Liquid Network Bitcoin Heist Leaves $47M Missing

NewsLiquid Network Bitcoin Heist Leaves $47M Missing

The Liquid Network Bitcoin heist ended with most of the money coming back, but not all of it. An attacker withdrew 3,996 BTC, worth about $319 million to $320 million at the time, then returned 3,400 BTC after Blockstream patched the underlying software flaw. As of September 9, 2026, the remaining 598.5 BTC, valued at roughly $47 million, had not been recovered.

That incomplete refund has complicated the attacker’s claim to be a helpful security researcher. Returning hundreds of millions of dollars is certainly preferable to keeping the lot. Holding onto another $47 million without a publicly confirmed agreement is a less conventional form of public service.

How did the attacker remove nearly all of Liquid’s Bitcoin?

Blockstream launched Liquid Network in 2018 as a Bitcoin settlement system used by cryptocurrency exchanges and financial institutions. Users can move Bitcoin into the network and receive L-BTC, which can later be redeemed for Bitcoin through its bridge.

According to The Block, the attacker exploited a bug in Elements, the software underpinning Liquid, to create unbacked L-BTC. They then used SideSwap’s legitimate peg-out process to exchange those tokens for 3,996 real BTC.

SideSwap said its own systems and authorization key were not compromised. In other words, the withdrawal mechanism worked as designed. The assets entering it were the problem.

Most read

  1. CelebrityVinnie Jones and Emma Ford Step Out in London
  2. CelebrityTheo James Punctures Meghan Markle Casting Rumors
  3. CelebrityErika Eleniak’s OnlyFans Pulls In $10K a Week

The stolen amount represented roughly 95% of Liquid’s reserves, which stood at about 4,200 BTC. That temporarily left L-BTC holders unable to redeem their tokens for the Bitcoin meant to back them, turning what might sound like an abstract software flaw into a direct solvency and redemption problem.

TRM Labs classified the incident as the largest cryptocurrency theft of 2026 so far. Some initial reports valued the withdrawal at approximately $340 million, although several later accounts placed it closer to $320 million based on Bitcoin’s price at the time.

Why is the attacker being called a white hat?

The attacker opened communications through a blockchain message reading: “we are whitehats. contact us on chain.” Blockstream later replied through the same channel: “Bridge nodes are patched, safe to return the funds.”

On September 7, former Blockstream executive Samson Mow said the vulnerability had been fixed and about 3,400 BTC had been returned. The Block, TechCrunch and The Hacker News separately corroborated that repayment through the on-chain messages and transactions.

What remains unclear is whether anyone authorized the attacker to keep the balance as a reward. Neither Liquid nor Blockstream had publicly confirmed such an agreement by September 9, according to The Hacker News. Decrypt reported that Blockstream was still negotiating to recover the outstanding Bitcoin.

Ledger chief technology officer Charles Guillemet rejected the friendly label outright. “The ‘white hats’ still hold 600 BTC,” he wrote, arguing that any undisclosed arrangement allowing the attacker to retain the money would look more like extortion than responsible security research.

That distinction matters. White-hat researchers usually seek permission, disclose flaws responsibly or negotiate a documented bounty. Removing nearly an entire reserve and deciding afterward how much to return rather stretches the job description.

When will Liquid Network fully restart?

Liquid paused operations while Blockstream investigated the breach and prepared security changes. The Hacker News reported that updated software had been deployed and federation members were preparing a coordinated restart.

Still, no outlet had confirmed a complete restart by September 9. Liquid’s status page continued to show an active bridge outage on September 8, and there was no verified return of the remaining 598.5 BTC.

Before reopening the affected systems, Blockstream and Liquid were expected to introduce further fixes and security improvements. The immediate software vulnerability may be closed, but the incident also exposed the danger of concentrating nearly all backing reserves behind a bridge that can be drained through one upstream flaw.

For users, the important question is not simply whether the network resumes producing transactions. It is whether redemptions can proceed normally, reserves remain adequate and the outstanding Bitcoin is recovered. A green status indicator would be welcome, but it would not make $47 million reappear.

How does the theft compare with other 2026 attacks?

The Liquid breach is part of a particularly expensive run of cryptocurrency security failures, though its partial reversal makes it unusual.

A Coldcard hardware wallet attack initially drew attention after thieves took 594 BTC from about 500 wallets in just 25 minutes by exploiting a flaw affecting certain Mk3 devices. Later reporting showed the campaign was much larger. Fortune documented four theft waves affecting more than 5,200 addresses, while Self Custody Labs counted about 1,816 BTC, worth roughly $116 million, stolen between July 30 and August 4.

Another theft followed a mistake by South Korean authorities. Officials seized nearly $5 million in cryptocurrency from a suspected money launderer, then exposed the wallet’s recovery phrase in evidence photographs. Someone used the phrase to remove about $4.8 million. Digital assets are secure, provided nobody publishes the password.

Liquid’s attacker at least returned the majority of the funds. The unresolved 598.5 BTC now determines whether the episode is remembered as an aggressive vulnerability disclosure, a negotiated bounty or a very large theft followed by a substantial partial refund.

Tags:
liquid network bitcoin heistblockstreambitcoin securitycrypto theft

About The Hook Editorial Team

Editorial Team

The Hook Editorial Team delivers daily news reporting and analysis.