< Back to all clusters
[TECHNOLOGY] · UN · 12 sources

started · updated

Liquid Network exploit results in theft of 4,000 Bitcoin

The Liquid Network, a Bitcoin sidechain developed by Blockstream, suffered a major security exploit on September 6, 2026. Attackers exploited a software bug in the Elements codebase, specifically a vulnerability in range proof verification caching, which allowed them to mint approximately 4,000 unbacked L-BTC tokens. These fraudulent tokens were then redeemed for genuine Bitcoin through the network’s peg-out mechanism, including via SideSwap’s authorization.

The theft initially drained nearly 95% of the federation wallet's reserves, valued at approximately $320 million at the time. However, the attackers, identifying themselves as white-hat hackers, engaged in on-chain negotiations with Blockstream using OP_RETURN messages and PGP-signed communications. They demanded that all bridge nodes be patched before returning the funds.

Following the application of a security patch, the attackers returned 3,400 Bitcoin to the Liquid Federation wallet. Approximately 598.5 Bitcoin, valued at roughly $47 million, remains outstanding. Blockstream confirmed that the core multisignature keys securing the federation wallet were not compromised, and the issue was strictly a software verification failure. The network has faced service disruptions as operators work to restore full functionality and implement further security upgrades.

Entities

Bitcoin · Blockstream · Elements · Liquid Network · SideSwap

Claims

What the coverage asserts, and how many sources carry each claim.