Logo
My Crypto News AI

September's First Week Brings $322 Million in Crypto Hacks, With Liquid Network Losing $320 Million Alone

Cryptocurrency exploits recorded between September 1 and 7 totaled roughly $322 million, with a single incident on Blockstream's Liquid Network accounting for more than 99% of the reported losses. The week highlighted how concentrated risk can be in cross-chain bridge infrastructure, even when individual blockchains remain secure. The remaining losses were spread across four confirmed exploits on Ethereum, BNB Chain, and the XRP Ledger (XRPL).

What Happened to Liquid Network's $320 Million?

On September 6, a customer initiated a peg-out transaction on Blockstream's Liquid Network, a Bitcoin sidechain designed to enable faster and more private transactions. The user sent 4,000 Liquid Bitcoin (L-BTC) to the SideSwap decentralized exchange's peg-out service at 14:05 UTC. The L-BTC was burned under valid authorization, and at 14:28 UTC, the Liquid Federation released approximately 3,996 BTC on the Bitcoin main chain, valued at roughly $320 million at the time.

What made this incident unusual was the response. An on-chain message attached to a follow-up Bitcoin transaction read, "we are whitehats. contact us on chain." This suggested the party responsible for the exploit was claiming to be a security researcher acting in good faith. Blockstream replied on-chain, asking the party to contact security@blockstream.com. Later messages indicated that most of the coins would be returned after every node was patched.

Independent on-chain analysis pointed to a range-proof cache flaw in Elements, the open-source software that powers Liquid's confidential-transaction system. A fix had been merged into the Elements repository but was not included in the tagged build running on the network at the time of the incident.

"The conventional white-hat practice is to disclose a flaw before moving a large reserve rather than after," noted Charles Guillemet, Chief Technology Officer at Ledger.

Charles Guillemet, Chief Technology Officer at Ledger

Why Are Crypto Bridges Such Attractive Targets?

Bridges are protocols that allow digital assets and data to move between separate blockchains. Most blockchains operate independently and cannot recognize transactions or tokens from other networks, so bridges create the infrastructure to make cross-chain transfers possible. For example, a user holding ETH on Ethereum who wants to use a DeFi application on Base, where transaction fees are much lower, can use a bridge instead of selling their assets and repurchasing them on a different network.

The problem is that while Bitcoin and Ethereum rely on massive decentralized validator networks to secure transactions, bridges often rely on smaller groups of validators, multisignature wallets, or complex smart contracts. This creates additional attack surfaces that hackers find attractive. The Liquid Network incident is just the latest example of how even well-established bridge infrastructure can harbor critical vulnerabilities.

History shows the scale of bridge-related losses. The Ronin Bridge hack resulted in approximately $625 million in stolen crypto when attackers compromised validator keys. The Wormhole Bridge lost around $320 million after hackers exploited a flaw in its transaction verification system. The Nomad Bridge suffered losses of about $190 million in a separate attack.

What Other Exploits Occurred During the Week?

Beyond the Liquid Network incident, four other confirmed on-chain drains occurred across Ethereum, BNB Chain, and the XRP Ledger. On Ethereum, the decentralized finance (DeFi) fixed-rate lending protocol Notional Finance suffered a drain of an escrow contract worth about $1.73 million. The alleged attacker exploited an integer overflow in an unsafe signed-to-unsigned downcast used in Notional's free-collateral valuation, which allowed a fabricated liability to be truncated to zero so the position registered as debt-free. The attacker converted the stolen stablecoins into approximately 689.2 Ether (ETH) and deposited them into the privacy tool Tornado Cash.

On the XRP Ledger, a sweep of XRPH Wallet, a mobile application published by the XRP Healthcare project, emptied 4,011 user wallets in about three hours starting on September 3. The haul totaled approximately 267,664 XRP alongside XRPH and XRPHAI tokens, with a combined value of about $452,000. Forensic analysis attributed the breach to a design flaw in the wallet's staking feature, which transmitted users' seed phrases to a remote XRP Healthcare server when staking was activated.

On BNB Chain, an award-contract flaw in Dream Health Chain allowed a claimant to reset a claimed award and claim it repeatedly, resulting in losses between $71,800 and $72,000 in USDT-equivalent value. Also on Ethereum, a single-transaction flash-loan exploit against Reddio's RedSonic Vault netted approximately 9.25 ETH, valued at roughly $23,000.

How to Reduce Your Risk When Using Crypto Bridges

While no bridge is completely secure, asset holders can take practical steps to reduce their exposure to bridge-related hacks and errors:

  • Use Established Protocols: Stick to bridges that have undergone independent security audits and have maintained a strong operational history over time.
  • Verify Networks Before Transferring: Double-check both the source and destination networks before making any transfers, as sending assets to the wrong blockchain can result in permanent loss if the wallet lacks a recovery option.
  • Test with Small Amounts First: Send a small amount as a test transfer before moving larger sums, even though this results in extra fees, to verify the bridge is functioning correctly.
  • Avoid Unsolicited Bridge Links: Do not use bridge links shared through social media, messaging apps, or unsolicited direct messages, as these are common vectors for phishing attacks.

What Does This Mean for the Broader Crypto Ecosystem?

The concentration of losses in a single bridge incident underscores a critical vulnerability in Web3 infrastructure. The Liquid Network incident, while claimed to be a white-hat disclosure, demonstrates that even mature, well-funded bridge projects can harbor critical flaws that go undetected until they are exploited. The fact that a security fix existed but was not deployed in the active build highlights gaps between development and production environments.

The week's events also show that bridge vulnerabilities remain distinct from blockchain security. None of the incidents involved breaking the actual blockchains underlying the transfers. The distinction is important because it shows that even the most secure blockchains are vulnerable to hacks when assets are moving between them.

As users continue to move assets across multiple chains to access lower-fee DeFi applications, NFTs, and gaming platforms, bridge security will remain a critical concern for the industry. The $322 million in losses during a single week serves as a reminder that cross-chain infrastructure requires the same level of scrutiny and investment in security as the blockchains themselves.