Timeline
- 7.5
GalaChain exploit turns 74 signatures from failed transactions into $3M drain
GalaChain disclosed in a Sept. 14 postmortem that an attacker used 74 replayable signatures harvested from failed transactions — some dating back 55 days — to drain roughly 2 billion GALA (about $3 million) plus dozens of other tokens from nine wallets on Aug. 18. The chain paused its bridge during the attack and has since patched both the signature-scope-confusion flaw and the replay-key rollback weakness. The attack shows that a cryptographically valid signature is not the same as an authorized economic action, and that audits reviewing signature verification, replay protection, and execution separately can miss flaws that only appear when those systems interact. It also raises a governance question for chain operators: whether human-triggered emergency controls and valid-signature-based systems can react fast enough once exploitation is automated. GalaChain's verifier previously accepted EIP-712 type definitions supplied with the request instead of deriving them from the invoked operation, so a signature covering one field set could be presented while a different method executed — one on-chain example shows a TransferToken call moving about 1.64 billion GALA while the supplied EIP-712 structure described an AddLiquidity operation. Because unique transaction keys could roll back when a transaction failed, the signature stayed visible on the public ledger while its replay key remained available; 57 of the 60 historical source transactions linked to the exploit contained at least one failed inner operation, and investigators reported no evidence that private keys, seed phrases, or passwords were compromised.
- 8.5
L-BTC Trading Reopens on SideSwap With Reserves Covering Only 85%
SideSwap reopened all of its L-BTC markets on Sept. 10 after the Liquid Network resumed block production in a controlled mode, while Liquid Federation peg-ins and peg-outs remained suspended. Readings at 22:55 UTC showed 4,229.33 L-BTC outstanding against 3,601.47 BTC at the cited federation reserve address, implying roughly 85.15% coverage and a shortfall of about 627.85 BTC. L-BTC 与 BTC 的 1:1 锚定是 Liquid 侧链的核心价值主张,而 peg-out 暂停后,市场价格已不再能保证按面值赎回,持有者无法确定能收回全部价值。这使个人用户资金、在 Liquid 上发行和结算资产的机构,以及托管 L-BTC 的交易所直接暴露于风险之中,也令联邦制侧链的信任模型受到更严格的审视。 Trading and redemption answer different questions: SideSwap operates a central-limit-order-book-style venue with L-BTC as the base asset and registered Liquid assets as quotes, and its documentation does not identify a direct L-BTC/BTC order book. No reproducible post-restart L-BTC/BTC price, bid-ask spread, depth or slippage data was public at publication time, so the actual discount or premium could not be measured, and the reserve ratio is a live reading (SideSwap's own Sept. 10 figures of 4,205 L-BTC and 3,597 BTC implied about 85.5% coverage and a 608 BTC gap) rather than a settled loss estimate.
- 8.5
Blockstream rejects Liquid attacker's ~600 BTC bounty demand
On Sept. 11, Blockstream publicly rejected the Liquid attacker's demand for a bounty of nearly 600 BTC (~$50 million) paid from Blockstream's own funds, after the attacker returned 3,400 of the roughly 3,996 BTC withdrawn in the Sept. 6 exploit. Blockstream said it would instead pursue the remaining funds through law enforcement, exchanges, service providers and forensic specialists if they are not voluntarily returned. The standoff sets a precedent for how crypto protocols handle exploit negotiations, weighing deterrence against restitution: refusing to pay may deter future attacks but could remove any incentive for hackers to return funds voluntarily. It directly affects Liquid users, whose network is only about 85% reserve-backed with peg-ins and peg-outs disabled. The attacker demanded a 10% bounty and warned that holders could otherwise face a roughly 15% shortfall; SideSwap said the wallet funding the attack traced through a cross-chain bridge to Tornado Cash, and that the attacker rehearsed the pattern with 70 similar transactions before the successful mint.
- 8.5
Blockstream Refuses Ransom After Liquid Bitcoin Exploit
Blockstream publicly refused to pay a ransom for roughly 598.5 BTC (about $47 million) still held by attackers after an exploit on the Liquid Network sidechain that drained around 4,000 BTC, worth roughly $320 million, on Sunday. The attackers returned 3,400 BTC (about 85%) on Monday, and Liquid resumed producing blocks and processing transactions on Thursday with peg-outs still disabled as a precaution. This is one of the largest confirmed losses on a Bitcoin sidechain, and the reserve backing Liquid's L-BTC fell as low as 197 BTC, raising questions about the security assumptions of federated bridges that many exchanges and traders rely on for fast, confidential Bitcoin transfers. Blockstream's refusal to pay also sets a public precedent for how infrastructure developers respond to exploiters demanding bug bounties under threat. The root cause was a flaw in how Liquid nodes cache range-proof verifications, which let attackers mint unbacked L-BTC and swap it for reserve Bitcoin through SideSwap, a federation member that held a peg-out authorization key; no private keys were reported stolen. Blockstream patched bridge nodes within ten hours and shipped Elements v23.3.4 on Wednesday, and separately warned that scammers are targeting node operators with fake update sites.
- 8.5
Liquid Network resumes block production after $320M exploit
The Liquid Network resumed block production on Thursday after deploying emergency software updates, though transactions and peg operations remain suspended as a precaution while the network is monitored for full stabilization. The restart follows an incident on Sept. 6 in which roughly 4,000 BTC, worth about $320 million, was withdrawn from the network's federation wallet via a bug in the Elements software. Liquid is one of the largest and longest-running Bitcoin sidechains, and the withdrawal drained roughly 95% of its federation wallet's balance, exposing how concentrated trust in federated bridge designs can translate into systemic risk. The incident affects L-BTC holders, issuers of tokenized assets and stablecoins on Liquid, and the exchanges and market makers that rely on it for settlement. The attacker exploited a proof-verification cache vulnerability in Elements' range proofs, allowing the minting of roughly 4,000 unbacked L-BTC that were then redeemed for real BTC through SideSwap's authorized exit peg path. The emergency patch, Elements v23.3.4, hardened the cache keys used for range proofs; after affected bridge nodes were patched, 3,400 BTC (about $270 million) was returned, leaving roughly 598 BTC (about $46 million) outstanding as of Sept. 7.
- 8.5
Liquid Network Bitcoin Hack Drains $320 Million
The Liquid Network, a blockchain settlement layer used by several cryptocurrency exchanges to move Bitcoin, was hacked for $320 million. The network halted all transactions after the exploit, which was reported around September 7, 2026. This is one of the latest major breaches to shake confidence in digital-asset security, and it exposes risks in the settlement infrastructure exchanges depend on. The incident may lead to stricter scrutiny of sidechain security and affect trust in exchange-related Bitcoin custody and transfer methods. Liquid Network is a Bitcoin sidechain designed to allow faster and more confidential transfers between exchanges. CoinDesk reported that the hacker made a conditional offer, with the attackers claiming they were 'the good guys.'
- 9.0
Liquid Network hackers steal $320M in Bitcoin, return most after patch
Attackers exploited a vulnerability in Liquid Network's Elements software to mint unbacked L-BTC and drained roughly 4,000 BTC (~$320 million) from its reserve. About 3,400 BTC were returned on Sept. 7, and Blockstream is negotiating to recover the remaining ~600 BTC after patching bridge nodes and preparing an emergency update. This is one of the largest exploits involving a Bitcoin sidechain and directly tests how much trust users place in federated pegs and wrapped Bitcoin products. It shows that transaction-validation failures can jeopardize user funds even when no private keys or federation nodes are compromised. Liquid's reserve fell from about 4,205 BTC to 197 BTC before operations were halted; Liquid said USDT and other Liquid-issued tokens were unaffected by the vulnerability, though users could not transact during the pause. The validation failure occurred at the transaction level before the peg-out was initiated, so SideSwap's node and Liquid's distributed functionary nodes accepted the unbacked L-BTC, and roughly 600 BTC (~$47 million) remains outstanding.
- 9.0
Liquid Hackers Return $270M in Bitcoin After $320M Theft
Hackers who breached the Liquid exchange returned about $270 million in Bitcoin after initially stealing roughly $320 million, according to the report. The partial return leaves approximately $50 million in stolen crypto still unaccounted for. A breach of this size at a cryptocurrency exchange reveals custodial risk and can seriously undermine user confidence in centralized platforms. Partial restitution limits the damage, but the unresolved remainder and the security failure itself may invite stricter regulatory scrutiny and push more users toward self-custody. The attackers initially moved around $320 million in Bitcoin off Liquid, then returned about $270 million, leaving roughly $50 million still missing. Because Bitcoin transactions are recorded on a public ledger, the movement of funds could be observed on-chain before and after the return.
- 8.5
Liquid Sidechain Paused After 3,998 BTC Leaves Federation Wallet
Blockstream's Liquid sidechain disabled its bridge nodes after nearly all the bitcoin reserves backing L-BTC, approximately 3,998 BTC, were withdrawn to a single address. The recipient wrote "we are whitehats" in the transaction. This event is significant because L-BTC is a 1:1 Bitcoin-backed asset, and the safety of its peg depends on the federation wallet's reserves. If the withdrawn Bitcoin is not fully secured and returned, trust in Liquid and similar sidechains could be shaken. The move reduced the federation wallet's Bitcoin reserves to near zero, potentially preventing peg-outs until the coins are returned. The address owner's "we are whitehats" message suggests a claimed rescue, but official confirmation has not been published.