2026-09-07 CoinTelegraph

White Hat Hackers Drain 4,000 BTC from Liquid Sidechain in $319M Breach

Purported white hat hackers have extracted nearly 4,000 Bitcoin (worth approximately $319 million) from the Liquid Network sidechain, exploiting a bug in the Elements software used by Blockstream to authorize peg-out transactions. According to Liquid's official communications, the funds were withdrawn via the SideSwap PAK (Peg-out Authorization Key), though that key was not compromised. An unverified OP_RETURN message left on-chain read: 'we are whitehats. contact us on chain.' The balance of Liquid's federation wallet plummeted from 4,200 BTC to just 207.275 BTC, prompting Blockstream to pause bridge nodes and instruct exchanges to halt LBTC deposits and withdrawals while the team investigates. Crypto analyst DBCrypto noted that the coins remain unmoved and unmixed on Bitcoin, behavior more consistent with a white hat extraction than a theft, though he stressed the incident raises serious questions about sidechain security. 'Either 11 of 15 functionaries signed this off, or the whitelist built to prevent exactly this didn't hold. Neither answer makes Liquid look good,' DBCrypto observed. Jan3 CEO Samson Mow confirmed that 'Everyone is actively working to resolve this,' while Blockstream CEO Adam Back had not publicly commented at the time of writing.

Meanwhile, the broader Bitcoin market has shown signs of recovery. US spot Bitcoin ETFs recorded their strongest three-week inflow stretch of 2026, attracting $986.9 million in the most recent week alone, bringing the total to $3.8 billion over the period. This surge comes as Bitcoin trades just above $80,000, though it has yet to hold above the 50-week moving average—a key technical indicator that would confirm a new bull market. Institutional appetite for Bitcoin exposure appears to be returning despite security concerns within the ecosystem, with the ETF inflows suggesting renewed confidence among professional investors.

The Liquid incident highlights ongoing vulnerabilities in cross-chain bridges and sidechain architectures, which have historically been prime targets for exploits. The Blockstream-run network uses an 11-of-15 multisig mechanism with approved withdrawal whitelists to secure funds, yet a software bug in Elements circumvented these safeguards. Until bridge nodes are re-enabled and the underlying vulnerability is patched, the Liquid sidechain remains effectively frozen, with the fate of the 4,000 BTC contingent on whether the self-identified white hat hackers cooperate with the network's recovery efforts.

Read Full Article at CoinTelegraph →

Related Tool

Find Your ID

Try Now →
Check My ID