BTCETHBNBSOLXRPUSDCTRXADADOGE
Data by CoinGecko
Scam WatchBearish

Record $320M Hack Leaves Peg-Outs Frozen As Ransom Disputed

Withdrawals from a major sidechain network remain suspended after an exploit drained nearly $320 million in digital assets on September 6, 2026, marking the year's largest cryptocurrency theft.

The breach targeted a federation wallet holding roughly 4,200 Bitcoin prior to the attack. The exploit swept approximately 4,000 BTC, leaving roughly 207.275 BTC, just 5% of the initial reserve, intact in the wallet. The precise stolen sum differs across industry analyses, calculated at 4,019.4 BTC by Bitcoin Magazine and 3,998.5 BTC by tftc.io.

The theft pushes the total value of digital assets lost to exploits in 2026 to $1.73 billion across 333 incidents, surpassing the April thefts from KelpDAO ($292 million) and Drift ($285 million).

Attackers executed the drain via a software bug in the open-source Elements codebase. This vulnerability allowed the hackers to bypass the network's 11-of-15 multisig security, mint unbacked derivative tokens, and redeem them for real BTC utilizing a Peg-out Authorization Key (PAK). Block production on the sidechain resumed on September 10 following the deployment of the Elements v23.3.4 patch, though other issued assets, including USDT and DePix, were entirely unaffected by the breach.

On-Chain Ransom Dispute

Following the initial exploit at Bitcoin block 965,783, the perpetrators and network developers engaged in negotiations using PGP-encrypted text and OP_RETURN messages embedded on-chain. The hackers initially stated, "we are whitehats. contact us on chain."

Record $320M Hack Leaves Peg-Outs Frozen As Ransom Disputed
we are whitehats. contact us on chain.

After negotiations and confirmation that bridge nodes were patched, the attackers returned 3,400 BTC, representing 85% of the drained funds and valued at approximately $269.2 million to $272 million. However, as of September 17, the hackers withheld 598.50 BTC, valued at over $45 million. The attackers demanded a 10% bug bounty while criticizing the network's security allocations.

"Your dereliction of duty is obvious that you allocated $1.5M (maybe even 0) to secure $5B of assets," the attackers wrote on-chain. "This is a flagrant neglect of security and a sign of complete mismanagement. You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess."

Maintainers at Blockstream formally rejected the ransom demands and the "white-hat" classification, stating: "Taking assets without authorization and withholding their return i[s theft]"

Peg-Outs Remain Frozen

As of September 18, the network faces an unreturned funds deficit. Network displays show 4,234.76 circulating derivative tokens backed by only 3,632.23 BTC in underlying reserves.

Settlement platform SideSwap confirmed the ongoing suspension, notifying users, "L-BTC cannot yet be redeemed for bitcoin." The platform further relayed developer assurances, noting, "Blockstream has said the peg will be covered 1:1 and peg-out returns in a later step."

Blockstream founder Adam Back insisted the 1:1 asset peg will be fully covered and cautioned holders against dumping their assets over-the-counter at a discount. The broader federation, comprising over 80 financial firms, brokers, and exchanges, continues to await full withdrawal restoration as the standoff over the final 15% of the funds persists.

← All stories