The $320 Million Question
Sunday, September 6, 2026, started like any other day in crypto. By the time it ended, Liquid Network, Blockstream’s flagship Bitcoin sidechain, had lost nearly 4,000 BTC from its federation wallet. That’s roughly $320 million at current prices. The attackers didn’t steal private keys. They didn’t break through firewalls. They found something far more insidious: a bug in the open-source Elements software that let them mint 4,000 unbacked LBTC tokens out of thin air.
Here’s the part that keeps me up at night. The withdrawal went through SideSwap, a Liquid Federation member operating a legitimate peg-out service. The system’s transaction checks accepted the counterfeit tokens as valid. The Hardware Security Modules signed off. The money moved. It wasn’t a hack in the traditional sense, it was a exploit of trust itself. Unreal!
In my opinion, a layer 2 chain, based on Bitcoin or anything else is not secure enough, therefore, I never use to store of value…
“We Are Whitehats”
Then came the note. Embedded in the Bitcoin blockchain’s OP_RETURN data field, the attackers left a message: “we are whitehats. contact us on chain”. They claimed to be ethical security researchers. They said they’d return the money, but only after Blockstream patched the vulnerability.
But, a message implying “we’re the good guys” is rarely the whole story. But this time, something unusual happened. Blockstream responded through a PGP-signed OP_RETURN message: bridge nodes were patched, funds could safely be returned. The attackers followed through, 3,400 BTC, roughly $270 million, flowed back to the federation wallet.
That’s where the fairy tale ends.,
The $47 Million Disagreement
About 600 BTC, worth roughly $47 million, remains in the attackers’ hands. Blockstream says negotiations are ongoing. The attackers call it a bounty. Ledger’s Chief Technology Officer Charles Guillemet calls it something else: “If this was ever a negotiated reward under an encrypted contract signed on-chain, it looks more like extortion than white-hat hacking!”
I think Guillemet is onto something. White hats disclose flaws before moving hundreds of millions in collateral. They don’t drain a bridge and then solicit an “on-chain” contact. The distinction matters, not just for this incident, but for how the entire industry thinks about vulnerability disclosure.
But on the other hand , 600 BTC is 15% of 4000 BTC, the so called “white hats” may be thinking this is only fair. Obviously Blockstream disagree, Wouldn’t you?, I personally do not think is the amount but the protocol used.
What This Means for Bitcoin’s Layer 2 Future
The Liquid Network was designed to speed up Bitcoin settlements for exchanges, with LBTC backed 1:1 by Bitcoin held in a multisig wallet controlled by 15 federation members. Before the hack, reserves held over 4,200 BTC. Afterward? Just over 200 BTC. That’s a 95% drawdown in a single transaction.
The Elements bug at the heart of this exploit, a range-proof verification cache issue that allowed two different validation inputs to produce the same cached entry, has since been patched. An emergency update, Elements v23.3.4, is now available. But the damage to confidence is harder to fix.
In my experience, incidents like this reveal a fundamental tension in crypto: the trade-off between innovation and security. Liquid’s federated model was supposed to be more resilient than purely decentralized systems. Fifteen signatories, requiring 11 signatures to move funds. Yet a single software bug bypassed all of that.
Why? Admin keys… The funfamental flaw of any Layer 2 blockchain.
The Bigger Picture
Bitcoin’s price barely moved, trading around $80,000 throughout. The market shrugged. But that doesn’t mean this isn’t important. The real impact is on L-BTC liquidity and the institutions that depend on Liquid Network’s settlement layer.
Samson Mow, Blockstream’s former CSO, has been providing updates: “No user action is needed, and please do not send Bitcoin to Liquid peg-in addresses until we confirm the network has restarted”. The network remains paused.
I tried to use the service for testing using Aqua Wallet as I write this article and the app says “Something Went Wrong Swap Creation is Temporary Disabled”, so issues are still current after 3 days,
Blockstream and the Liquid Federation are working to resolve the chain split and ensure L-BTC is fully backed before restarting the network. But trust, once broken, takes longer to rebuild than any software patch.
Summary
- On September 6, 2026, attackers exploited an Elements software bug to mint 4,000 unbacked LBTC and redeem them for ~4,000 BTC ($320M) from Liquid Network’s federation wallet
- The attackers left an on-chain message claiming to be white hats and offered to return funds after Blockstream patched the vulnerability
- Blockstream patched bridge nodes; attackers returned 3,400 BTC (~$270M) on September 7
- ~598.5 BTC (~$47M) remains outstanding; Blockstream is in ongoing negotiations
- Ledger CTO Charles Guillemet and others have questioned the attackers’ white-hat claims
- The network remains paused; an emergency Elements update (v23.3.4) has been released
- Bitcoin’s price remained stable around $80,000, but confidence in Liquid’s 1:1 backing model has been shaken
Comments
Please login to comment
Login