Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Liquid Network Hackers Return Most Bitcoin, M Still Held

Liquid Network Hackers Return Most Bitcoin, $47M Still Held

Posted on September 8, 2026 By CWS

On September 6, 2026, a significant security breach occurred within the Liquid Network, leading to the misappropriation of nearly 4,000 Bitcoin. The following day, approximately 3,400 Bitcoin were returned to the network, while 598.5 Bitcoin remain unaccounted for. This incident has drawn considerable attention within the cryptocurrency community, highlighting vulnerabilities within blockchain systems.

Details of the Liquid Network Breach

The Liquid Network, a Bitcoin sidechain that supports a token known as L-BTC, suffered a major setback when unauthorized access resulted in the withdrawal of a substantial portion of its Bitcoin reserves. The federation, responsible for holding the Bitcoin backing L-BTC, received 3,400 Bitcoin back on September 7. The remaining 598.5 Bitcoin, however, were not transferred back, leaving a notable deficit.

According to blockchain records, the withheld Bitcoin transacted back to its original address but has not been retrieved. Blockstream, the technology provider for Liquid, has not confirmed whether this Bitcoin is part of any agreement.

Investigation and Response

Blockstream disclosed that the breach was executed by hackers claiming to be white hats, who withdrew approximately 4,000 Bitcoin valued at $320 million at the time. This withdrawal accounted for 95% of Liquid’s total Bitcoin reserves, initially reported as 4,200 Bitcoin.

The Bitcoin’s retrieval was facilitated through SideSwap’s Peg-out Authorization Key, which remained uncompromised according to Blockstream. A flaw in the Elements software, which Liquid operates on, was exploited to create the L-BTC used in the withdrawal. Despite the incident, SideSwap confirmed that neither its systems nor its keys were compromised.

Ongoing Developments and Community Reaction

Communications between the parties involved transpired publicly on the Bitcoin blockchain. The hackers requested the flaw be rectified and all nodes updated before returning any Bitcoin. Following assurances from Blockstream that necessary patches were applied, a small transaction confirmed the transfer of 3,400 Bitcoin back to the federation.

Samson Mow, former Blockstream executive, indicated that negotiations with the hacker group continue, with the unreturned Bitcoin totaling approximately 598.5. As of September 8, Blockstream’s status page still marked the incident as unresolved, with public bridge nodes inactive.

While Blockstream advises users against depositing Bitcoin to Liquid’s peg-in addresses until a restart is confirmed, other Liquid-issued assets remain unaffected. However, not everyone agrees with the hackers’ white-hat claim. Charles Guillemet from Ledger views the arrangement, if involving a reward, as closer to extortion.

The situation underscores the importance of robust security measures in cryptocurrency platforms and raises questions about the ethical boundaries of white-hat hacking.

The Hacker News Tags:Bitcoin, Blockchain, Blockstream, crypto vulnerability, Cryptocurrency, Cybersecurity, Elements bug, Hack, L-BTC, Ledger, Liquid Network, peg-out, Samson Mow, SideSwap, white hat hackers

Post navigation

Previous Post: Reflectiz Unveils Advanced Website Penetration Testing
Next Post: Cylake Secures $245M for AI Cybersecurity Platform

Related Posts

Breaches Hidden, Attack Surfaces Growing, and AI Misperceptions Rising Breaches Hidden, Attack Surfaces Growing, and AI Misperceptions Rising The Hacker News
Critical Flaw in Palo Alto PAN-OS Allows Remote Code Execution Critical Flaw in Palo Alto PAN-OS Allows Remote Code Execution The Hacker News
Cyber Campaign Targets Ukrainian Health and Government Cyber Campaign Targets Ukrainian Health and Government The Hacker News
5 Ways Identity-based Attacks Are Breaching Retail 5 Ways Identity-based Attacks Are Breaching Retail The Hacker News
Iranian Hackers Target U.S. Networks with New Malware Iranian Hackers Target U.S. Networks with New Malware The Hacker News
Key Insights from Gartner’s Guardian Agents Guide Key Insights from Gartner’s Guardian Agents Guide The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Claude Mythos AI Completes Cyber Kill Chain Autonomously
  • Unseen Threats: How Hidden Prompts Manipulate AI
  • Brazilian Financial Firms Targeted by Slim Spider for Crypto Theft
  • Mars Security Unveils Instant Threat Detection Engine
  • Cylake Secures $245M for AI Cybersecurity Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Claude Mythos AI Completes Cyber Kill Chain Autonomously
  • Unseen Threats: How Hidden Prompts Manipulate AI
  • Brazilian Financial Firms Targeted by Slim Spider for Crypto Theft
  • Mars Security Unveils Instant Threat Detection Engine
  • Cylake Secures $245M for AI Cybersecurity Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark