Status as of September 8, 2026, 19:10 UTCWhat Happened?
On September 6, 2026 at 15:53:10 UTC (Liquid block 4,050,336), a vulnerability in the open-source Elements software related to how Liquid nodes cache range proof verifications was exploited, resulting in the creation of ~4,000 LBTC that were not backed by bitcoin held in reserve.
The individual(s) responsible for the exploit then used the SideSwap service, a Liquid Federation member that holds a peg-out authorization (PAK) key, to convert the unbacked LBTC to BTC via Liquid’s standard peg-out mechanism. Because the validation failure occurred at the transaction level before the peg-out was initiated, both SideSwap’s node and the Liquid Network’s globally distributed functionary nodes accepted the LBTC as valid. The functionaries processed the peg-out as authorized, releasing approximately 4,000 BTC through SideSwap’s whitelisted bitcoin address, which SideSwap then forwarded to the address specified by the exploiters. Before the incident, the Liquid reserve held approximately 4,205 BTC. Following this peg-out and additional peg-outs processed before operations were halted, the reserve balance fell to 197 BTC.Key Clarifications
No keys were compromised. The Liquid Federation functionaries were not hacked, and no private keys were compromised. The peg-out mechanism that authorizes withdrawals to whitelisted addresses operated as designed.
Other Liquid-issued assets were not affected. USDT and other tokens issued on the Liquid Network were not impacted by the vulnerability, though they are temporarily unavailable while the network remains paused.
Investigation is ongoing. As is common in complex critical-system failure investigations, this incident arose from the convergence of several individually low-probability factors that interacted in ways that ultimately defeated the system's built-in redundancies. More detail will be shared in forthcoming communications.What Steps Have Been Taken To Recover The Assets?
The individual(s) responsible for the exploit left a public message on the bitcoin mainchain identifying themselves as white-hat security researchers and requesting contact to address the vulnerability.
Patch deployed. Blockstream identified and deployed a patch to the Liquid Network’s bridge nodes, which was completed on September 7 at 01:09 UTC, ensuring the vulnerability is no longer exploitable.
Partial fund recovery. On September 7 at 16:09:25 UTC (Liquid block 965,950), the exploiters returned 3,400 BTC to the Liquid Federation peg wallet. Approximately 598.5 BTC (15% of the total) remains outstanding. Discussions between Blockstream and the individuals responsible are ongoing to secure the return of the remaining funds.What Comes Next?
Our immediate priorities are recovering the remaining funds and resuming normal network operations safely and as quickly as possible.
Software update in progress. A fix for the exploited vulnerability has been developed and is undergoing multiple rounds of internal and external review. Blockstream is preparing an emergency release of Elements (v23.3.4), which is expected to be released as soon as possible, but within approximately 48 hours.
Network restoration. Once the software update is finalized, Liquid Network functionary operators will perform additional adjustments to resume full functionality and restore the corrected network state, including rejection of the invalid peg-out.
Ongoing updates. We will continue to provide detailed updates as the situation progresses.What You Should Know
The Liquid Network remains offline at this time, while we work on reviewing the security fixes and network resumption code and coordinate with the white hat hacker towards timely resumption of the network with 1:1 backing for BTC. While the network is paused, users cannot transact on Liquid. If you operate a Liquid node, please watch for the emergency Elements release and follow the upgrade instructions when available. Users do not need to take any proactive steps to protect their funds at this time.
The Liquid Federation and its members are committed to resolving this incident in coordination with Blockstream and to resuming normal operations as soon as it is safe to do so.
pull down to refresh
related posts
Darth didn't bite on Den's bitcoin laundering post and he hasn't bitten on this as yet, even though he forewarned about it countless times. TBF Justin has been holding the fort in the meantime
I miss him :/
frozen network
FAFO
Yikes, I mean Bitcoin University did kind of call the fuckery out about Blockstream about a million times. Hopefully they get the final 600 coins back.
sounds like a very tricky inflation bug; 🙈🐞
https://twiiit.com/Liquid_BTC/status/2097404704028545175
Nothing further about the neat 15% cut?
Also: did you see the comment about Bitcoin L2s done for?
The implication I read is that it wasn't agreed upon.
L2s aren't done. Liquid may very well be, though.
What Comes Next?
Our immediate priorities are recovering the remaining funds
shocking
Liquid isn’t even a L2
Edit: I stand corrected by Blockstream itself:
funky, fuuuuunky.
How would you classify it? 2.5? 3? A separate thing altogether?
a custodian
That's how you know it's not a L2
Taps the sign
deleted by author