
Share
A bug in a bitcoin settlement network used by major exchanges let an attacker drain roughly 4,000 bitcoin. Most came back once the flaw was patched, but the episode exposes how fragile crypto infrastructure trust remains.
A hacker exploited a bug in Liquid Network, a bitcoin settlement layer used by several cryptocurrency exchanges, and withdrew roughly 4,000 bitcoin worth about $340 million. That makes it one of the largest crypto thefts of the year. Most of the money is already back.
Liquid Network, launched in 2018 by crypto infrastructure firm Blockstream, disclosed the incident in a post on X on Sunday. The company said a "white hat" hacker took the funds from the network's wallet and confirmed it had paused all operations while it investigates. Crypto media outlet CoinDesk reported that the attacker claimed to have exploited a bug and offered to return the stolen bitcoin if Blockstream fixed the underlying flaw. That framing, a hacker positioning themselves as a benevolent actor rather than a thief, has become a familiar pattern in crypto exploits over the past several years.
By Monday, former Blockstream executive Samson Mow said in a post on X that the bug had been fixed and that around 3,400 of the roughly 4,000 stolen bitcoin had already been returned. That leaves about 600 bitcoin, worth roughly $47 million, still under the hacker's control. Mow said Liquid Network will stay offline until additional security improvements are completed and verified.
Most crypto thefts fall into one of two buckets: money that is gone for good, or money recovered through negotiation, law enforcement pressure, or bounty payments. This case sits closer to the second category, but with an unusual twist. The attacker appears to have returned the bulk of the funds voluntarily and quickly, tying the return to a specific technical demand rather than a ransom payment.
The scale still matters. At $340 million, this ranks among the largest crypto exploits tracked by Rekt, a leaderboard that catalogs cryptocurrency thefts across the industry. Even with roughly 3,400 bitcoin returned, the incident sits alongside some of the biggest breaches in crypto history by initial exposure.
Liquid Network's role as settlement infrastructure for multiple exchanges is what elevates this beyond a single-platform problem. When a settlement layer that other businesses depend on gets exploited, the blast radius extends well past Blockstream's own balance sheet. Exchanges relying on Liquid for interoperability and liquidity now face their own operational disruptions while the network stays paused.
The bug itself has not been publicly detailed beyond the fact that it has been patched. That is fairly standard practice after an active exploit, but it leaves outside auditors and rival platforms unable to independently assess whether the vulnerability class shows up elsewhere. Given how much of the crypto ecosystem shares code, wallet architecture, and settlement logic across platforms, that opacity is a real limitation for anyone trying to gauge systemic risk here.
There is also the matter of the roughly $47 million still outstanding. Blockstream and Mow have not detailed what happens next if the remaining bitcoin isn't returned. Does the company pursue legal action? Does it treat the balance as a de facto bounty payment for finding the bug? The lack of clarity on that point is a gap worth watching.

For investors and institutions with exposure to bitcoin infrastructure, this incident is a reminder that "settlement layer" does not mean "risk-free layer." Liquid Network was built specifically to give exchanges faster, more efficient bitcoin transfers. It is not a consumer-facing wallet or a speculative altcoin project. The fact that a bug this severe existed in infrastructure marketed as institutional-grade should prompt a harder look at how these systems get audited before launch and after updates.
The speed of the partial recovery is a mildly positive signal. Unlike heists where funds vanish into mixers and cross-chain bridges within hours, this attacker left a paper trail and appears to have engaged with Blockstream directly. Whether that reflects genuine ethical hacking intent or a calculated bet that returning most of the funds reduces legal exposure is unclear. Either way, the outcome was better than the alternative.
The risk for exchanges relying on Liquid Network is more immediate. Extended downtime on settlement infrastructure creates operational friction, delayed transfers, and potential liquidity mismatches for platforms that built workflows around it. Blockstream has not given a timeline for when operations resume, only that it will happen after further security improvements are verified.
There is a broader pattern here too. Crypto's largest hacks increasingly target infrastructure rather than end users, a shift from the exchange hacks of the 2010s toward attacks on bridges, settlement layers, and smart contract logic. That shift raises the stakes for institutional adoption of crypto rail systems, since a single infrastructure bug can now cascade across multiple downstream businesses simultaneously.
The numbers here are worth holding onto. Roughly 4,000 bitcoin were stolen, valued at approximately $340 million at the time of the theft. About 3,400 bitcoin, close to $290 million at current pricing, was returned within roughly 24 hours of the initial disclosure. That leaves approximately 600 bitcoin, or $47 million, unaccounted for and still in the hacker's possession.
Blockstream has not confirmed a restart date for Liquid Network. Until it does, exchanges and users dependent on the platform are effectively locked out of settlement services that route through it. For an infrastructure provider serving multiple exchange clients, that downtime carries its own reputational and commercial cost, separate from the dollar value of the stolen funds themselves.
The episode is unlikely to be the last of its kind. As crypto infrastructure grows more interconnected, the incentive for attackers to target shared settlement and bridging systems, rather than individual wallets, will only increase. Investors watching this space should treat bug bounty programs, third-party audits, and incident response speed as core due diligence items, not afterthoughts.
Tags
Original Sources
A hacker stole $340M in a crypto heist, then returned most of it | TechCrunch
↗ https://techcrunch.com/2026/09/08/a-hacker-stole-340m-in-a-crypto-heist-then-returned-most-of-it
About the author
Marcus began tracking AI's market implications in 2016, noticing AI-related patent filings accelerating ahead of earnings upgrades before most of the sell-side had caught on. A former fixed-income quantitative analyst, he spent two decades building models that priced risk across emerging markets before pivoting to cover the economic impact of AI full-time. His writing translates opaque technical developments into clear risk/reward terms — and he's rarely diplomatic about the gap between AI valuations and underlying fundamentals. He believes most market participants still underestimate AI's long-run deflationary effect on knowledge work.
More from The Analyst →This Week's Edition
9 September 2026
28 articles
Related Articles

Anthropic Faces Class Action Over Claude Max Subscription Marketing
Security & Risk · 5 min

Parakeet Health Signs Qualderm as AI Patient Access Platform Targets Specialty Care Bottlenecks
Products & Applications · 6 min

FDA Fills Top Drug and Vaccine Oversight Posts as Overton Nomination Advances
Policy & Regulation · 5 min
Related Articles

Anthropic Faces Class Action Over Claude Max Subscription Marketing
Security & Risk · 5 min

Parakeet Health Signs Qualderm as AI Patient Access Platform Targets Specialty Care Bottlenecks
Products & Applications · 6 min

FDA Fills Top Drug and Vaccine Oversight Posts as Overton Nomination Advances
Policy & Regulation · 5 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.