Hacker drains 4,000 Bitcoin from Blockstream Liquid vault
- A software bug allowed a hacker to forge tokens and drain 4,000 BTC from Blockstream's Liquid network.
- The hacker returned 3,400 BTC but kept 600 BTC as an unapproved $48M bounty.
- Federated multisig signers blindly approved payouts because their nodes ran the flawed validation code.
A single caching bug wiped out Liquid's core reserves.
Jack Mallers detailed how an attacker printed 4,000 fake tokens out of thin air on The Jack Mallers Show. To speed up complex cryptographic checks, Liquid's Elements validation software cached range proof signatures. A software update failed to bind those signature keys to specific asset types. The hacker submitted a valid transaction to prime node memory, then immediately pushed a second transaction with a massive negative value, bypassing range checks completely.
The forged tokens passed directly to the network's withdrawal layer. On Ungovernable Misfits, hosts q and a explained that 11 federation signers approved the peg-out because their nodes relied on the same broken software consensus. The hacker swapped fake tokens for 4,000 real Bitcoin, draining $320 million from reserve vaults and leaving barely 200 coins on the sidechain.
The breach highlighted severe operational lapses. On Ungovernable Misfits, analyst Orange Surf revealed that a pull request fixing the exact caching bug had sat unmerged on GitHub since early September 2026. On Bitcoin And, host David Bennett warned that AI-powered vulnerability scanners now continuously sweep public repositories. Automated bots generate functioning exploits far faster than human maintainers can merge patches, turning unapplied fixes into instant targets.
The aftermath turned into a tense on-chain standoff. The hacker returned 3,400 Bitcoin to the network but retained nearly 600 BTC - worth roughly $48 million - as a self-assigned finder's fee. David Bennett reported on Bitcoin And that when Blockstream sent encrypted payloads pushing back on the fee, the attacker responded with a single sad-face emoji and broke off communication.
That refusal to return the full stash split the community. On Stacker News Live, host Keon rejected the hacker's attempt to label the breach a whitehat security audit, arguing that holding stolen funds hostage constitutes plain extortion. On Presidio Bitcoin Jam, analysts noted that all 15 federated entities had blindly trusted Blockstream's software update without running independent code audits, proving federated multi-sig setups inherit single-point-of-failure risks.
Federated sidechains promised institutional security without base-layer changes. But when code breaks, multi-sig consensus collapses instantly, leaving real Bitcoin exposed to software errors.