Liquid Network Bitcoin Exploit: 3400 BTC Returned, 10% Bounty Demanded Bitcoin's Liquid sidechain suffered a serious security breach on September 6, 2026, after attackers found a way to mint
Liquid Network Bitcoin Exploit: 3400 BTC Returned, 10% Bounty Demanded
Bitcoin's Liquid sidechain suffered a serious security breach on September 6, 2026, after attackers found a way to mint bitcoin-backed tokens without putting up any real collateral.
The flaw sat inside Elements, the open-source software that powers Liquid network, and specifically involved how nodes cache the verification of range proofs, a technical check meant to confirm that transaction amounts are valid.
Using this gap, the attacker created roughly 4,000 unbacked LBTC and converted it into real bitcoin. Crucially, no private keys or Liquid Federation signing keys were touched in the process.
Before the incident, Liquid Network bitcoin reserve stood at about 4,205 coins. After the fraudulent peg-out and a few additional transactions processed before the network was halted, that reserve dropped to just 197 coins.
At a Glance
Date: September 6, 2026, Elements software bug exploited
Cause: Flaw in range-proof verification caching
Impact: ~4,000 unbacked LBTC created, converted to BTC
Reserve drop: ~4,205 token fell to ~197 token
Keys: No private or Federation keys compromised
Recovery: ~3,400 tokens returned; ~598.5 tokens still outstanding
Attackers' demand: 10% bug bounty from Blockstream, or 15% loss threat
Fix: Elements v23.3.4 patch released September 9
Status: Network paused, recovery plan underway in stages
How Attackers Minted Unbacked LBTC and Converted It to BTC?
The exploit worked because the flawed verification cache allowed newly created LBTC to appear valid even though no equivalent bitcoin backed it. The attacker then routed these tokens through SideSwap, a Liquid Federation member that operates a peg-out authorization key, or PAK, used to convert LBTC back into bitcoin.
That authorization key itself was never compromised. Because the validation failure happened earlier in the process, both SideSwap's systems and the Liquid Network's functionary nodes treated the tokens as legitimate.
As a result, functionaries processed the withdrawal exactly as the protocol is designed to, releasing close to 4,000 BTC to the address SideSwap forwarded funds to.

Source: Official Liquid Network News
SideSwap Says Operational Gaps Amplified the Liquid Network Loss
SideSwap has publicly acknowledged that while the underlying bug originated in Elements and not in its own infrastructure, two of its operational choices made the damage worse. Its peg-out authorization key stayed online at all times, and payouts to customers were forwarded automatically rather than being reviewed.
The platform also had no checks in place for unusually large, fast, or suspicious peg-out requests, which let the roughly 4,000 LBTC withdrawal pass through unnoticed until it was too late.

Source: Sideswap Post
Liquid Attackers Demand 10% Bug Bounty From Blockstream
In a new on-chain message, the individuals behind the exploit described themselves as white-hat security researchers. They alleged that Blockstream had spent only around $1.5 million, possibly nothing at all, to secure roughly $5 billion in assets.
Based on that claim, they are demanding that Blockstream pay a 10% bug bounty out of its own funds, warning that refusal would result in a 15% loss for LBTC holders.
The group also threatened to publish a private key that could decrypt earlier communications with Blockstream. These statements come directly from the attackers and remain unverified allegations rather than confirmed facts.

Source: Bitcoin News
3400 BTC Returned as Around 600 BTC Remains Outstanding
On September 7, the attackers returned approximately 3,400 BTC to the Liquid Federation. According to Liquid's official incident report, about 598.5 BTC, roughly 15% of the total taken, is still outstanding.
Blockstream and the parties claiming responsibility are reportedly continuing discussions over the remaining funds, which the Federation now lists as an immediate priority.
Key Detail
Information
Exploit date
September 6, 2026
Vulnerability
Elements range-proof verification cache issue
Unbacked LBTC created
~4,000 LBTC
BTC released
~4,000 coins
Bitcoin (BTC) returned
~3,400 coins
BTC still outstanding
~598.5 coins
Liquid status
Network operations paused
Emergency fix
Elements v23.3.4
Attackers' claim
Self-described white-hat researchers
Bounty demand
10% bug bounty
Liquid Network Paused as Blockstream Deploys Elements v23.3.4 Fix
Liquid remains suspended while recovery work continues. Blockstream released Elements v23.3.4 on September 9 as an emergency patch addressing the cache vulnerability and strengthening how range proofs are verified.
Functionary nodes are now being upgraded to the new version. The update closes the door on this specific exploit, though recovering the outstanding bitcoin remains a separate, ongoing effort.
Liquid Recovery Plan: Block Production First, Peg-Outs Later
Blockstream has outlined a three-stage path back to normal operations: resuming block production while peg-in and peg-out functions stay paused, replaying transactions already confirmed as valid, and only then restoring peg operations once the network state and 1:1 bitcoin backing are fully verified.
The first two stages are being tested in parallel, and Blockstream has cautioned that the sequence could shift depending on results, with no stage advancing until deemed safe.
What the Liquid Exploit Means for BTC Holders and Liquid Users
For now, Liquid users cannot transact normally on the network. Other Liquid-issued assets, including USDT, were not directly affected by the vulnerability itself, though related services remain unavailable during the pause.
According to official guidance, users do not need to take any proactive steps to protect their funds. Liquid and Blockstream have also warned about fake recovery websites and phishing attempts capitalizing on the incident, urging users to rely only on official channels.
The bottom line: the vulnerability has been patched, 3,400 Bitcoins has already been recovered, but around 600 BTC remains unresolved, and full restoration of the Liquid Network depends on the outcome of ongoing recovery and validation work.
Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency markets are volatile and carry significant risk. Readers should conduct their own research and consult a qualified professional before making any financial decisions.