[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fT6-36oZI9tcZjVBD2-zB9bucuKq194Pzxfj1pwGXSWY":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"9470e2c3-4038-4820-9dcc-9af10a24431c","Hackers Return $263 Million Stolen From Liquid Network","hackers-return-263-million-stolen-from-liquid-network-e5b4ca","Alleged ‘white-hat’ hackers drained $320 million from Liquid’s federation wallet, demanding a bug fix. The post Hackers Return $263 Million Stolen From Liquid Network appeared first on SecurityWeek.","Alleged 'white-hat' hackers stole approximately $320 million in Bitcoin from the Liquid Network's federation wallet. They have since returned 3,400 Bitcoin, valued at around $262.6 million, with the remaining ~598 Bitcoin outstanding. The hackers claim they will return the rest once Liquid resolves the vulnerability that enabled the heist.","Hackers returned $263M of $320M stolen from Liquid Network, demanding a bug fix.","Alleged ‘white-hat’ hackers have returned 3,400 Bitcoin (worth approximately $262.6 million) of the 4,000 Bitcoin (~$320 million) stolen from the Bitcoin sidechain Liquid Network over the weekend. The Blockstream-developed sidechain disclosed the incident on Sunday, after disabling its nodes and suspending all transactions in response to the heist. “Exchanges have been notified and have already paused (or will pause) LBTC deposits and withdrawals. Other Liquid assets such as USDT, DePix, and RWAs are unaffected by this security incident,” Liquid said. The funds were drained from Liquid’s federation wallet, which held approximately 4,200 Bitcoin before the attack. However, it is unclear how the funds were stolen. “What we know so far is that the funds were withdrawn via the SideSwap PAK (Peg-out Authorization Key), but that key was not compromised, nor were any others,” Liquid said. “Liquid wallets will be impacted, and we’re sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity,” it added.Advertisement. Scroll to continue reading. The incident was claimed by alleged ‘white-hat’ hackers who said they would return most of the stolen funds as soon as Liquid resolves the vulnerability that led to the heist. “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” a blockchain message from the hackers reads. On Monday, 3,400 Bitcoin was returned to Liquid, but approximately 598 Bitcoin (~$47 million) remains outstanding as Blockstream continues to communicate with the hackers, former Blockstream executive Samson Mow said. “The network remains paused while Blockstream and Federation members make additional fixes and security improvements, resolve the chain split, and prepare for a safe restart. Liquid wallets and services will continue to be affected during this time,” Mow said. Related: Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft Related: $290 Million Kelp DAO Crypto Heist Blamed on North Korea Related: Mathspace Data Breach Exposes Over 1 Million People Related: OpenAI Agents Hijack Another Victim Website Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire North Korean Hackers Deploy New Linux Espionage ToolkitAdobe Commerce Zero-Day Exploited to Backdoor Online StoresModified ScreenConnect Clients Used in Worm-Like CampaignElementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesHPE Patches Critical RCE Vulnerabilities in AOS-CXSangoma Switchvox Vulnerability Exploited in the Wild12-Year-Old PostgreSQL Vulnerability Enables Database, Server TakeoverVMware Workstation and Fusion Updates Patch Critical Vulnerability Latest News The Hidden Instructions That Can Hijack AI AgentsCylake Raises $245 Million Ahead of Cybersecurity Platform BetaSAP Patches Critical Extended Passport Processing VulnerabilityParty’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin TheftMikroTik Patches Critical Flaws Chained to Hack RoutersMathspace Data Breach Exposes Over 1 Million PeopleN-able Patches Critical Zero-Day in N-centralNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fhackers-return-263-million-stolen-from-liquid-network\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2024\u002F08\u002Ftakedown-law-enforcement.jpeg","2026-09-08T16:35:54+00:00","2026-09-08T18:00:08.215636+00:00",7,[18,21],{"name":19,"type":20},"Liquid Network","product",{"name":22,"type":23},"Blockstream","vendor","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":24,"icon":26,"name":27,"slug":28},null,"Breaches","breaches",[30,35,37,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"0493c7e9-989a-4692-b4e6-136f5ec09675","Cryptography","cryptography",{"category":36},{"id":24,"icon":26,"name":27,"slug":28},{"category":38},{"id":39,"icon":26,"name":40,"slug":41},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[48],{"type":41,"value":49,"context":50},"SideSwap PAK","The funds were withdrawn via the SideSwap PAK (Peg-out Authorization Key), which was reportedly not compromised."]