AdvertisementAdvertisementAdvertisementAdvertisement
Cryptocurrency

Around 4,000 Bitcoin Withdrawn from Liquid Network Wallet with Hack Message

9/7/2026, 11:55 AM • Evgenia Sliv

(edited: 09/07/2026)

Around 4,000 Bitcoin Withdrawn from Liquid Network Wallet with Hack Message

On September 6, unknown individuals withdrew approximately 4,000 BTC worth around $320 million from the federated wallet of the Bitcoin sidechain Liquid Network. The recipients identified themselves as "white hat hackers" and left a message in a transaction linked to the incident: "We are white hat hackers. Contact us via blockchain."

The attackers later stated their intention to return "the majority" of the funds after the vulnerability is patched. Their correspondence with Liquid's technical provider Blockstream was published by Galaxy's head of research Alex Thorn. In one message, the attackers stated: "After confirming the fix, we will transfer the money back." The specific amount to be returned was not mentioned in the public portion of the correspondence. Developers shut down bridge nodes and halted the acceptance of new transactions, and also notified exchanges of the need to suspend L-BTC deposits and withdrawals. According to the Liquid team, other network assets — USDT, DePix, and several RWAs — were not affected by the hack.

The incident was caused by a bug in the Elements software that allowed L-BTC tokens to be created without a corresponding top-up of Bitcoin reserves. These tokens were then exchanged for Bitcoin via SideSwap. Under normal conditions, a user locks Bitcoin on the main network and receives an equivalent amount of L-BTC on the sidechain. Upon reverse exchange, the tokens are burned and Bitcoin is returned from the federation's reserve wallet. During the attack, a request to swap 4,000 L-BTC was submitted to SideSwap. The service accepted the assets and initiated the standard withdrawal procedure. After the tokens were burned, the federation transferred 3,996 BTC to the recipient's Bitcoin address.

Mempool space researcher known as OrangeSurf believes the cause may be related to a bug in the caching of cryptographic verifications. About seven years ago, developers added a cache to avoid repeating resource-intensive computations. However, when accessing the cache, the asset type and spending conditions were not taken into account, which meant a new invalid operation could receive a positive result from a previously verified one. A full verification should have rejected it.

The fix had been prepared before the attack: the Elements repository already contains a change authored on August 3 and committed on September 1. However, a separate release with the fix had not yet been published at the time of the hack. OrangeSurf also noted the absence of additional controls for large withdrawals, and pointed out that despite running the unpatched version of the software, the Liquid Network node rejected the problematic transaction. The researcher additionally reported that Anthropic's Fable 5 model in GitHub Copilot identified the bug in the source code of the proposed change via a simple query.

As a reminder, in late August the Cronos network, associated with Crypto.com, suspended blockchain operations after an exploit was discovered in the Tectonic lending protocol.

***

This material is prepared for informational purposes only and does not constitute financial advice or recommendations.

Popular news