Key TakeawaysOn Sunday, September 6, 2026, self described whitehat hackers withdrew about 4,000 Bitcoin (BTC), worth roughly $320 million, from the federation wallet backing Blockstream's Liquid NetwoKey TakeawaysOn Sunday, September 6, 2026, self described whitehat hackers withdrew about 4,000 Bitcoin (BTC), worth roughly $320 million, from the federation wallet backing Blockstream's Liquid Netwo

Liquid Network Hack Explained: $320 Million in Bitcoin Drained, 85% Returned, and the $47 Million Question

Key Takeaways
On Sunday, September 6, 2026, self described whitehat hackers withdrew about 4,000 Bitcoin (BTC), worth roughly $320 million, from the federation wallet backing Blockstream's Liquid Network, about 95% of the sidechain's reserves of around 4,200 BTC.
The attackers exploited a bug in Elements, the open source software underlying Liquid, to create L-BTC that was not backed by real Bitcoin, then pegged it out through SideSwap's peg out authorization path. Blockstream says the key itself was not compromised and no other Liquid assets were affected.
The negotiation happened entirely on the Bitcoin blockchain: the group wrote "we are whitehats. contact us on chain" into a transaction, demanded every bridge node be patched first, and Blockstream answered with PGP signed messages confirming the fix.
On Monday, September 7, the group returned exactly 3,400 BTC, about $268 million, and kept 598.5 BTC worth roughly $47 million, an apparent self awarded bounty that Blockstream is still negotiating over.
Liquid remains paused with a chain split to unwind, bridge nodes disabled and L-BTC deposits and withdrawals halted at exchanges. Bitcoin held on the main chain is unaffected, and BTC barely reacted, trading near $78,500.
 
 

What Liquid Is and Why the Peg Matters

Liquid Network is a Bitcoin sidechain launched by Blockstream in 2018 and operated by a federation of exchanges and institutions. Users lock BTC on the main chain and receive L-BTC on Liquid, where transactions settle in about a minute with confidential amounts, which is why it became a preferred settlement rail between trading venues and a home for assets such as Tether's USDT. The entire system rests on a promise: every L-BTC in circulation is backed one to one by real Bitcoin held in the federation wallet, and a peg out destroys L-BTC on the sidechain while releasing the matching BTC on the main chain.
That promise is what broke on Sunday. Blockstream's incident notice said hackers claiming to be whitehats took about 4,000 BTC from the federation wallet, roughly 95% of reserves that stood near 4,200 BTC beforehand. The coins left through SideSwap's peg out authorization key, one of the keys that can release funds, though Blockstream stressed that the key was not compromised and neither were any others. The root cause, according to SideSwap and subsequent analysis, was a bug in Elements, the blockchain software powering Liquid, that allowed the creation of L-BTC without backing. In effect, the attackers minted counterfeit sidechain Bitcoin and redeemed it for the real thing.
 
 
 

A Negotiation Written Into the Blockchain

What followed was unlike any security disclosure in the industry's history. Rather than emails or a bug bounty portal, the actors communicated through messages embedded in Bitcoin transactions using OP_RETURN. One of the earliest read "we are whitehats. contact us on chain." At Bitcoin block 965,875 they stated they would return the funds, but only after the vulnerability was fixed and the patch applied to every relevant node, a condition Blockstream acknowledged in a PGP signed message of its own. Blockstream then confirmed all bridge nodes had been patched and the funds were safe to send back.
The return came on Monday, September 7. A transaction confirmed at 15:31 UTC sent the federation address 1,000 satoshis along with a PGP encrypted message whose contents remain private. Thirty eight minutes later, in block 965,950, exactly 3,400 BTC arrived back in the federation wallet, worth about $268 million at prevailing prices. The remaining 598.5 BTC, roughly $47 million and about 15% of the haul, stayed with the actors. Samson Mow, the JAN3 chief executive and former Blockstream strategy chief who has been posting updates on the incident, said Blockstream continues to engage with the group over the balance. Whether that sum is a demanded bounty, a unilateral fee, or something still to be returned has not been made public.
 
 

Whitehats, or Something Else?

The label is contested. Liquid itself has carefully referred to "purported" whitehats, and Ledger's chief technology officer Charles Guillemet questioned the take first and negotiate later approach, before allowing that the actors could be inexperienced researchers rather than criminals. Genuine whitehat disclosure normally involves reporting a flaw privately and being rewarded after a fix, not draining 95% of a system's reserves and setting terms in public. The counterargument is pragmatic: the group demonstrated the bug, forced a rapid patch, returned the overwhelming majority of the funds, and never attempted to launder anything. The crypto industry has seen this ambiguous middle ground before, and the $47 million now sitting outside Blockstream's control will decide which reading history settles on.
 
 

What Is Still Broken

The return eased the collateral crisis but did not end it. Liquid remains paused, bridge nodes are disabled, and L-BTC deposits and withdrawals at centralized exchanges are halted. During the pause a chain split emerged that operators must resolve before a coordinated restart, and the federation has to demonstrate that L-BTC is once again fully backed, either by recovering the outstanding coins, funding the shortfall, or documenting a plan for it. Blockstream says updated software has been deployed and federation members are preparing the restart. Until an official statement confirms peg ins and peg outs have resumed, the peg is operating under supervision rather than restored.
Notably, the Bitcoin price barely flinched, holding near $78,500 through the episode. The market appears to have drawn the right distinction: this was a failure in a federated sidechain's software, not in Bitcoin, and main chain BTC was never at risk. It does, however, land in a bruising year for security following the Coldcard firmware exploit and the Trezor and SafePal data leak
 

What It Means for Traders on MEXC

For most holders the practical impact is zero. Bitcoin on the main chain, including balances held on MEXC, is unaffected; only L-BTC on the paused sidechain is frozen, and anyone with funds there simply has to wait for the restart. The incident is a reminder that wrapped and pegged versions of Bitcoin carry their own trust assumptions, from federations to bridge software, that native BTC does not. Traders can follow the market on BTC/USDT as the restart news develops.
 
Disclaimer: This content is for educational and reference purposes only and does not constitute any investment advice. Digital asset investments carry high risk. Please evaluate carefully and assume full responsibility for your own decisions.
市場機遇
4 圖標
4實時價格 (4)
$0.023022
$0.023022$0.023022
USD

本頁面分享的文章均源自公開平台,僅供參考。該內容不代表 MEXC 的立場或觀點。所有版權歸 OoJae 所有。如果您認為任何內容侵犯了第三方的權益,請聯絡 service@support.mexc.com 以便及時刪除。 MEXC 不保證任何內容的準確性、完整性或及時性,且不對基於所提供信息而採取的任何行動負責。本內容不構成財務、法律或其他專業建議,亦不應被解釋為 MEXC 的推薦或認可。如需專家見解和深入分析,請造訪 MEXC 學院。

學習更多 4 知識

查看更多
Oura 競爭對手:三星、蘋果與智慧戒指市場

Oura 競爭對手:三星、蘋果與智慧戒指市場

根據其IPO招股說明書,Oura的競爭對手分為三類:智慧手錶製造商,如Apple、Google和Samsung;健身穿戴裝置,如Garmin、Coros和Whoop;以及純軟體健康應用程式。在智慧戒指領域,Oura遙遙領先,2025年上半年約占全球出貨量的74%,研究公司Omdia估計。 重點摘要 小池塘裡的大魚:Oura 主導智慧戒指市場,但截至 2026 年 6 月 30 日的 12 個月內,
2026/09/25
Oura 競爭對手:三星、蘋果與智慧戒指市場

Oura 競爭對手:三星、蘋果與智慧戒指市場

根據其IPO招股說明書,Oura的競爭對手分為三類:智慧手錶製造商,如Apple、Google和Samsung;健身穿戴裝置,如Garmin、Coros和Whoop;以及純軟體健康應用程式。在智慧戒指領域,Oura遙遙領先,2025年上半年約占全球出貨量的74%,研究公司Omdia估計。 重點摘要 小池塘裡的大魚:Oura 主導智慧戒指市場,但截至 2026 年 6 月 30 日的 12 個月內,
2026/09/25
Oura是否盈利?營收、商業模式與估值

Oura是否盈利?營收、商業模式與估值

是的,Oura在淨利潤基礎上是盈利的。其IPO招股說明書顯示,截至2026年6月30日的九個月內,淨利潤為6080萬美元,營收為12.1億美元。部分標題中提到的9.243億美元虧損是另一行數字:這是普通股股東在扣除與回購早期投資者優先股相關的9.85億美元會計費用後的結果。 重點摘要 有獲利,但只是近期才開始:截至2026年6月30日的九個月內,淨收入為6,080萬美元,而2024財年為360萬美
2026/09/25
查看更多

4 最新動態

查看更多
從稀缺交易到估值紀律:SpaceX的回調考驗OpenAI的IPO野心

從稀缺交易到估值紀律:SpaceX的回調考驗OpenAI的IPO野心

據報導,OpenAI 傾向將其 IPO 推遲至 2027 年,但更強烈的市場訊號來自 SpaceX。SpaceX 於 6 月 22 日收盤下跌了 16.4%,收於 154.60 美元,較盤中高點 225.64 美元降低了 31.5%,但仍較其 135 美元的 IPO 價格高出 14.5%。這一走勢使 SpaceX 從一個由稀缺性驅動的 IPO 成功案例,轉變為 AI 相關超大型上市週期中首個重大公開市場壓力測試。 OpenAI 的問題不在於需求,而在於估值。路透社引用《紐約時報》的報導指出,OpenAI 正考慮等待至 2027 年,以維持高達 1 兆美元的估值目標,而顧問將此選擇定調為:要麼等待達到該估值,要麼以較低目標提前上市。 預測市場已開始反映這種謹慎態度。Polymarket 的 OpenAI IPO 市場近期顯示,OpenAI 在 2026 年 12 月 31 日前完成 IPO 的機率約為四分之一,這表明交易者不再將近期上市視為明確的基本情境。對於加密貨幣交易者而言,這使得 AI 上市前的曝險從單向的稀缺性交易,轉變為與公開市場基準掛鉤的估值紀律交易。
2026/06/29
Coldcard Mk3 警告隨 $38M Bitcoin 掃蕩而來,但原因仍未確認

Coldcard Mk3 警告隨 $38M Bitcoin 掃蕩而來,但原因仍未確認

比特幣硬體錢包製造商 Coinkite 已警告用戶,Coldcard 裝置存在種子生成問題,影響範圍涵蓋所有 4.0.1 及更高版本的 Mk3 韌體。此警告是在安全研究人員調查一宗涉及 594.48 BTC(價值約 3,800 萬美元)的協調性盜取事件時出現的。然而,目前尚無公開的技術證據證實 Coldcard 的問題導致了這些轉帳。
2026/07/31
Mastercard 完成對 BVNK 的收購,金額高達 18 億美元——穩定幣進入全球支付核心

Mastercard 完成對 BVNK 的收購,金額高達 18 億美元——穩定幣進入全球支付核心

Mastercard 於三月宣布該交易後,已於 2026 年 8 月 3 日(UTC +8)完成對穩定幣基礎設施供應商 BVNK 的收購。
2026/08/04
查看更多