NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
NewsLayer PulseLIVEBTC$78,288-1.66%ETH$2,471-1.36%SOL$103-2.58%XRP$1.4-1.17%DOGE$0.0892-2.41%ADA$0.218-2.60%Total Cap$2.80T-0.99%Layer Index43 Neutral

Crypto

breaking

Attackers Drained 4,000 Bitcoin From Blockstream's Liquid Network. They Say They Are White Hats and Want to Give It Back.

A bug in Liquid's code let someone mint Bitcoin-backed tokens out of thin air, drain 95% of the federation wallet, and then claim they did it to help. Whether that story holds up depends on what happens to the coins…

24/7 Wall St.

Publisher

Sep 8, 2026 at 12:31 PM UTC · 5 min read

Attackers Drained 4,000 Bitcoin From Blockstream's Liquid Network. They Say They Are White Hats and Want to Give It Back.
Image via 24/7 Wall St.

Entities

bitcoin

Last Updated

3 minutes ago

A bug in Liquid's code let someone mint Bitcoin-backed tokens out of thin air, drain 95% of the federation wallet, and then claim they did it to help. Whether that story holds up depends on what happens to the coins…

This post may contain links from our sponsors and affiliates, and Flywheel Publishing may receive compensation for actions taken through them.

Around 4,000 Bitcoin (CRYPTO:BTC), worth about $320 million, drained out of the Liquid Network federation wallet on September 6, 2026, and Blockstream says no private key was stolen. The wallet held about 4,200 BTC before, so 95% of the Bitcoin backing the sidechain left in one transaction. Blockstream paused the network and blocked redemptions, so holders of L-BTC, the token meant to represent Bitcoin one-for-one on Liquid, can’t convert it back into real coins.

Ordinary Bitcoin holders on the base layer aren’t affected, with Bitcoin’s price trading around $79,700–$80,000 at the time of the incident. The attackers attached a message to the transaction saying, “we are whitehats. contact us on chain,” and Blockstream responded on-chain the same day. A white hat is generally expected to report a vulnerability responsibly rather than take funds first, which makes the incident harder to classify. So how much of this is a real security event, and how much is theater?