Liquid Network Exploit Drains $320M in BTC, 85% Returned

By Blockchain News | Created at 2026-09-09 22:47:06 | Updated at 2026-09-09 23:26:56 1 hour ago

Lawrence Jengar Sep 09, 2026 22:23

Hackers exploited a Liquid Network bug to steal $320M in BTC, returning 85%. The incident reveals risks in blockchain-based financial layers.

Liquid Network Exploit Drains $320M in BTC, 85% Returned

A critical software vulnerability in Liquid Network allowed hackers to siphon off nearly 4,000 BTC, worth $320 million at the time, before returning 85% of the stolen funds. The exploit, which occurred on September 6, targeted flaws in the Bitcoin sidechain’s transaction validation mechanisms, underscoring risks in blockchain-based financial infrastructure.

The attack hinged on Liquid’s Confidential Transactions system, which uses cryptographic proofs to validate transfers while keeping transaction amounts hidden. A flaw in the caching mechanism for these proofs enabled the attackers to create unbacked L-BTC tokens, which they then swapped for actual BTC from Liquid's reserve. Approximately 3,998 BTC—95% of Liquid’s federation wallet—was drained before the network was paused.

Liquid Network, developed by Blockstream, is intended to provide fast, low-cost, and private Bitcoin transactions using L-BTC, a token pegged 1:1 to BTC. Under normal conditions, users must deposit BTC into Liquid’s network to mint L-BTC. However, the exploit bypassed this requirement, allowing hackers to mint tokens without collateral and “withdraw” real BTC.

After the breach, the attackers, claiming to be white-hat hackers, communicated with Blockstream via Bitcoin’s OP_RETURN field. They pledged to return the stolen funds once the vulnerability was patched. On September 7, Blockstream confirmed the exploit was fixed, and the attackers returned 3,400 BTC in a single transaction. However, they kept nearly 600 BTC, worth roughly $47 million at Bitcoin’s current price of $77,872.

Blockstream has not clarified whether the retained BTC constitutes a bounty or if further negotiations are ongoing. As of September 9, Liquid Network remains paused, with a restart pending additional security measures.

Market and Security Implications

The exploit highlights vulnerabilities in blockchain infrastructure beyond the base layer. While Bitcoin’s core protocol remains secure, sidechains like Liquid introduce new attack vectors. With institutional adoption of such solutions growing, this incident serves as a cautionary tale for assessing the security of auxiliary systems like bridges, sidechains, and custodial platforms.

Bitcoin’s price showed little reaction to the breach, trading at $77,872 on September 9, down 0.8% over 24 hours. The muted market response reflects the isolated nature of the incident, as it did not compromise Bitcoin’s underlying network.

For traders and institutions, the case underscores the importance of due diligence when using Layer-2 solutions or sidechains. The ability of the attackers to exploit Liquid’s validation process without impacting Bitcoin itself demonstrates how even well-established systems can harbor critical flaws.

Next Steps for Liquid and Blockstream

Blockstream has deployed updated software to address the vulnerability and is preparing Liquid Network for a secure restart. Going forward, the company and the Liquid Federation will likely face increased scrutiny over their security practices, particularly around cryptographic validation systems like Confidential Transactions.

This incident is a reminder that no system is entirely risk-free. As crypto ecosystems expand, ensuring robust safeguards in every layer of the stack will be essential to maintaining trust and preventing similar exploits.

Image source: Shutterstock

Read Entire Article