Liquid Network drained of 4,000 BTC in Elements bug exploit
Money MovesPurported white-hat hackers say they'll return most funds once the bug is patched
Yesterday: SideSwap processes 4,000 L-BTC peg-outNew here? Follow stories to track developments over time. Create a free account to get updates when stories you care about change.
Overview
Updated 1 hour agoLiquid, a Bitcoin sidechain run by Blockstream, lost nearly all its bitcoin reserves on September 6. A single peg-out transaction moved about 4,000 BTC, worth roughly $320 million, out of the federation wallet onto the Bitcoin mainchain. The wallet held about 4,200 BTC before the transfer; it now holds roughly 200.
The withdrawal wasn't a key theft. Someone exploited a validation bug in Elements, the open-source software that powers Liquid, to create L-BTC that no real Bitcoin backed, then redeemed it through a legitimate-looking peg-out. Liquid says no federation key was compromised.
Liquid paused its bridge nodes and asked exchanges to suspend L-BTC deposits and withdrawals. The party behind the withdrawal says it's white-hat hackers who will return most of the funds once the bug is fixed on every node. Blockstream replied, 'Yes, thank you.'
Why it matters
If the bitcoin isn't returned, L-BTC holders are stuck with tokens backed by a wallet that's 95% empty.
Questions about this story
Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.
No questions yet — be the first to ask.
Key Indicators
Voices
Curated perspectives — historical figures and your fellow readers.
Play
Exploring all sides of a story is often best achieved with Play.
Higher or Lower
A number from this story, against one from elsewhere in the news — guess which is bigger, then keep the chain going. 5 rounds, 3 strikes; a miss costs a strike and resets your streak.
Keyboard: ↓/L lower · ↑/H higher
0 points — sign up to put that on the leaderboard.
Connections
Sixteen names from the news. Find the four hidden groups of four. Four mistakes max.
Sign up to keep a daily streak — a new puzzle lands every day.
Exit debate?
Your progress in this debate will be lost.
- 1 Two AI personas square off on this story.
- 2 You predict who'll win each round — correct picks earn XP.
- 3 One crossfire question is yours to fire. Pick it carefully.
Couldn't generate a topic
Select Your Champions
Choose one persona for each side of the debate
DEBATE TOPIC
Choose personas with different perspectives for a more dynamic debate.
Select debater for this side:
No debate personas available right now.
Select debater for this side:
No debate personas available right now.
Who's Got This Round?
Make your prediction before the referee scores
The referee scores both sides on
Round Results
Set the Crossfire
Pick the question both personas must answer in the final round
Debate Oracle! You called every round!
Sharp Instincts! You know your debaters!
The Coin Flip Strategist! Perfectly balanced!
The Contrarian! Bold predictions!
Inverse Genius! Try betting the opposite next time!
XP Breakdown
Prediction History
People Involved
Organizations Involved
Developer of Liquid, a Bitcoin sidechain, and Elements, the open-source software that powers it.
A Bitcoin sidechain secured by a 15-member federation, used for faster and more confidential Bitcoin transfers.
A Liquid Federation member and bridge exchange that processed the peg-out used in the exploit.
The 15 companies that jointly control and secure the Liquid Network.
Timeline
-
SideSwap processes 4,000 L-BTC peg-out
Latest Security IncidentA customer's 4,000 L-BTC is burned under a valid authorization at SideSwap's bridge service.
-
Block 965,783 settles 3,996 BTC payout
Security IncidentThe federation releases 3,996 BTC from the reserve wallet in one 83-input transaction.
-
Liquid disables bridge nodes, alerts exchanges
StatementLiquid announces the withdrawal, pauses bridge nodes, and asks exchanges to suspend L-BTC.
-
Hackers identify themselves on-chain
CommunicationThe destination address broadcasts 'we are whitehats. contact us on chain' via OP_RETURN.
-
Blockstream responds, negotiations go on-chain
CommunicationBlockstream shares its security team's email; PGP-signed messages are exchanged in Bitcoin transactions.
-
Hackers set return conditions
CommunicationHackers say they'll send back most funds after the Elements bug is fixed on every node.
-
Blockstream replies 'Yes, thank you'
CommunicationBlockstream confirms the deal; roughly 3,998.5 BTC remains at the hackers' address.
Historical Context
3 moments from history that rhyme with this story — and how they unfolded.
The DAO hack (2016)
An attacker drained about $60 million from The DAO, a smart contract on Ethereum, using a reentrancy bug. The attacker argued the code permitted the withdrawal, calling it a legitimate exercise of the contract's rules.
The Ethereum community hard-forked the blockchain to reverse the theft, splitting the network into Ethereum and Ethereum Classic.
The incident set a precedent that code exploits could be reversed through community consensus, and it framed the debate around whether an exploit that follows the code's letter is theft.
Like the DAO, this Liquid exploit used a legitimate-looking transaction that exploited a code bug. The white-hat justification echoes the DAO attacker's argument, though this party is offering to return the funds.
Ronin Bridge hack (2022)
Attackers stole $625 million from the Ronin bridge, which moved funds between the Axie Infinity game and Ethereum. Compromised private keys, not a code bug, allowed the drain, making it the largest DeFi hack at the time.
US law enforcement recovered about $30 million and later indicted two individuals. The Securities and Exchange Commission charged the parent company, Sky Mavis.
The case showed both the vulnerability of bridges and sidechains and the reach of law enforcement in recovering stolen crypto.
Ronin was a sidechain bridge exploit on a massive scale, like Liquid. Its recovery came through law enforcement action rather than negotiation, offering a contrasting path to resolution.
Wormhole bridge hack (2022)
A hacker drained $320 million, roughly the same amount as this Liquid incident, from the Wormhole bridge using a signature validation bug. Jump Crypto, which backed the project, replaced the funds within hours.
Wormhole users were made whole. The attacker remained unidentified but later returned $155 million.
The incident showed that a financial backer could absorb losses to protect user confidence, and that crooks sometimes return a portion of stolen funds.
Wormhole's $320 million loss matches this exploit almost exactly. It illustrates the scale of bridge and sidechain hacks and one path to resolution: a deep-pocketed backer covering the loss.
