On September 6, 2026, the Liquid Network—Blockstream’s Bitcoin‑sidechain used by exchanges and institutional traders to settle Bitcoin transactions more quickly—was hit by a massive theft. Approximately 4,000 Liquid‑Bitcoin (L‑BTC) tokens were withdrawn from the federation wallet that backs the sidechain, a loss worth about $320 million at the time.

The breach stemmed from a flaw in Elements, the software that powers Liquid. A range‑proof verification cache error let attackers forge invalid L‑BTC tokens that the network accepted as legitimate. The attackers, who identified themselves as “white‑hat hackers,” even communicated with the federation members via Bitcoin transactions, demanding that every node be patched before the stolen funds would be returned.

In the wake of the attack, Liquid Network halted all new transactions and temporarily disabled bridge nodes. The federation paused operations while developers worked to fix the vulnerability. After a patch was released, the attackers returned 3,400 of the 4,000 BTC they had withdrawn, a value of roughly $269 million. The remaining 598 BTC—about $47 million—have not yet been returned.

This incident follows a string of high‑profile crypto security breaches earlier this year. In early September, a hacker stole $6 million from the crypto‑lending platform Tectonic. In August, a firmware flaw in older Coldcard Bitcoin hardware wallets caused losses estimated between $115 million and $130 million.

The hack has intensified scrutiny of crypto infrastructure. A recent FinCEN analysis highlighted that banks can detect investment‑scam patterns before the final fraudulent payment is made by monitoring indicators such as sudden retirement‑account liquidations, rapid depletion of savings, new home‑equity or personal loans, and transfers to crypto exchanges or unfamiliar beneficiaries.

Liquid’s vulnerability underscores the risks associated with Layer‑2 solutions that rely on federation‑controlled wallets. While the sidechain offers faster settlement and privacy features, the centralization of the federation wallet creates a single point of failure. The incident has prompted exchanges that use Liquid to review their own security practices and to consider additional safeguards such as multi‑signature requirements and real‑time monitoring of federation activity.

Blockstream, the company behind Liquid, has stated that the patch will be deployed across all nodes and that the network will resume normal operations once the vulnerability is fully addressed. The organization has also announced that it will conduct a comprehensive audit of the Elements codebase to prevent similar exploits.

The partial return of the stolen funds has been welcomed by the crypto community, but the remaining 598 BTC remain a concern. The Liquid Network team has requested that the attackers complete the return of the outstanding balance once the patch is confirmed. Until then, the sidechain remains in a suspended state.

The broader industry is watching closely. Institutional investors who rely on Liquid for settlement are evaluating whether to continue using the network or to shift to alternative Layer‑2 solutions. Regulators are also monitoring the incident as part of ongoing discussions about the security standards required for crypto infrastructure that interfaces with traditional financial systems.

In summary, the Liquid Network hack resulted in a $320 million loss of Bitcoin, a partial return of $269 million after a software patch, and the suspension of the sidechain’s operations. The incident highlights the importance of rigorous security testing for blockchain infrastructure and the need for rapid response mechanisms when vulnerabilities are discovered.