2026’s Biggest Hack To Date: Attackers Drained USD 319 Million in Bitcoin From Liquid Network, Then Returned 85% of Funds
TRM User Conference
Which mission will you select?
Key takeaways
- On September 6, 2026, attackers drained about USD 319 million in bitcoin from the Liquid Network, a Bitcoin sidechain run by Blockstream
- The Liquid Network hack is the single largest crypto theft of 2026, ahead of the April thefts from KelpDAO and Drift
- The attackers exploited a bug in Liquid's validator software to create unbacked synthetic bitcoin tokens, then cashed them out for real BTC
- Claiming to be white hats, the attackers negotiated with the Blockstream team via onchain messaging and returned about 85%, or roughly USD 272 million, after Blockstream patched the bug
- About USD 47 million remains with the attackers, and the Liquid Network is still paused
- TRM has labeled the attackers' addresses and continues to track the funds that were not returned
{{horizontal line}}
2026’s largest hack yet
The Liquid Network hack is the largest crypto theft of 2026 so far at USD 319 million. The next two, the April thefts from KelpDAO and Drift, took USD 292 million and USD 285 million.
Liquid Network is a Bitcoin sidechain built by Blockstream and used by exchanges and traders to move bitcoin faster and more privately than is possible on the Bitcoin blockchain itself. That makes this hack unusual: large thefts have hit Ethereum-based layer-2 blockchains and associated infrastructure like bridges, but this is by far the largest attack recorded against a Bitcoin sidechain.

With Liquid, 2026 has now seen about USD 1.73 billion stolen across 333 incidents. The incident count is already a record, but the dollar total is running lower than previous years. Annualized, 2026's losses would reach about USD 2.5 billion, below both 2025 and 2022. The year has brought more attacks but smaller typical hauls, with occasional large exceptions like this one.

How the Liquid Network hack happened
Liquid is run by a federation of exchanges and infrastructure firms. To mint L-BTC, users lock BTC in the federation’s wallet on Bitcoin and receive L-BTC on Liquid. To move funds back out, they burn L-BTC and ask the federation to release BTC from its reserve, which it approves or denies via an 11-of-15 multisig. Liquid hides transaction amounts, so every confidential output carries a range proof attesting that its value falls within a valid bound. Without that check, a transaction can create spendable value from nothing.
Verifying range proofs is expensive, so Elements — the Liquid Network’s validation software — caches the results. Reconstructions from Bitquery and DeFiPrime, along with analysis by mempool.space developer mononaut, point to a flaw in that cache that may have let an invalid output pass as already verified.
The onchain reconstructions lay out the sequence. In the hours before the attack, the attacker broadcast dozens of Liquid transactions carrying matching proof data. At 13:53 UTC on September 6, in block 4,050,336, they minted about 4,000 L-BTC with no backing. By 14:06 UTC they had requested a withdrawal through SideSwap, an approved operator. At 14:28 UTC the federation paid out about 4,000 BTC, and roughly 3,996 BTC reached the attacker. From mint to payout took 36 minutes.
The federation's 11-of-15 signers approved the withdrawal because Elements treated the chain state holding the unbacked L-BTC as valid. SideSwap said the unbacked L-BTC came from an Elements software bug rather than a compromise of its systems, and Blockstream said none of its signing keys were compromised.

The onchain negotiation
Hours after the drain, a message appeared onchain. The attackers embedded the words "we are whitehats. contact us on chain" in the OP_RETURN field of a Bitcoin transaction, and proceeded to communicate with the Blockstream team via encrypted onchain messaging. The attackers promised to return funds once every node patched the bug the attackers exploited. Once the patch went out, the attackers began sending funds back.

On September 7, the attackers returned about 3,400 BTC, roughly USD 272 million, to the federation. The remaining 598.5 BTC, about USD 47 million, remains with the attackers, who appear to be claiming it as a bounty.

The Liquid Network remains paused, and exchanges have not resumed L-BTC trading.
What this means for L-BTC holders
With the peg halted, L-BTC cannot be redeemed. Using about 3,597 BTC in the identified reserve address and an estimated 4,200 L-BTC outstanding, the implied backing ratio is about 86%. That estimate is not a complete reserve-and-liability reconciliation. The federation has not announced how it will address the shortfall or when redemptions will resume.
Hackers continue to target cross-chain infrastructure in new ways
Cross-chain infrastructure has long been a lucrative target for hackers, with Liquid joining other notable examples like Ronin (USD 625 million), Poly Network (USD 611 million), and Wormhole (USD 325 million). What sets Liquid apart, aside from being the lone Bitcoin sidechain on the list, is how it happened. While those earlier thefts came due to stolen validator keys, flawed bridge contracts, or forged signatures, Liquid's came from a bug in the sidechain's validation software that let the attackers forge the asset itself.
Overall though, this attack is emblematic of what makes cross-chain infrastructure so attractive to hackers. A sidechain reserve wallet concentrates a large pool of funds in one place, and one security flaw can expose the entire thing.
TRM labeled the attackers' addresses within a day and continues to track the roughly USD 47 million that was never returned.
{{horizontal-line}}
Frequently asked questions (FAQs)
1. How much was stolen from the Liquid Network?
About USD 319 million in bitcoin, roughly 4,000 BTC, on September 6, 2026. The attackers later returned about 3,400 BTC, leaving around USD 47 million outstanding.
2. Was Bitcoin itself hacked?
No. The flaw was in the software of the Liquid Network, a Bitcoin sidechain built by Blockstream. Bitcoin's main chain and protocol were unaffected. The stolen coins are real bitcoin that left Liquid's reserve wallet.
3. Who carried out the attack?
The attackers remain unidentified. They described themselves as white hats and returned most of the funds after Blockstream patched the bug, but the claim is unverified and about USD 47 million remains with them.
4. Is the Liquid Network safe to use now?
Blockstream has patched the underlying bug. As of September 8, 2026, the network remains paused and exchanges have not resumed L-BTC trading.
5. Is L-BTC still backed one to one?
Available public figures suggest a shortfall. About 3,597 BTC in the identified reserve address against an estimated 4,200 L-BTC outstanding implies roughly 86% backing, though that is not a full reserve-and-liability reconciliation. Redemptions remain halted, and the federation has not announced terms for resuming them.
6. What should exchanges and other virtual asset service providers do?
Account for the continued suspension of Liquid peg activity, screen Bitcoin exposure to the attacker address below, and monitor the retained funds for movement.




















