Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
3 clusters · 70 sources · 5 days · First seen · Last updated
Liquid Network exploit and fund recovery
Overview
The Liquid Network, a Bitcoin sidechain developed by Blockstream, suffered a major security exploit on September 6, 2026, caused by a software bug in its underlying Elements technology. A vulnerability in range proof verification caching allowed for the creation of approximately 4,000 unbacked L-BTC tokens, which were used to withdraw roughly 4,000 BTC (valued at approximately $320 million) from the federation wallet via the peg-out mechanism.
Following the application of a security patch demanded by the attackers—who identified as ‘whitehats’—3,400 BTC was returned to the Liquid Federation wallet. Blockstream confirmed that core multisignature keys were not compromised and the issue was strictly a software verification failure. Approximately 598.5 BTC, valued at roughly $47 million, remains outstanding as negotiations continue.
As of September 10, 2026, the Liquid Network has resumed block production after functionary nodes resumed signing and validating blocks following necessary software updates. However, the network is currently operating “without transactions” to allow developers to monitor stability. Transactions and BTC peg operations, including the ability to move funds between Bitcoin and Liquid or utilize Peg-out Authorization Keys (PAKs), remain suspended.
Negotiations between the attackers and Blockstream have shifted from encrypted communications to public plaintext messages. The attackers are reportedly demanding a 10% bug bounty to be paid from Blockstream’s own funds in exchange for the remaining assets. Blockstream CEO Adam Back has stated that the company will compensate for the damages if necessary, while continuing to communicate via encrypted, PGP-signed notes. Liquid has not yet provided a specific date for the full reopening of transaction and bridge systems as work continues to restore the reserves supporting L-BTC.
Entities
Blockstream · Elements · Bitcoin · Liquid Network · SideSwap
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 8 SOURCES] The Liquid Network suffered an exploit resulting in the theft of approximately 4,000 Bitcoin. t3n.de · bitcoinethereumnews.com · crypto-times.jp · blockcast.cc · www.ad-hoc-news.de · +3 more
- [● 6 SOURCES] Blockstream patched the software vulnerability and confirmed the recovery of 3,400 Bitcoin. bitcoinethereumnews.com · crypto-times.jp · blockcast.cc · www.blocktempo.com · securityaffairs.com · +1 more
- [● 5 SOURCES] Approximately 598.5 Bitcoin remains outstanding following the return of 3,400 Bitcoin. bitcoinethereumnews.com · blockcast.cc · www.blocktempo.com · securityaffairs.com · thanhnien.vn
- [● 4 SOURCES] The exploit was caused by a software bug in the Elements codebase related to range proof verification caching. bitcoinethereumnews.com · blockcast.cc · www.blocktempo.com · securityaffairs.com
- [● 4 SOURCES] The attackers identified themselves as white-hat hackers and negotiated via on-chain messages. t3n.de · blockcast.cc · www.blocktempo.com · thanhnien.vn
- [● 3 SOURCES] The attackers used SideSwap’s peg-out authorization to convert unbacked L-BTC into real Bitcoin. bitcoinethereumnews.com · www.blocktempo.com · securityaffairs.com
- [● 2 SOURCES] The return of funds occurred after Blockstream confirmed that bridge nodes had been patched. www.blocktempo.com · securityaffairs.com
- [● 2 SOURCES] The core multisignature keys securing the federation wallet were not compromised during the attack. blockcast.cc · securityaffairs.com
Timeline
-
about 18 hours ago
[TECHNOLOGY] 10 sourcesLiquid Network resumes block production after $320M Bitcoin exploitLiquid Network has resumed block production following a $320M Bitcoin exploit, though transactions and peg operations remain suspended while developers monitor for stability and negotiate with attackers.
-
3 days ago
[TECHNOLOGY] 12 sourcesLiquid Network exploit results in theft of 4,000 BitcoinAttackers exploited a software bug in the Liquid Network to drain 4,000 Bitcoin. After Blockstream patched the vulnerability, the hackers returned 3,400 BTC, leaving approximately 598 BTC outstanding.
-
5 days ago
[TECHNOLOGY] 59 sourcesLiquid Network recovers 85% of $320M Bitcoin stolen in exploitLiquid Network recovered 85% of 4,000 BTC ($270M) stolen in a software bug exploit after negotiating with self-described white-hat hackers. Approximately 600 BTC remains outstanding.
Sources
ad-hoc-news.de · ambcrypto.com · americanbazaaronline.com · bitcoin.fr · bitcoinbasis.de · bitcoinethereumnews.com · bitcoinke.io · bitnewsbot.com · bizblog.spidersweb.pl · block-builders.de · blocktempo.com · brasilemfolhas.com.br · btc-echo.de · cnbce.com · coinchoice.net · coindeskjapan.com · coindoo.com · coinedition.com · coinpedia.org · cointelegraph.com · cointrust.com · criptotendencias.com · cryps.pl · crypto-times.jp · crypto.news · cryptobreaking.com · cryptobriefing.com · cryptonews.com.au · cryptoninjas.net · cryptopolitan.com · cryptoslate.com · cybernoz.com · decrypt.co · detlionblood32.wordpress.com · dijitaliyidir.com · doviz.com · economytoday.sigmalive.com · equasis.org · fakt.pl · finanzasdigital.com · finex.cz · generation-nt.com · guiadoinvestidor.com.br · infomoney.com.br · it-boltwise.de · kurzy.cz · leo.bo · memeburn.com
This summary has been updated 3 times: see revision history