Liquid Network Attacker Sends Back Most of the Stolen Bitcoin, Keeps $47M
A bug in the Elements software behind Bitcoin's Liquid sidechain let someone drain nearly 4,000 bitcoin. Most of it came back the next day. Roughly 598 bitcoin, worth about $47 million, has not.

Key points
- Someone drained nearly 4,000 bitcoin from the Liquid Network on Sunday, 6 September, and returned about 3,400 of it the next day.
- Around 598.5 bitcoin, worth roughly $47 million at current prices, is still in the attacker's hands.
- Liquid is a Bitcoin sidechain, a separate network that holds real bitcoin to back a token called L-BTC, so any loss on Liquid means missing backing for that token.
- The network remains paused, meaning holders of L-BTC cannot swap the token back for real bitcoin.
- The root cause was a flaw in Elements, the open-source software Liquid runs on, developed by Blockstream.
Someone walked off with almost 4,000 bitcoin from the Liquid Network on Sunday, 6 September. The next day, most of it came back.
Bitcoin's public ledger, the shared record that shows every transaction on the network, confirms the return of about 3,400 coins. The remaining 598.5 bitcoin, worth roughly $47 million, has not moved back. Nobody outside the attacker knows why.
What is the Liquid Network and why does this matter?
Liquid is a sidechain, a smaller network that runs alongside Bitcoin and holds real bitcoin in reserve to back its own token, called L-BTC. Traders and exchanges use it for faster settlement. Every L-BTC in circulation is supposed to be matched, one for one, by a real bitcoin locked up on Liquid.
If coins go missing on Liquid, the token stops being fully backed. That is why the operators paused the network. Holders of L-BTC currently cannot redeem their tokens for actual bitcoin, and will not be able to until the network restarts.
How did the attacker get in?
The attacker exploited a bug in Elements, the open-source software that Liquid is built on. Elements is maintained by Blockstream, the company that also runs much of Liquid's infrastructure. In plain terms, the flaw let someone move bitcoin out of Liquid's reserves without the usual permission checks.
Blockstream has not published a full technical writeup as of this reporting, first covered by The Hacker News. What we know from the on-chain data is that the movement was large, fast, and clean. The failure mode here is a classic one for multi-party custody systems: a single software defect undermines the maths that is supposed to make theft impossible.
What happens to the money that came back?
| Item | Amount | Status |
|---|---|---|
| Total taken | ~3,998.5 BTC | Drained on 6 Sept |
| Returned | ~3,400 BTC | Sent back 7 Sept |
| Still missing | ~598.5 BTC | ~$47M at current price |
| Network status | Liquid | Paused, no redemptions |
The returned coins landed at an address Blockstream controls. Partial returns like this usually mean one of two things: the attacker is negotiating a bounty, or they got spooked and kept a share they think they can launder. In practice, the industry treats these as ransom payments dressed up as "whitehat" returns.
Should ordinary crypto users worry?
If you do not hold L-BTC or trade on an exchange that uses Liquid, this does not touch you directly. Regular bitcoin on the main Bitcoin network is unaffected. The bug lived in Elements, not in Bitcoin itself.
If you do hold L-BTC, you cannot redeem it right now. Watch Blockstream's status page for updates, and be wary of anyone in your inbox or on social media offering to "help" you recover funds. Every large crypto incident brings a wave of follow-on scams within days.
One thing the post-mortem will say: a sidechain is only as trustworthy as the code holding the reserves. Operational takeaway: if your treasury sits behind one software stack, one bug is your entire risk model.



