Hackers withdrew about 4,000 BTC from the wallet that backs Liquid Network, a Bitcoin sidechain used by exchanges and other financial institutions. Liquid said the attackers used SideSwap through its Peg-out Authorization Key system, but said no SideSwap key or other PAK appeared to be compromised. Liquid disabled bridge nodes and asked exchanges to halt L-BTC deposits and withdrawals while it investigates the vulnerability and patches nodes.
Why it matters: This is a major live crypto security incident affecting a network used to move Bitcoin-backed assets, with immediate risk to exchanges and users handling L-BTC. Anyone operating Liquid infrastructure or supporting Liquid assets should follow vendor guidance, pause affected activity where advised, and wait for confirmed remediation before resuming transfers.
2026.09.08
99% relevant
This is a direct update on the same Liquid Network theft, adding that Blockstream deployed updated software, the attackers returned about $266.5 million, kept 598.5 BTC worth about $47 million as a claimed bug bounty, and SideSwap’s post-mortem points to a vulnerability in Elements software as the likely source.
Ionut Arghire
2026.09.08
98% relevant
This article directly updates the same Liquid Network theft by reporting that 3,400 of the 4,000 stolen Bitcoin have been returned, about 598 Bitcoin remain outstanding, and the network is still paused while Blockstream and federation members apply fixes and resolve a chain split.
info@thehackernews.com (The Hacker News)
2026.09.08
97% relevant
This is a direct update on the same Liquid Network theft event, adding that attackers returned 3,400 BTC after the Elements bug was fixed while still retaining about $47 million in bitcoin.
2026.09.07
100% relevant
This article appears to be the first tracked report here of the specific exploit that drained Liquid Network’s federation wallet and triggered emergency suspension of bridge activity and exchange transfers.
← Back to all stories