Attackers exploited a software bug, not a stolen key, to mint fake Bitcoin on a sidechain network, and kept roughly $47 million of it as a self-declared bounty.
An attacker exploited a caching flaw in the verification software underlying Blockstream's Liquid Network, a Bitcoin sidechain, on September 6, minting approximately 4,000 units of the network's Bitcoin-pegged token without backing. Within roughly 36 minutes, the attacker withdrew about 3,996 of those coins, worth roughly $320 million, through an approved exchange operator on the network. Blockstream has stated that no federation cryptographic key was compromised; the exploit targeted a bug in how the software verified transaction proofs, not the network's custody mechanism.
The attacker identified themselves as "white hat" via on-chain messages and returned approximately 3,400 of the minted coins, worth roughly $266 million to $272 million, the following day. The remaining roughly 598.5 coins, worth about $47 million, were kept as a self-declared bounty, and the most recent reporting available indicates the attacker retained that sum rather than returning it in full. The network paused deposits and withdrawals, and Blockstream reported patched infrastructure by September 8. Whether the network has fully resumed normal operations, and who ultimately bears the retained loss, both remain unresolved as of this writing.
Blockchain-forensics firm TRM Labs has characterized the exploit as the largest crypto theft of the year to date, a characterization attributed to that firm rather than independently verified against a comprehensive industry tally.
The more useful detail for anyone assessing sidechain risk is the mechanism. This wasn't a compromised private key or a bridge operator absconding with funds, the failure modes that have defined most major crypto losses. It was a bug in how the system verified its own transactions, a category of risk that exists independent of how well any individual party safeguards its keys. For a network built on a federation model specifically meant to avoid single points of custodial failure, that distinction matters more than the size of the number attached to it.
