0x5fbb78805fbb…5fbb787d

ConfirmedSecurity784 vB180 sat/vB4 min decode

Liquid Network Attacker Returns $268M, Keeps $47M After Elements Bug

An attacker drained ~4,000 BTC ($320M) from Liquid Network's federation reserve on Sept. 6, returned ~3,400 BTC, and kept ~598.5 BTC after Blockstream patched an Elements bug.

Outputs

  1. Roughly 4,000 BTC (~$320M) drained from Liquid Network's federation reserve on September 6, 2026, recorded in Bitcoin block 965,783.

  2. Attacker returned ~3,400 BTC (~$268M) and retained ~598.5 BTC (~$47M) after Blockstream shipped patched Elements v23.3.4.

  3. Root cause: a bug in how Elements cached range proofs, allowing unbacked L-BTC to trigger a valid peg-out.

  4. H1 2026 saw ~$1.315 billion in losses across 344 on-chain incidents, per Blockaid.

  5. Bitcoin price dipped ~1% to near $79,500; no charges or asset-recovery actions publicly confirmed.

An attacker drained roughly 4,000 BTC — about $320 million — from the federation reserve backing Blockstream's Liquid Network on September 6, 2026, then returned approximately 3,400 BTC ($268 million) while retaining about 598.5 BTC, worth close to $47 million, according to on-chain records and analyses by TRM Labs, Halborn and CoinDesk.

Blockstream pinpointed the exploit to 13:53 UTC on Liquid block 4,050,336, and the withdrawal was recorded in Bitcoin block 965,783. Operators halted the network almost immediately after detection, limiting further exploitation while the cause was diagnosed. TRM Labs pegged the theft slightly lower, at about $319 million, and estimated roughly 85% of the funds had been returned within days.

What caused the exploit?

The root cause sits in Elements, the open-source software underpinning the Liquid sidechain. Liquid's own @Liquid_BTC account attributed the flaw to a bug in how Elements cached range proofs, allowing roughly 4,000 L-BTC to come into existence with no bitcoin backing them. The attacker then used those unbacked tokens to trigger a peg-out — the mechanism for redeeming L-BTC back into BTC on the base chain — that looked entirely legitimate to the network.

Security firm Halborn traced the loss to the unauthorized minting of about 4,000 L-BTC. Reuters reported the funds were withdrawn through SideSwap's Pegout Authorization Key (PAK), though Liquid maintained SideSwap's own key was not compromised and that other third-party services' systems were untouched, pointing the blame at the shared Elements codebase.

The mechanics matter for institutional users: investigations referenced by Crypto Briefing indicate the flaw sat in the verification logic tied to peg-outs, not in general transaction processing. Ordinary L-BTC transfers between wallets on the sidechain were not themselves at risk.

How did the return unfold?

Rather than moving funds into mixers, the attacker negotiated with Blockstream directly through messages embedded in Bitcoin transactions — a public, permanent channel. According to on-chain notes reported by Crypto Times and CoinDesk, the attackers, who publicly framed themselves as "white-hat" hackers, said the bulk of the funds would be returned once the vulnerability was fixed and every federation node had applied the patch.

Blockstream, led by CEO Adam Back, shipped an emergency build, Elements v23.3.4, to close the range-proof caching flaw across bridge nodes, then confirmed via on-chain messaging that it was safe to return the funds. Within roughly a day of the withdrawal, a large share of the funds moved back to Liquid's federation address.

Blockstream has rejected the idea that the retained ~$47 million constitutes a legitimate bounty. The company characterized the unauthorized taking as a crime and said that if the funds are not returned, it will work with law enforcement, exchanges and forensic specialists to trace and recover them. No criminal charge, lawsuit or arrest tied to the incident had been publicly confirmed as of this writing.

What does it change for exchanges?

Exchanges routing Bitcoin through Liquid paused L-BTC deposits and withdrawals after the network halt, a standard precaution when settlement-layer integrity is in question. The incident forces a near-term reassessment for institutions that adopted Liquid for faster, confidential settlement: rely on a patched but recently compromised sidechain, or shift volume back to slower base-layer settlement.

Key operational facts:

  • Roughly 4,000 of the federation's ~4,200 BTC were drained in a single event.
  • Bitcoin's price dipped about 1%, holding near $79,500, reflecting the market's read that this was a sidechain-specific failure rather than a weakness in Bitcoin's proof-of-work consensus.
  • Restoration of full L-BTC service is expected to follow confirmation that the patch has been applied across all federation nodes, likely gated behind an independent code review.

The incident lands in a year already shaping up as one of the worst on record for crypto security. Industry tracker Blockaid counted roughly $1.315 billion in losses across 344 on-chain incidents in the first half of 2026 alone, per The Block — and much of that damage came from bridge and sidechain infrastructure, the category of code that must reason correctly about the state of two chains at once.

The unresolved question is the retained 598.5 BTC. If law enforcement classifies the attacker's actions as unauthorized access regardless of intent, the funds could become the subject of asset-recovery efforts, but unmasking a pseudonymous wallet poses real practical difficulty. With no recovery action publicly confirmed, the remaining $47 million sits outside Liquid's control, and full-year 2026 losses on track to rival record years, keeping regulatory pressure on custody and disclosure rules into 2027.

via business-standard.com (Original)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

419 articles