

The attackers did not steal a key. Preliminary technical analyses instead point to a flaw in the Elements node, the software behind the sidechain. The affected component is specifically the rangeproof cache, which the network uses for confidential transactions. As a result, attackers were able to create L-BTC without any locked Bitcoin backing it. During the peg-out, the federation only checked whether the payout address was authorized; it never verified the backing of the submitted L-BTC. The 15 functionaries hold the keys in dedicated HSM hardware and also validate the sidechain's blocks.

A patch apparently already existed. On 3 August 2026, a Blockstream developer committed "fix: range proof cache bind to asset and scriptpubkey." However, the change only reached the release branch after the incident, meaning release 23.3.3 — the version running in production — did not contain it. The gap between the fix being committed and being deployed underscores a broader operational challenge for federated networks: security depends not only on discovering flaws but on every functionary upgrading in time.

Block explorers offered an early signal as well. Blockstream's own Liquid explorer accepted the block in question, 4,050,336, while the independent service mempool.space rejected it. Consequently, SideSwap could not see where the coins came from; the service said it had no way to distinguish these coins from ordinary L-BTC.

At the block level, the payout request arrived at 14:06 UTC. Roughly twenty minutes later, the federation paid out on the Bitcoin mainchain. The exact sum varies depending on the measurement point: the peg-out covered roughly 3,996 BTC, while the federation's payout including fees ultimately came to around 4,019 BTC. Custody security does not cover the layer this incident hits — the keys stayed intact. What failed was the code.

Blockstream halts the Liquid Network temporarily

The network responded with a stop. Operators disabled the bridge nodes so that no new transactions can enter, and exchanges received instructions at the same time to pause L-BTC deposits and withdrawals. Other assets issued on Liquid, among them Tether and the Brazilian DePix, are said to be unaffected.

"Liquid wallets will be affected, and we apologize for any inconvenience." — Liquid Network, official statement

The reach of the halt follows from the user base: the federation counts more than 80 exchanges, infrastructure firms, and asset managers. Blockstream lists Bitfinex and BTSE as users, as well as BitMEX, which closes in September 2026. Bitfinex notably shares its parent company with Tether. These firms use the sidechain for fast settlement, because transfers on the Bitcoin mainchain take longer and cost more. Public statements from the named exchanges were not yet available, however.

Blockstream itself held back. Neither the company nor co-founder Adam Back had commented on the outflow on X by press time, leaving the network account and SideSwap as the main public voices.

Alleged attackers signal a partial return

Those responsible surfaced on-chain. "we are whitehats. contact us on chain," read a message they embedded in a transaction. A day later came the offer to return most of the funds once developers fix the flaw: first the developers should patch the bug and update every node, after which the attackers would transfer the money back safely. Blockstream replied on-chain as well and pointed the other side to security@blockstream.com.

Doubts about that self-description came from the industry. Ledger CTO Charles Guillemet noted publicly that serious security researchers usually report a vulnerability before moving reserves of this size. The objection lands: anyone who drains 95% of a reserve and paralyzes a network is negotiating from a position of strength that a regular disclosure would never have created.

The incident joins an expensive year of hacks

The scale also stands out in the annual comparison. According to TRM Labs, hack losses in 2026 added up to roughly USD 1.2 billion across 276 incidents before the Liquid outflow. Until then, the third-largest single case of the year was the attack on Coldcard hardware wallets in late July, which drained roughly USD 116 million — about 1,816 BTC — from more than 5,200 addresses. In late August, an exploit also hit the Cronos lending platform Tectonic. The attacker inflated the price of the Tonic token roughly 300-fold within 20 minutes, allowing them to borrow more than USD 74 million and ultimately take around USD 6 million net. The Cronos validators then froze trading. With the Liquid outflow, 2026's reported losses now approach USD 1.5 billion, and the case is set to rank among the largest cryptocurrency exploits on record — comparable in scale to major bridge hacks of previous years such as Ronin and Wormhole. The outcome of the attackers' return offer, the pace of the Elements patch deployment across federation nodes, and the eventual resumption of L-BTC deposits and withdrawals are the key open questions for the network's users in the days ahead.