Observed Signal · Sep 7, 2026 · Security Incident · Source: Trending Topics (DACH/CEE Innovation & Tech) · Impact: 3/5 · Sentiment: Negative

Bitcoin Sidechain Liquid Network Hit by $320M Exploit

Executive Signal Summary

The Liquid Network, a Bitcoin sidechain operated by Blockstream, suffered a significant security breach in which attackers stole approximately 4,000 BTC (worth around $320 million) by exploiting a software vulnerability that allowed the exchange of unbacked L-BTC. The attackers, claiming to be white-hat hackers, offered to return most of the funds if Blockstream patched the bug. After the patch was applied, around 3,400 BTC were returned to the network's wallet, while about 598.5 BTC (worth ~$47 million) remained in the hackers' possession, possibly as an unplanned bug bounty. The vulnerability was traced to a caching flaw in Blockstream's Elements software, specifically in the Confidential Transactions validation process, which allowed counterfeit token creation. The federation's multisig and PAK mechanisms were not compromised. The network remains paused while security enhancements are implemented before a safe restart.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Significant security exploit affecting a Bitcoin Layer-2 sidechain, with implications for the broader crypto and blockchain ecosystem, but limited direct relevance to AdTech/MarTech.

SIGNAL RADAR

Track Crypto.com Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Approximately 4,000 BTC (worth ~$320 million) were stolen from the Liquid Network, with around 3,400 BTC returned after the vulnerability was patched.
  • The hack was enabled by a software bug in Blockstream's Elements software, specifically a caching flaw in Confidential Transactions validation, allowing creation of unbacked L-BTC.
  • The attackers, claiming to be white-hat hackers, returned most funds after the patch; about 598.5 BTC (worth ~$47 million) remain in their wallet.
  • The federation's multisig and PAK mechanisms were not compromised; the bug was in the validation logic.
  • The Liquid Network remains halted while security enhancements are made before restarting.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: Trending Topics (DACH/CEE Innovation & Tech)•Published: Sep 7, 2026
Original Coverage Title: “320 Mio. Dollar in Bitcoin abgeflossen: Was beim Hack des Liquid Network passiert ist”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

SecuritySep 7, 2026

Liquid Network Bitcoin Sidechain Hit by $320M Exploit

The Liquid Network, a Bitcoin sidechain used by crypto exchanges, was hit by a $320 million exploit, with roughly 4,000 bitcoin withdrawn from its federation wallet. The network has been halted as bridge nodes were disabled and exchanges paused L-BTC deposits and withdrawals. The incident stems from a bug in the Elements software, which allows the creation of unbacked L-BTC. The attackers, claiming to be white-hat hackers, have offered to return most of the funds if the bug is patched. The event raises questions about the security of sidechains and bridges.

Read assessment
SecuritySep 25, 2026

Bitget Loses $352 Million in Hack, CEO Suspects North Korea

Cryptocurrency exchange Bitget reported a hack involving unauthorized transfers from its hot and warm wallets, totaling approximately $351.6 million. CEO Gracy Chen suspects North Korean hackers based on IP address analysis, though attribution is not fully confirmed. The attackers breached a central backend system, forged transfer details, and initiated the exchange's authorized signature process without compromising private keys. Bitget has suspended withdrawals but trading continues, and its cold wallets remain unaffected. The company's Protection Fund, exceeding $465 million, is intended to cover the loss, supplemented by over $1 billion in equity. This incident echoes the February 2025 Bybit hack, also attributed to North Korean actors, which involved a compromised Safe{Wallet} developer machine and resulted in a $1.5 billion theft. Bitget had previously lent Bybit 40,000 ETH to help it recover from that attack.

Read assessment
SecurityJun 25, 2026

Hackers stole funds from Polymarket users

Polymarket, a prediction market platform, confirmed hackers stole users’ funds after a compromise at a third-party vendor allowed malicious code to be injected into its website for some users. Polymarket said it has contained the incident, is contacting affected users and will refund victims in full. Blockchain monitoring firm PeckShield reported a related phishing campaign and estimated about $3 million in cryptocurrency was stolen; a blockchain analyst said losses affected more than 11 victims. Polymarket’s spokesperson confirmed the theft but declined to provide further details. The breach follows separate recent scrutiny of Polymarket over deceptive promotional content, which the company said it would audit.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.