started · updated
Liquid Network exploit results in theft of 4,000 Bitcoin
The Liquid Network, a Bitcoin sidechain developed by Blockstream, suffered a major security exploit on September 6, 2026. Attackers exploited a software bug in the Elements codebase, specifically a vulnerability in range proof verification caching, which allowed them to mint approximately 4,000 unbacked L-BTC tokens. These fraudulent tokens were then redeemed for genuine Bitcoin through the network’s peg-out mechanism, including via SideSwap’s authorization.
The theft initially drained nearly 95% of the federation wallet's reserves, valued at approximately $320 million at the time. However, the attackers, identifying themselves as white-hat hackers, engaged in on-chain negotiations with Blockstream using OP_RETURN messages and PGP-signed communications. They demanded that all bridge nodes be patched before returning the funds.
Following the application of a security patch, the attackers returned 3,400 Bitcoin to the Liquid Federation wallet. Approximately 598.5 Bitcoin, valued at roughly $47 million, remains outstanding. Blockstream confirmed that the core multisignature keys securing the federation wallet were not compromised, and the issue was strictly a software verification failure. The network has faced service disruptions as operators work to restore full functionality and implement further security upgrades.
Entities
Bitcoin · Blockstream · Elements · Liquid Network · SideSwap
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] The core multisignature keys securing the federation wallet were not compromised during the attack. blockcast.cc · securityaffairs.com
- [● 8 SOURCES] The Liquid Network suffered an exploit resulting in the theft of approximately 4,000 Bitcoin. t3n.de · crypto-times.jp · blockcast.cc · www.ad-hoc-news.de · www.blocktempo.com · +2 more
- [● 3 SOURCES] The attackers used SideSwap’s peg-out authorization to convert unbacked L-BTC into real Bitcoin. www.blocktempo.com · securityaffairs.com
- [● 4 SOURCES] The attackers identified themselves as white-hat hackers and negotiated via on-chain messages. t3n.de · blockcast.cc · www.blocktempo.com · thanhnien.vn
- [● 4 SOURCES] The exploit was caused by a software bug in the Elements codebase related to range proof verification caching. blockcast.cc · www.blocktempo.com · securityaffairs.com
- [● 6 SOURCES] Blockstream patched the software vulnerability and confirmed the recovery of 3,400 Bitcoin. crypto-times.jp · blockcast.cc · www.blocktempo.com · securityaffairs.com · thanhnien.vn
- [● 5 SOURCES] Approximately 598.5 Bitcoin remains outstanding following the return of 3,400 Bitcoin. blockcast.cc · www.blocktempo.com · securityaffairs.com · thanhnien.vn
- [● 2 SOURCES] The return of funds occurred after Blockstream confirmed that bridge nodes had been patched. www.blocktempo.com · securityaffairs.com