Ethical Hacking News
Liquid hackers return 3,400 Bitcoin taken via Elements bug, still holding $47M in BTC. A recent incident involving the Liquid Network highlights the importance of cybersecurity and the need for constant vigilance in the digital assets space. The exploit of the Elements bug and the subsequent theft of 3,400 Bitcoins serves as a reminder that even the most seemingly secure systems can be vulnerable to attack.
The Liquid Network, a Bitcoin sidechain, was hacked, with hackers stealing approximately 3,400 Bitcoins. The hackers exploited a bug in the Elements software, allowing them to gain unauthorized access to the network. The stolen Bitcoins were sent to a Liquid Federation address, but 598.5 Bitcoins were left unaccounted for. The hackers returned 3,400 of the stolen Bitcoins, leaving approximately 598.5 Bitcoins still unaccounted for. The Liquid Network has been paused, and holders are unable to turn the token back into Bitcoin until the issue is resolved. The value of the stolen Bitcoins was estimated to be around $320 million at the time of the theft. The hackers' identity and motivations are still unclear, with some describing them as "white-hats" while others question their legitimacy.
The cryptocurrency market witnessed a shocking turn of events recently, as hackers managed to exploit a vulnerability in the Liquid Network, a Bitcoin sidechain, and made off with approximately 3,400 Bitcoins. The incident, which occurred on Sunday, September 6, left the entire cryptocurrency community in a state of disbelief and raised several questions about the security of the digital assets.
According to reports, the hackers took advantage of a bug in the Elements software, which is used by the Liquid Network. The Elements software is designed to facilitate the transfer of Bitcoin between the sidechain and the main Bitcoin chain. However, the bug, which has not been publicly disclosed by the parties involved, allowed the hackers to gain unauthorized access to the Liquid Network and steal a significant amount of Bitcoin.
The stolen Bitcoins were sent to a Liquid Federation address, which is the group of operators that holds the Bitcoin backing the token called L-BTC. The federation is responsible for ensuring the security and integrity of the Liquid Network. The 3,400 Bitcoins were sent to the federation address at 16:09 UTC on September 7, approximately 85% of the total amount stolen.
The hackers then returned 3,400 of the stolen Bitcoins the next day, leaving approximately 598.5 Bitcoins still unaccounted for. The remaining Bitcoins were part of the same transaction and were sent back to the address from which they originated. The unaccounted Bitcoins were still present on the mempool.space block explorer as of September 8.
The Liquid Network has been paused since the incident, and holders are unable to turn the token back into Bitcoin. The pause is expected to last until the issue is resolved and the network is restored to its normal functioning state.
Blockstream, which provides the technology for the Liquid Network, stated that the hackers who claimed to be white hats took approximately 4,000 Bitcoins from the federation wallet. The value of the stolen Bitcoins was estimated to be around $320 million at the time of the theft. The withdrawal took roughly 95% of Liquid's reported Bitcoin reserves, which stood at approximately 4,200 Bitcoins beforehand.
The bitcoin price at the time of the theft was around $78,000. The 3,400 Bitcoins were worth approximately $265 million, while the 598.5 Bitcoins were worth around $47 million. The bitcoin was sent via SideSwap's Peg-out Authorization Key, one of the keys that release funds from the sidechain. Blockstream stated that the key was not compromised, nor were any others.
A peg-out destroys L-BTC on the sidechain and releases the matching bitcoin on the main Bitcoin chain. SideSwap stated that the bug in Elements had created the L-BTC used in the withdrawal. SideSwap also stated that neither its systems nor its key were compromised.
Liquid did not explain the flaw when it announced the incident, and Blockstream's incident page does not describe it. The two sides then talked in public, on the Bitcoin blockchain. An early message written into a transaction read "we are whitehats. contact us on chain," according to Unchained.
The group asked for the flaw to be fixed and every node patched before they would send anything back. Blockstream replied with a signed message saying its bridge nodes were patched and the funds were safe to return.
A transaction confirmed at 15:31 UTC on September 7 sent the federation address 1,000 satoshis, or 0.00001 bitcoin, along with a PGP-encrypted message. The contents of the message are not public. The 3,400 bitcoin followed, confirmed 38 minutes later.
Blockstream stated that updated software has been deployed and that federation members are preparing a coordinated restart. Samson Mow, chief executive of JAN3 and a former Blockstream executive, put the amount not returned at about 598 bitcoin. He stated that Blockstream is still in contact with the group.
Mow advised users not to send bitcoin to Liquid's peg-in addresses, the deposit addresses that create L-BTC, until the restart is confirmed. Other assets issued on Liquid, including USDT and DePix, are unaffected, according to Blockstream.
Not everyone accepts the white-hat description. Charles Guillemet, chief technology officer at Ledger, rejected the label, stating that if the roughly 600 bitcoin still held was a reward negotiated through encrypted messages on the blockchain, the arrangement looked more like extortion.
In conclusion, the recent incident involving the Liquid Network highlights the importance of cybersecurity and the need for constant vigilance in the digital assets space. The exploit of the Elements bug and the subsequent theft of 3,400 Bitcoins serves as a reminder that even the most seemingly secure systems can be vulnerable to attack.
The incident also raises questions about the nature of the hackers and their motivations. While some have described them as white-hats, others have questioned the legitimacy of their claims. The situation is ongoing, and it remains to be seen how it will be resolved.
As the cryptocurrency market continues to evolve, it is essential to stay informed and up-to-date on the latest developments. The recent incident involving the Liquid Network serves as a timely reminder of the importance of cybersecurity and the need for constant vigilance in the digital assets space.
Related Information:
https://www.ethicalhackingnews.com/articles/Liquid-Hackers-Return-3400-Bitcoin-Taken-via-Elements-Bug-Still-Holding-47M-in-BTC-ehn.shtml
https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html
Published: Tue Sep 8 10:52:51 2026 by llama3.2 3B Q4_K_M