Liquid Network Drains $320M in Bitcoin as Hackers Demand Bug Fix

Liquid Network drained of $320M in Bitcoin. Hackers demand a bug fix before returning funds, suspending transactions across the federation.

Liquid Network Drains $320M in Bitcoin as Hackers Demand Bug Fix

Blockstream’s Liquid Network suffered a massive security breach on September 6, 2026, that drained approximately $320 million in Bitcoin from its federation wallet. This incident removes roughly 95 percent of the wallet’s total balance and forces users to pause all transactions until the network stabilizes. The incident is significant because Liquid Network functions as a key infrastructure layer for institutional Bitcoin liquidity, and its temporary suspension disrupts high-value settlement flows across the market.

Attackers claim white-hat status and promise to return funds after vulnerability is patched

Liquid Network operates as a Bitcoin sidechain managed by a federation of more than 80 firms, including Blockstream. The breach specifically involved the Peg-out Authorization Key (PAK) associated with SideSwap, a service that facilitates the conversion of Liquid Bitcoin back to native Bitcoin. SideSwap stated that a customer sent 4,000 Liquid Bitcoin to its peg-out service at 14:05 UTC, which triggered the withdrawal. Liquid Network maintains that the PAK itself was not compromised, suggesting a complex attribution scenario rather than a direct key theft.

The scale of the loss is significant, with attackers moving 4,000 BTC, which represents nearly the entire balance of the federation wallet at the time of the exploit. In response to the incident, Liquid Network suspended all transactions and issued warnings about potential service disruptions. The network relies on this federation model for security, and the current pause affects all participants waiting for withdrawals or deposits to process.

Hackers involved in the breach identified themselves as white-hat actors and left an on-chain message demanding that developers fix the underlying vulnerability first. They promised to return the funds once the bug is patched and every node is updated. This claim remains unconfirmed, as there is no guarantee the attackers will honor their word or that the funds can be recovered. Users are advised to monitor official Liquid Network channels for updates regarding the patch timeline and service restoration.

The incident highlights the risks inherent in centralized federation models for sidechains, even when backed by numerous reputable firms. Liquid Network has stopped operations to investigate the exploit and secure the remaining infrastructure. The network will resume normal operations only after the vulnerability is addressed and the federation confirms the fix.

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion