Bitcoin Infrastructure Under Attack: Third Major Attack in Six Months
Hackers withdrew 4,000 BTC ($320 million) from the Liquid Network, exploiting a validation bug in Elements

Bitcoin Infrastructure Under Attack: Third Major Attack in Six Months
Hackers have drained 4,000 BTC ($320 million) from the Liquid Network by exploiting a validation bug in Elements — representing 95% of the network's reserves. Already, 3,400 BTC ($270 million) has been returned, while $47 million remains with the attackers, who promised to return the funds once the bug is patched. This is the third major hack in a year and a half, undermining trust in the Bitcoin infrastructure.
Liquid Network, a settlement network used by dozens of cryptocurrency exchanges for expedited Bitcoin settlements, lost approximately $320 million in an attack that has called into question the security of sidechains and infrastructure layers surrounding the main Bitcoin network.
The hackers, calling themselves "white hat hackers," withdrew approximately 4,000 out of 4,200 Bitcoins from the network's federated wallet and promised to return the funds once the vulnerability is resolved. At the time of the hack, Bitcoin was trading 0.18% lower, at $79,659.
On September 6, 2026, two transactions totaling approximately 3,998.5 Bitcoins were executed from the Liquid Network's federated wallet.
The network, launched by Blockstream in 2018 and managed by a federation of more than 80 exchanges, infrastructure companies, and asset managers, immediately suspended all new transactions. "Liquid wallets will be affected, and we apologize for the inconvenience," the network announced on X.
Unlike most crypto hacks this year, the incident did not involve the theft of passwords or private keys. The funds were withdrawn through SideSwap, a legitimate and approved trading platform that is part of the Liquid infrastructure.
A subsequent investigation by Blockstream revealed that a software bug in Elements — the open-source platform on which Liquid is built — allowed for the incorrect generation of Bitcoins within the system. Since SideSwap could not distinguish the bug-generated coins from real ones, it processed them identically.
Aneyrin Flynn, CEO of cybersecurity firm FailSafe, stated that preliminary data points to a bug allowing the minting of L-BTC — tokens backed by Bitcoin in reserve. "This hack is the latest in a series of attacks exposing weaknesses in crypto infrastructure this year," Flynn noted.
The hackers, positioning themselves as "white hats," claimed they are acting ethically and will return the funds once the vulnerability is patched. In messages embedded in small Bitcoin transactions on the blockchain, they demanded: "Please fix the bug first. The network is at risk. Make sure every node is updated. Then we will return the money."
By the morning of September 8, according to Galaxy Digital, the hackers had returned 3,400 Bitcoins, keeping about $47 million. Liquid Network has not yet announced when the network will resume operations and whether all funds will be returned.
The Liquid Network incident marks the third major blow to the crypto industry's security in the last month and a half. In late July 2026, a vulnerability was discovered in the firmware of Coldcard hardware wallets, allowing attackers to recover private keys due to insufficient entropy during seed phrase generation.
During three waves of attacks from July 30 to August 6, at least 1,789 BTC (about $114.7 million) was stolen, affecting more than 8,865 addresses. According to Galaxy Research, the hackers used THORChain and CoinJoin to launder the funds. In late August and early September, attackers withdrew $6 million from a lending platform associated with Crypto.com.
The significance of the Liquid Network hack goes far beyond the stolen funds. Liquid was created to solve a practical problem for exchanges — the slow speed of the main Bitcoin network.
The network issues L-BTC backed by Bitcoins locked in reserve, allowing for faster settlements. The outflow of almost the entire reserve calls into question the security of this model.
As Bloomberg notes, the damage extends beyond the stolen Bitcoins. "The incident highlights risks in the layers surrounding the blockchain — wallets, custody mechanisms, and transactional infrastructure that users ultimately rely on."
This comes at a time when the industry is trying to convince banks and institutional investors that digital assets can become part of mainstream financial infrastructure.
Ziceng Ang, Head of Policy for Asia-Pacific at TRM Labs, noted: "While these events may understandably shake consumer confidence, they highlight where critical infrastructure elements need to be strengthened and why comprehensive security at all levels is imperative for operators."

