BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Sep 8, 2026 · 2 min read · Original story

‘White hat’ hackers take $47 million bounty after $320 million crypto theft

‘White hat’ hackers take $47 million bounty after $320 million crypto theft
‘White hat’ hackers take $47 million bounty after $320 million crypto theft

A public, hours-long negotiation between hackers and a cryptocurrency firm on Sunday ended with the attackers keeping $47 million of a $320 million theft as a “reward” for identifying what they said was a bug in the company’s platform.

The trading platform Liquid Network said on Sunday that “purported white-hat hackers” withdrew 4,000 BTC ($320 million) from its own wallet. Blockstream, which runs Liquid, pledged to reach out to the hackers and said deposits and withdrawals were paused. Liquid supports a coin pegged to the price of bitcoin.

Over the next 12 hours, the company negotiated in public on the blockchain with the hackers, who initially wrote, "we are whitehats, contact us on chain" in a message attached to the transaction bridging the $320 million out of Liquid’s account.

“Sending most back…is that ok," the hackers said, before demanding Blockstream fix an alleged vulnerability.

"Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix," they added.

After several public and private messages back and forth, the hacker sent $266.5 million worth of bitcoin back to Liquid on Monday morning and kept 598.5 BTC — worth about $47 million — as reward. The two sides have continued to go back and forth in public but encrypted messages on the blockchain.

On Monday morning, Blockstream confirmed the negotiations and said “updated software” was deployed as they ramped up to restart the system.

The incident set off a fierce debate on social media and in blog posts about the source of the vulnerability. Blockstream and Liquid did not respond to requests for comment.

SideSwap, the service the hacker used to get the stolen funds out of Liquid, published a post-mortem that said Blockstream believes the issue was sourced back to a vulnerability in the Elements software. Several other blockchain security experts also traced the issue back to Elements.

Elements, founded in 2015, allows people to create blockchains extending from bitcoin’s codebase. On its website, the organization said an “example of an Elements based sidechain in production use is Blockstream’s Liquid.”

Backed by several other major cryptocurrency players, Blockstream launched Liquid in 2018 as a way to enable faster bitcoin transactions, claiming to “improve a broken financial system” and “extend Bitcoin's use cases into the realm of new capital markets.”

The $320 million stolen on Sunday would be one of the largest cryptocurrency thefts in 2026 after a pair of April incidents saw alleged North Korean hackers steal $290 million and $280 million respectively from the Kelp and Drift platforms.

References in this story

  1. Liquid Network 🌊 (@Liquid_BTC) on X x.com We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain…
  2. https://mempool.space/tx/3a3eac4a26395b8c2563aaf1eb8b1b77798c81c7d6337f51321827a244a480aa t.co
  3. https://mempool.space/tx/a6d697a25266ce3c78774fd1d75f896b7af522ada209b0f6228ea497bc49a46d t.co
  4. Blockstream (@Blockstream) on X x.com Following the recent incident affecting the Liquid Network and the movement of funds, Blockstream, as Liquid’s technical provider, and the Liquid Federation have been working diligently to resolve the ongoing situation…
  5. SideSwap (@side_swap) on X x.com Statement on today's Liquid incident Today at 14:05 UTC a customer sent 4,000 L-BTC to the SideSwap peg-out service. Our service processed it like any other order: the L-BTC was burned on Liquid with a valid peg-out…
  6. Liquid Network Incident Analysis - CertiK www.certik.com On 6 September 2026, the Liquid Network was exploited through a vulnerability in the Elements codebase used to validate Confidential Transactions. The issue stemmed from an ambiguous cache-key encoding in the rangeproof…
  7. Elements elementsproject.org Elements - an open source, sidechain-capable blockchain platform.
  8. Crypto infrastructure company blames $290 million theft on North Korean hackers therecord.media A theft of nearly $300 million worth of cryptocurrency has been attributed to hackers from North Korea, as the industry grapples with the fallout of a wide-ranging incident involving multiple prominent platforms.
  9. ‘It reads like a spy novel’: $280 million theft from Drift involved North Korean fake companies, cutouts therecord.media Drift officials said the operation began six months ago, when they were approached at a cryptocurrency conference by members of a company claiming to focus on quantitative trading.
  10. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  11. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  12. jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
  13. jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51

Guides related to this story

← Back to all news