Key TakeawaysOn Sunday, September 6, 2026, self described whitehat hackers withdrew about 4,000 Bitcoin (BTC), worth roughly $320 million, from the federation wallet backing Blockstream's Liquid NetwoKey TakeawaysOn Sunday, September 6, 2026, self described whitehat hackers withdrew about 4,000 Bitcoin (BTC), worth roughly $320 million, from the federation wallet backing Blockstream's Liquid Netwo

Liquid Network Hack Explained: $320 Million in Bitcoin Drained, 85% Returned, and the $47 Million Question

Key Takeaways
On Sunday, September 6, 2026, self described whitehat hackers withdrew about 4,000 Bitcoin (BTC), worth roughly $320 million, from the federation wallet backing Blockstream's Liquid Network, about 95% of the sidechain's reserves of around 4,200 BTC.
The attackers exploited a bug in Elements, the open source software underlying Liquid, to create L-BTC that was not backed by real Bitcoin, then pegged it out through SideSwap's peg out authorization path. Blockstream says the key itself was not compromised and no other Liquid assets were affected.
The negotiation happened entirely on the Bitcoin blockchain: the group wrote "we are whitehats. contact us on chain" into a transaction, demanded every bridge node be patched first, and Blockstream answered with PGP signed messages confirming the fix.
On Monday, September 7, the group returned exactly 3,400 BTC, about $268 million, and kept 598.5 BTC worth roughly $47 million, an apparent self awarded bounty that Blockstream is still negotiating over.
Liquid remains paused with a chain split to unwind, bridge nodes disabled and L-BTC deposits and withdrawals halted at exchanges. Bitcoin held on the main chain is unaffected, and BTC barely reacted, trading near $78,500.
 
 

What Liquid Is and Why the Peg Matters

Liquid Network is a Bitcoin sidechain launched by Blockstream in 2018 and operated by a federation of exchanges and institutions. Users lock BTC on the main chain and receive L-BTC on Liquid, where transactions settle in about a minute with confidential amounts, which is why it became a preferred settlement rail between trading venues and a home for assets such as Tether's USDT. The entire system rests on a promise: every L-BTC in circulation is backed one to one by real Bitcoin held in the federation wallet, and a peg out destroys L-BTC on the sidechain while releasing the matching BTC on the main chain.
That promise is what broke on Sunday. Blockstream's incident notice said hackers claiming to be whitehats took about 4,000 BTC from the federation wallet, roughly 95% of reserves that stood near 4,200 BTC beforehand. The coins left through SideSwap's peg out authorization key, one of the keys that can release funds, though Blockstream stressed that the key was not compromised and neither were any others. The root cause, according to SideSwap and subsequent analysis, was a bug in Elements, the blockchain software powering Liquid, that allowed the creation of L-BTC without backing. In effect, the attackers minted counterfeit sidechain Bitcoin and redeemed it for the real thing.
 
 
 

A Negotiation Written Into the Blockchain

What followed was unlike any security disclosure in the industry's history. Rather than emails or a bug bounty portal, the actors communicated through messages embedded in Bitcoin transactions using OP_RETURN. One of the earliest read "we are whitehats. contact us on chain." At Bitcoin block 965,875 they stated they would return the funds, but only after the vulnerability was fixed and the patch applied to every relevant node, a condition Blockstream acknowledged in a PGP signed message of its own. Blockstream then confirmed all bridge nodes had been patched and the funds were safe to send back.
The return came on Monday, September 7. A transaction confirmed at 15:31 UTC sent the federation address 1,000 satoshis along with a PGP encrypted message whose contents remain private. Thirty eight minutes later, in block 965,950, exactly 3,400 BTC arrived back in the federation wallet, worth about $268 million at prevailing prices. The remaining 598.5 BTC, roughly $47 million and about 15% of the haul, stayed with the actors. Samson Mow, the JAN3 chief executive and former Blockstream strategy chief who has been posting updates on the incident, said Blockstream continues to engage with the group over the balance. Whether that sum is a demanded bounty, a unilateral fee, or something still to be returned has not been made public.
 
 

Whitehats, or Something Else?

The label is contested. Liquid itself has carefully referred to "purported" whitehats, and Ledger's chief technology officer Charles Guillemet questioned the take first and negotiate later approach, before allowing that the actors could be inexperienced researchers rather than criminals. Genuine whitehat disclosure normally involves reporting a flaw privately and being rewarded after a fix, not draining 95% of a system's reserves and setting terms in public. The counterargument is pragmatic: the group demonstrated the bug, forced a rapid patch, returned the overwhelming majority of the funds, and never attempted to launder anything. The crypto industry has seen this ambiguous middle ground before, and the $47 million now sitting outside Blockstream's control will decide which reading history settles on.
 
 

What Is Still Broken

The return eased the collateral crisis but did not end it. Liquid remains paused, bridge nodes are disabled, and L-BTC deposits and withdrawals at centralized exchanges are halted. During the pause a chain split emerged that operators must resolve before a coordinated restart, and the federation has to demonstrate that L-BTC is once again fully backed, either by recovering the outstanding coins, funding the shortfall, or documenting a plan for it. Blockstream says updated software has been deployed and federation members are preparing the restart. Until an official statement confirms peg ins and peg outs have resumed, the peg is operating under supervision rather than restored.
Notably, the Bitcoin price barely flinched, holding near $78,500 through the episode. The market appears to have drawn the right distinction: this was a failure in a federated sidechain's software, not in Bitcoin, and main chain BTC was never at risk. It does, however, land in a bruising year for security following the Coldcard firmware exploit and the Trezor and SafePal data leak
 

What It Means for Traders on MEXC

For most holders the practical impact is zero. Bitcoin on the main chain, including balances held on MEXC, is unaffected; only L-BTC on the paused sidechain is frozen, and anyone with funds there simply has to wait for the restart. The incident is a reminder that wrapped and pegged versions of Bitcoin carry their own trust assumptions, from federations to bridge software, that native BTC does not. Traders can follow the market on BTC/USDT as the restart news develops.
 
Disclaimer: This content is for educational and reference purposes only and does not constitute any investment advice. Digital asset investments carry high risk. Please evaluate carefully and assume full responsibility for your own decisions.
市場機遇
4 圖標
4實時價格 (4)
--
----
USD
4 (4) 實時價格圖表

本頁面分享的文章均源自公開平台,僅供參考。該內容不代表 MEXC 的立場或觀點。所有版權歸 OoJae 所有。如果您認為任何內容侵犯了第三方的權益,請聯絡 service@support.mexc.com 以便及時刪除。 MEXC 不保證任何內容的準確性、完整性或及時性,且不對基於所提供信息而採取的任何行動負責。本內容不構成財務、法律或其他專業建議,亦不應被解釋為 MEXC 的推薦或認可。如需專家見解和深入分析,請造訪 MEXC 學院

學習更多 4 知識

查看更多
LITEON價格的驅動因素是什麼?AI數據中心、光纖網路與Lumentum股價解析

LITEON價格的驅動因素是什麼?AI數據中心、光纖網路與Lumentum股價解析

摘要 LITEON 的價格從根本上與 Lumentum Holdings 股票 LITE 掛鉤。 這意味著分析 LITEON 最有用的方式不是透過傳統的幣種代幣經濟學,而是透過驅動 Lumentum 的經濟鏈: AI 資本支出 → 更多加速器 → 更多頻寬 → 更多光纖連接 → Lumentum 營收與利潤率 → LITE 估值 → LITEON 目前最重要的變數包括 1.6T 採用、光電路交換、
2026/09/14
光寶科技風險解析:AI資本支出、估值、客戶集中度與光學技術風險

光寶科技風險解析:AI資本支出、估值、客戶集中度與光學技術風險

摘要 LITEON 結合了 Lumentum 的基礎權益風險與額外的代幣化市場層面。 最大的公司層級風險包括: AI 資本支出放緩; 極高的成長預期; 客戶集中度; 製造產能; 依賴光學技術轉型的成功; 競爭; 利潤壓力; LITE 估值。 LITEON 另外增加: 追蹤風險; 流動性風險; 市場交易時間錯配; 託管與營運風險; 區塊鏈風險; 司法管轄限制。 一個有用的分析框架是: AI 基礎設施
2026/09/14
Lumentum 與 Coherent:兩大 AI 光學領導者的差異

Lumentum 與 Coherent:兩大 AI 光學領導者的差異

摘要 Lumentum Holdings 和 Coherent Corp. 均已成為AI資料中心光學需求上升的主要受益者。 這項比較在2026年3月變得尤為重要,當時NVIDIA宣布對兩家公司各進行20億美元的戰略投資。兩項協議均包含數十億美元的採購承諾和未來產能權利。 但Lumentum和Coherent並非完全相同的企業。 Lumentum按營收計算規模較小,且高度專注於與雲端和AI網路相關的
2026/09/14
查看更多

4 最新動態

查看更多
從稀缺交易到估值紀律:SpaceX的回調考驗OpenAI的IPO野心

從稀缺交易到估值紀律:SpaceX的回調考驗OpenAI的IPO野心

據報導,OpenAI 傾向將其 IPO 推遲至 2027 年,但更強烈的市場訊號來自 SpaceX。SpaceX 於 6 月 22 日收盤下跌了 16.4%,收於 154.60 美元,較盤中高點 225.64 美元降低了 31.5%,但仍較其 135 美元的 IPO 價格高出 14.5%。這一走勢使 SpaceX 從一個由稀缺性驅動的 IPO 成功案例,轉變為 AI 相關超大型上市週期中首個重大公開市場壓力測試。 OpenAI 的問題不在於需求,而在於估值。路透社引用《紐約時報》的報導指出,OpenAI 正考慮等待至 2027 年,以維持高達 1 兆美元的估值目標,而顧問將此選擇定調為:要麼等待達到該估值,要麼以較低目標提前上市。 預測市場已開始反映這種謹慎態度。Polymarket 的 OpenAI IPO 市場近期顯示,OpenAI 在 2026 年 12 月 31 日前完成 IPO 的機率約為四分之一,這表明交易者不再將近期上市視為明確的基本情境。對於加密貨幣交易者而言,這使得 AI 上市前的曝險從單向的稀缺性交易,轉變為與公開市場基準掛鉤的估值紀律交易。
2026/06/29
Coldcard Mk3 警告隨 $38M Bitcoin 掃蕩而來,但原因仍未確認

Coldcard Mk3 警告隨 $38M Bitcoin 掃蕩而來,但原因仍未確認

比特幣硬體錢包製造商 Coinkite 已警告用戶,Coldcard 裝置存在種子生成問題,影響範圍涵蓋所有 4.0.1 及更高版本的 Mk3 韌體。此警告是在安全研究人員調查一宗涉及 594.48 BTC(價值約 3,800 萬美元)的協調性盜取事件時出現的。然而,目前尚無公開的技術證據證實 Coldcard 的問題導致了這些轉帳。
2026/07/31
Mastercard 完成對 BVNK 的收購,金額高達 18 億美元——穩定幣進入全球支付核心

Mastercard 完成對 BVNK 的收購,金額高達 18 億美元——穩定幣進入全球支付核心

Mastercard 於三月宣布該交易後,已於 2026 年 8 月 3 日(UTC +8)完成對穩定幣基礎設施供應商 BVNK 的收購。
2026/08/04
查看更多