On September 6, 2026, at 15:53 UTC, an unknown actor exploited a range-proof verification cache bug in Blockstream's Liquid Network to mint approximately 4,000 unbacked L-BTC and peg them out for real bitcoin — draining 95% of the federation's 4,200 BTC reserve in 36 minutes. At prevailing prices...
"If you exploit vuln, steal 4k BTC and demand a fix for ransom, that's EXTORTION." — Alena Vránová, Security Researcher
On September 6, 2026, at 15:53 UTC, an unknown actor exploited a range-proof verification cache bug in Blockstream's Liquid Network to mint approximately 4,000 unbacked L-BTC and peg them out for real bitcoin — draining 95% of the federation's 4,200 BTC reserve in 36 minutes. At prevailing prices near $80,000 per BTC, the haul totaled approximately $320 million, making it the single largest crypto security incident of 2026.
The attacker communicated via Bitcoin OP_RETURN messages, self-identified as a "whitehat," and returned 3,400 BTC (~$272 million) on September 7 after Blockstream deployed a bridge-node patch. The attacker retained 598.5 BTC (~$47 million) as a self-declared bounty. Blockstream has not publicly accepted those terms. As of September 10, Liquid block production has resumed with empty blocks, but peg-in and peg-out operations remain suspended. No timeline for full restoration has been announced.
The incident raises fundamental questions about the security model of federated sidechains — not because the federation's 11-of-15 multisig failed, but because it worked exactly as designed while processing a fraudulent withdrawal.
| Time (UTC) | Event | |---|---| | Sept. 1-3 | Fix for range-proof cache bug merged to Elements repository; no tagged release issued | | Sept. 6, 13:53 | Attacker broadcasts dozens of transactions with matching proof data to poison the cache | | Sept. 6, 14:06 | Withdrawal request submitted through SideSwap's peg-out service | | Sept. 6, 14:28 | Federation's 11-of-15 multisig signs peg-out; ~3,996 BTC reaches attacker wallet | | Sept. 6, 15:53 | Liquid block 4,050,336 confirms the exploit; on-chain analyst ErgoBTC raises first alert | | Sept. 6, 20:25 | Blockstream disables bridge nodes, halting all peg operations | | Sept. 7, 01:09 | Emergency bridge-node patch deployed | | Sept. 7, 16:09 | Attacker returns 3,400 BTC to Liquid federation address | | Sept. 9, 13:30 | Elements v23.3.4 released with hardened cache-key verification | | Sept. 10, 12:26 | Block production restarts; transactions remain frozen |
From cache-poisoning to BTC exfiltration, 36 minutes elapsed. From first alert to bridge shutdown, approximately five hours. The gap between fix-merge and exploit: five days.
The vulnerability sat in Elements, the open-source software that underpins Liquid's consensus layer. Liquid uses Confidential Transactions, which rely on computationally expensive range proofs to verify that transaction outputs are valid without revealing amounts. To reduce overhead, Elements caches verification results.
The cache key was incomplete. According to independent code analysis, it omitted asset and script context, meaning a proof validated in one transaction context could be reused to authorize a different one. The attack unfolded in five stages:
Stage 1 — Cache Poisoning. The attacker submitted dozens of legitimate-looking transactions whose range proofs were verified and cached by Liquid nodes. These proofs shared characteristics with what would follow.
Stage 2 — Counterfeit Issuance. Exploiting the cache-key collision, the attacker minted approximately 4,000 L-BTC with no backing collateral. A subset of nodes accepted these tokens under the consensus rules in force because the cache reported the range proofs as already verified.
Stage 3 — Laundering Through SideSwap. The unbacked L-BTC was sent to SideSwap, an authorized peg-out service operating within Liquid. SideSwap had no mechanism to distinguish exploit-created coins from genuine ones. The authorization key was used correctly and was never stolen.
Stage 4 — Federation Signing. The 11-of-15 multisig produced eleven valid signatures for a withdrawal that appeared legitimate under every consensus rule in effect. The federation performed its intended function.
Stage 5 — Exfiltration. Approximately 3,996 BTC transferred to the attacker's wallet on the Bitcoin mainchain. No amount or velocity ceiling existed on a single peg-out. One transaction drained 95% of reserves.
Blockstream attributed the incident to the software bug, not compromised keys: "No evidence that the PAK itself, or the federation's other signing keys, were directly compromised."
Liquid's security pitch has rested on its federated architecture: 15 functionaries drawn from approximately 87 member organizations operate signing nodes, with an 11-of-15 threshold required to authorize withdrawals. The design assumes that compromising 11 independent entities is prohibitively difficult.
The September 6 incident demonstrated a different failure mode. The federation's cryptographic keys were intact. The multisig threshold held. The vulnerability existed upstream — in the code that tells the federation what to sign. As Bitcoin Core contributor Michael Folkson characterized it: "It is effectively single sig... actual multisig signing is security theater." While that framing is contested, the structural point stands: the federation validated a fraudulent withdrawal because no layer in the stack flagged the underlying L-BTC as unbacked.
Several design gaps amplified the damage:
This last point is significant for infrastructure security broadly. The vulnerability was known, the code fix was written, reviewed, and merged, but the last mile of delivery had not happened.
The attacker communicated through Bitcoin OP_RETURN messages and PGP-encrypted text embedded in transactions. The initial message read: "We are whitehats. Contact us on chain."
The return of funds was conditional. The attacker demanded Blockstream patch the vulnerability before returning any bitcoin, and stated that they expected 10% of the returned amount as a bug bounty, or else would cause "a 15% loss" to holders. On September 7, after Blockstream confirmed the bridge-node patch was deployed, 3,400 BTC was returned. The attacker retained 598.5 BTC (~$47 million).
Blockstream has not publicly acknowledged the retained amount as an authorized bounty. The company used the phrase "purported white hat" in its communications.
Blockstream's recovery is proceeding in three stages:
Blockstream CEO Adam Back stated on September 9 that the L-BTC peg "will be covered" and urged holders not to panic-sell L-BTC over-the-counter. Elements v23.3.4, released September 9, hardened the cache keys used in range-proof verification.
TRM Labs labeled attacker addresses within 24 hours and continues to track the approximately $47 million in retained funds.
Bitcoin's price held near $80,000 throughout the incident — markets correctly treated it as a sidechain-specific event, not a base-layer protocol failure. No BTC consensus rules were breached or tested.
The impact was concentrated within the Liquid ecosystem:
Cake Wallet COO Seth for Privacy posed the question that institutional users would ask: "Who is going to trust Liquid with their money?" Bitcoin developer Nicolas Burtey stated the exploit "killed Liquid" regardless of the fund recovery outcome.
The $320 million total exceeded the combined $136-140 million lost across approximately 50 separate incidents in August 2026, according to Immunefi data.
The Liquid incident exposes a structural tension in federated bridge design. The federation model was not breached — it was bypassed. The vulnerability sat in the validation layer that feeds data to the federation, and no amount of key-holder diversification could have caught it.
Three lessons emerge:
1. Code audits ≠ deployment safety. The fix existed in the repository for five days before the exploit. Quarterly or semi-annual audit cycles cannot protect against the window between a public commit and a deployed release. As one analysis noted: "Discovery is automated, chaining is automated, and the window between a public fix and a deployed fix is an exploitation window by default."
2. Withdrawal guardrails are non-optional. A system holding $335 million in reserves had no rate limiter on outbound transactions. A time-delayed withdrawal mechanism, a per-block peg-out cap, or an automated reserve-to-supply check — any of these would have reduced the damage by orders of magnitude.
3. Vulnerability scope fragmentation remains an industry problem. Consensus code audits and peg-out service assessments typically occur separately. According to analysis by CodeAnt, "the attack path crossed that boundary, and nobody owned the seam." The exploit was low-severity in isolation, catastrophic when chained through issuance, SideSwap's peg-out rail, and the federation wallet.
For the broader Bitcoin sidechain landscape — including proposals for drivechains and other trust-minimized bridges — the incident provides empirical evidence that federation trust is only as strong as the weakest software layer in the validation stack.
The Liquid Network exploit is not a story about stolen keys or compromised signers. It is a story about the gap between a security model's theoretical guarantees and its operational reality. The federation performed as designed. The software feeding it did not.
Blockstream faces a restoration challenge that extends beyond technical patching. The 598.5 BTC gap between total loss and total return remains unresolved. The L-BTC peg's credibility depends on whether Adam Back's pledge of coverage translates into verifiable, on-chain reserve matching. And the institutional users who chose Liquid specifically for its federated trust model now have empirical evidence that federation security is a necessary but insufficient condition.
For the broader ecosystem, the incident is a data point against the assumption that known-party federations inherently outperform permissionless bridges. Both models carry risk. The difference is where the risk concentrates — and whether anyone owns the seam between components.