A range-proof cache bug in Blockstream's Elements codebase allowed an unidentified actor to mint approximately 4,000 unbacked L-BTC on the Liquid Network and peg them out for real Bitcoin on September 6, draining 95% of the federation's reserves in 23 minutes. The 3,998.5 BTC taken, valued at $31...
"We are whitehats. Contact us on chain." — Unidentified attacker(s), embedded in Bitcoin OP_RETURN field, September 6, 2026
A range-proof cache bug in Blockstream's Elements codebase allowed an unidentified actor to mint approximately 4,000 unbacked L-BTC on the Liquid Network and peg them out for real Bitcoin on September 6, draining 95% of the federation's reserves in 23 minutes. The 3,998.5 BTC taken, valued at $318.7 million at the time of exploit, makes it the single largest crypto theft of 2026 and one of the ten largest in the industry's history.
The attacker returned 3,400 BTC within 36 hours, retaining 598.5 BTC (approximately $47 million) as a self-declared bounty. The Liquid Network remains paused as of September 9, with L-BTC backed at roughly 86% of outstanding supply and no public timeline for resuming redemptions. The incident raises pointed questions about federated sidechain security, patch deployment timelines, and the economic incentives that govern so-called white-hat exploits.
Liquid Network is a Bitcoin sidechain operated by a 15-member federation of exchanges and financial firms, including Bitfinex and BTSE. Users lock BTC on the Bitcoin main chain to receive L-BTC, a 1:1 pegged token that settles faster and supports Confidential Transactions. Prior to the exploit, the federation wallet held approximately 4,200 BTC.
On September 6, at 13:52 UTC, an attacker began a two-transaction sequence that exploited a vulnerability in the Elements software layer — the open-source codebase that validates Liquid transactions before they reach the federation's 11-of-15 multisig. No private keys were compromised. The bug sat upstream, in the software that checks whether transaction outputs fall within valid ranges.
Within 38 minutes of the first setup transaction, 3,998.5 BTC had left the federation wallet via SideSwap's Peg-out Authorization Key. The federation's reserve dropped from over 4,200 BTC to approximately 197 BTC.
The exploit targeted an ambiguity in how the Elements codebase cached range-proof verifications for Confidential Transactions.
How Confidential Transactions work: Liquid uses Pedersen commitments and range proofs to hide transaction amounts while proving outputs are non-negative. Range proofs are computationally expensive, so Elements caches verification results to avoid re-checking previously validated proofs.
The cache-key collision: The cache implementation concatenated variable-length fields — specifically the range proof (P) and script (S) — into a SHA-256 hash stream without encoding their respective lengths. This allowed an attacker to craft two distinct input tuples that produced identical cache keys by shifting bytes across field boundaries.
According to CertiK's incident analysis, the attack followed four steps:
Cache priming: The attacker submitted valid setup transactions with carefully structured outputs containing commitment C0, script S0, and embedded data. These were accepted into the mempool cache as legitimate.
Cache collision: By restructuring byte boundaries, the attacker created a malicious transaction whose cache key collided with the valid primer. The valid entry: (P0, C0, X, 6a43 || C1 || X || 6a). The malicious entry: (P0 || C0 || X || 6a43, C1, X, 6a). Both resolved to the same 4,301-byte SHA-256 stream.
Inflation: The cache lookup occurs before commitment parsing and secp256k1_rangeproof_verify. A cache hit returns true immediately, so the invalid proof was never cryptographically checked. The malicious transaction created approximately 4,000 L-BTC backed by nothing.
Peg-out: The attacker routed the unbacked L-BTC through SideSwap's authorized peg-out mechanism, converting them to native Bitcoin.
The federation's 11-of-15 multisig signed the peg-out withdrawals correctly — but it was signing based on corrupted inputs produced by the software layer above it. The multisig itself was never breached.
| Time (UTC) | Event |
|---|---|
| Sept 6, 13:52:10 | Setup transaction submitted (txid: 271147...7ec5) |
| Sept 6, 13:53:10 | Inflation transaction submitted (txid: f24a4b...183f) |
| Sept 6, 14:01:10 | First peg-out: 2.65 L-BTC |
| Sept 6, 14:06:10 | Large peg-out: 3,996.02 L-BTC |
| Sept 6, 14:28:56 | 3,996.02 BTC received at bc1ql4mfu6... |
| Sept 6, ~15:30 | Blockstream disables bridge nodes, pauses sidechain |
| Sept 6, ~16:00 | Attacker embeds "we are whitehats" in OP_RETURN message |
| Sept 6, ~18:00 | Blockstream sends 1,000 satoshis to attacker's address with OP_RETURN requesting email contact |
| Sept 7, 18:09:25 | 3,400 BTC returned to federation wallet |
| Sept 8 | Blockstream confirms patched software deployed; federation prepares coordinated restart |
| Sept 9 | Network remains paused; no redemption timeline announced |
The on-chain communication between attacker and Blockstream represents an unusual case study in post-exploit negotiation.
The attacker embedded the message "we are whitehats. contact us on chain" in the OP_RETURN field of a Bitcoin transaction shortly after the exploit. Blockstream responded by sending 1,000 satoshis to the attacker's address with its own OP_RETURN message asking them to contact the security team via email. Blockstream followed up with a PGP-signed, encrypted on-chain message.
The attacker's stated condition for returning funds was that every federation node patch the underlying bug. After Blockstream confirmed patches had been deployed to bridge infrastructure, 3,400 BTC was transferred back to the federation's custody wallet on September 7.
The 598.5 BTC retained by the attacker — approximately $47 million at current prices — appears to be claimed as a bug bounty. For context, this would be among the largest bug bounty payouts in software history, dwarfing Immunefi's record $10 million payout. Blockstream has not publicly stated whether it considers this an acceptable bounty or a theft.
The "white-hat" framing is contested. As multiple security researchers have noted, a white-hat disclosure involves reporting the vulnerability before exploiting it. Draining 95% of a live network's reserves and negotiating return terms after the fact is, at minimum, a gray-hat operation. The legal status of the retained 598.5 BTC remains unresolved.
Immediate impact on L-BTC: Unlike a standard multisig drain that removes real reserves, a mint bug dilutes the peg by adding unbacked units. After the partial return, the federation wallet holds approximately 3,597 BTC against an estimated 4,200 L-BTC outstanding — implying roughly 86% backing. Full reserve-and-liability reconciliation has not been published.
Exchange impact: Major exchanges including Bitfinex and BTSE suspended L-BTC deposits and withdrawals. Aqua wallet halted L-BTC activity. No exchange has resumed L-BTC trading as of September 9.
Bitcoin main-chain impact: Minimal. BTC traded approximately 0.2% lower in the 24 hours following the exploit. The market correctly assessed this as a sidechain infrastructure failure, not a Bitcoin protocol vulnerability.
USDT and RWA assets on Liquid: Unaffected. The bug was specific to L-BTC range-proof validation, not the broader sidechain infrastructure. Tether's USDT issuance on Liquid continued to function normally.
The most troubling aspect of the incident is the patch timeline.
The fix for the range-proof cache bug was committed to the Elements GitHub repository on August 3, 2026. It was merged into the main branch on September 2 — four days before the exploit. The commit title was descriptive enough to identify exactly where the vulnerability sat in the codebase.
Federation nodes were running Elements version 23.3.3, released on April 13, 2026 — nearly five months before the fix was available. No release containing the patched code had been deployed to any production node by September 6.
This creates a disclosure paradox common in open-source security: publishing a fix in a public repository before deploying it to production nodes effectively advertises the vulnerability to anyone monitoring the codebase. Whether the attacker discovered the bug independently or identified it from the public commit remains unknown.
The Liquid Network exploit arrives in a year already marked by elevated crypto theft:
The Liquid exploit now stands as 2026's single largest theft by dollar value, surpassing Drift Protocol. Unlike the Lazarus-linked attacks, it resulted in partial fund recovery — a pattern that has become more common in 2026, where attacker profiles have diversified beyond state actors.
DeFi protocols have lost an estimated $1.3 billion to hacks in 2026, according to crypto.news, with repeated exploitation of similar vulnerability classes. The Liquid incident, while technically a sidechain rather than a DeFi protocol, fits the broader pattern: infrastructure-layer bugs in validation logic, not smart-contract re-entrancy.
The Liquid exploit exposes structural tensions in the federated sidechain model:
1. Federation ≠ security guarantee. The 11-of-15 multisig functioned as designed. The vulnerability sat in the software layer that feeds data to the multisig. A federation can only sign what its software tells it is valid.
2. Confidential Transactions add attack surface. The range-proof cache that was exploited exists specifically to make Confidential Transactions performant. Simpler transaction models would not require this caching layer. Privacy features carry a security cost that must be weighed against their economic utility.
3. Open-source patch visibility is a double-edged sword. Publishing fixes before deploying them to production is a well-known risk in open-source security. The Liquid incident may become a case study in responsible disclosure timelines for blockchain infrastructure.
4. Federated custody concentrates risk. The entire L-BTC supply was backed by a single federation wallet. The attack drained 95% of it in 23 minutes. Distributed custody models, while slower, would limit single-point-of-failure exposure.
5. "White-hat" bounty economics are unresolved. A $47 million self-declared bounty, taken from live user funds without prior agreement, exists in a legal gray area. The precedent it sets — exploit first, negotiate later — may incentivize similar behavior against other federated or bridged networks.
The Liquid Network exploit is notable less for its dollar amount — large but not unprecedented — than for what it reveals about the security assumptions underlying federated Bitcoin sidechains. The federation's multisig performed correctly. The cryptographic primitives held. The failure was in a caching optimization designed to make Confidential Transactions faster: a performance shortcut that became an inflation vector.
The incident also highlights the tension between open-source transparency and operational security. A fix committed to a public repository five weeks before the exploit, merged four days before, and deployed to zero production nodes is a process failure, not a code failure. The code was fixed. The deployment pipeline was not.
For the Liquid Federation's member exchanges and their users, the immediate question is when redemptions resume and whether the remaining 598.5 BTC deficit will be absorbed by Blockstream, the federation, or L-BTC holders. For the broader sidechain and bridge ecosystem, the question is whether federated custody models can maintain credibility when a single software bug can drain nearly all reserves in under half an hour.
The attacker claimed to be a white hat. The $47 million they kept suggests the hat is, at best, gray.