Liquid Network Hit with $320M BTC Heist as Hacker Demands Patch First
The Liquid Network suffered a significant loss of $320 million in BTC on September 6, 2026, after someone exploited a flaw in the open-source software underneath it, Elements.
The attacker used the SideSwap Peg-out Authorization Key to move funds without compromising any private keys or phishing federation members. The transaction was presented as a normal customer order, fully signed and authorized.
Mononaut estimated that after the drain, each LBTC in circulation was backed by only about 4.7% of an actual Bitcoin. Researchers traced the issue to how Liquid's confidential transactions validate and cache, an inflation bug, not a stolen-key story.
The attacker then began sending messages back to Blockstream embedded directly in Bitcoin transactions, demanding that the company fix the bug first before confirming every node was patched. Blockstream answered in kind, stating they had sent their own signed message once the fix was live.