Bitcoin Sidechain Drained of $320M in Code Exploit
A software flaw in Blockstream's Liquid Network allowed attackers to drain roughly 4,000 BTC, worth approximately $320 million, on September 6, making it one of the largest security incidents to hit Bitcoin infrastructure this year. The exploit reduced the federation's reserves from more than 4,200 BTC to around 197 BTC within hours.
Liquid Network, a Bitcoin sidechain launched in 2018 for faster institutional settlement, is overseen by a federation of more than 80 exchanges and asset managers. The breach targeted the network's core trust model, with attackers extracting roughly 4,000 of the 4,200 Bitcoin held in the federation wallet, according to Blockstream and CoinDesk reporting.
The network halted new transactions immediately after the drain, warning users that wallets would be affected while the team worked on a fix. All L-BTC activity remains suspended across exchanges with no public timeline for resuming normal service.
White-Hat Claims and Partial Return
In an unusual development, the attackers identified themselves as white-hat hackers and communicated with Liquid maintainers through onchain Bitcoin messages. One message stated: "Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix."
After Blockstream confirmed the vulnerability had been patched, the hackers returned around 3,400 BTC but kept approximately 598 BTC, worth roughly $47 million, as a self-appointed bounty. The network's reserves now sit at roughly 3,600 BTC, still short by the retained amount.

Technical Root Cause
The exploit originated in Elements software, the open-source codebase underlying Liquid Network. A range-proof verification cache bug allowed attackers to mint invalid L-BTC tokens that the system mistakenly treated as legitimate. Those fraudulent tokens then moved through SideSwap's Peg-out Authorization Key, converting them into genuine BTC withdrawals from the federation wallet.
SideSwap later indicated it had no way to distinguish the fraudulent tokens from real ones at the time, processing them like any legitimate peg-out request. The trusted platform operated exactly as designed, fed incorrect data by a flawed validation layer.
Critically, no federation signing keys were compromised. Liquid runs on an 11-of-15 federation multisig requiring eleven of fifteen designated entities to approve transactions. The multisig functioned properly throughout the incident, the failure occurred upstream in the software validating what reached the multisig.
Other assets on the network, including USDT and tokenized real-world assets, were unaffected since the bug was specific to L-BTC token validation. However, the Elements vulnerability also exists in code used by other projects, requiring industry-wide audits of range-proof verification logic.
The legal status of keeping $47 million as an unsolicited bounty remains unresolved, sitting in a gray zone between responsible disclosure and theft with partial restitution.


