pull down to refresh

Status as of September 8, 2026, 19:10 UTC

What Happened?

On September 6, 2026 at 15:53:10 UTC (Liquid block 4,050,336), a vulnerability in the open-source Elements software related to how Liquid nodes cache range proof verifications was exploited, resulting in the creation of ~4,000 LBTC that were not backed by bitcoin held in reserve.

The individual(s) responsible for the exploit then used the SideSwap service, a Liquid Federation member that holds a peg-out authorization (PAK) key, to convert the unbacked LBTC to BTC via Liquid’s standard peg-out mechanism. Because the validation failure occurred at the transaction level before the peg-out was initiated, both SideSwap’s node and the Liquid Network’s globally distributed functionary nodes accepted the LBTC as valid. The functionaries processed the peg-out as authorized, releasing approximately 4,000 BTC through SideSwap’s whitelisted bitcoin address, which SideSwap then forwarded to the address specified by the exploiters. Before the incident, the Liquid reserve held approximately 4,205 BTC. Following this peg-out and additional peg-outs processed before operations were halted, the reserve balance fell to 197 BTC.

Key Clarifications

No keys were compromised. The Liquid Federation functionaries were not hacked, and no private keys were compromised. The peg-out mechanism that authorizes withdrawals to whitelisted addresses operated as designed.

Other Liquid-issued assets were not affected. USDT and other tokens issued on the Liquid Network were not impacted by the vulnerability, though they are temporarily unavailable while the network remains paused.

Investigation is ongoing. As is common in complex critical-system failure investigations, this incident arose from the convergence of several individually low-probability factors that interacted in ways that ultimately defeated the system's built-in redundancies. More detail will be shared in forthcoming communications.

What Steps Have Been Taken To Recover The Assets?

The individual(s) responsible for the exploit left a public message on the bitcoin mainchain identifying themselves as white-hat security researchers and requesting contact to address the vulnerability.

Patch deployed. Blockstream identified and deployed a patch to the Liquid Network’s bridge nodes, which was completed on September 7 at 01:09 UTC, ensuring the vulnerability is no longer exploitable.

Partial fund recovery. On September 7 at 16:09:25 UTC (Liquid block 965,950), the exploiters returned 3,400 BTC to the Liquid Federation peg wallet. Approximately 598.5 BTC (15% of the total) remains outstanding. Discussions between Blockstream and the individuals responsible are ongoing to secure the return of the remaining funds.

What Comes Next?

Our immediate priorities are recovering the remaining funds and resuming normal network operations safely and as quickly as possible.

Software update in progress. A fix for the exploited vulnerability has been developed and is undergoing multiple rounds of internal and external review. Blockstream is preparing an emergency release of Elements (v23.3.4), which is expected to be released as soon as possible, but within approximately 48 hours.

Network restoration. Once the software update is finalized, Liquid Network functionary operators will perform additional adjustments to resume full functionality and restore the corrected network state, including rejection of the invalid peg-out.

Ongoing updates. We will continue to provide detailed updates as the situation progresses.

What You Should Know

The Liquid Network remains offline at this time, while we work on reviewing the security fixes and network resumption code and coordinate with the white hat hacker towards timely resumption of the network with 1:1 backing for BTC. While the network is paused, users cannot transact on Liquid. If you operate a Liquid node, please watch for the emergency Elements release and follow the upgrade instructions when available. Users do not need to take any proactive steps to protect their funds at this time.

The Liquid Federation and its members are committed to resolving this incident in coordination with Blockstream and to resuming normal operations as soon as it is safe to do so.

Darth didn't bite on Den's bitcoin laundering post and he hasn't bitten on this as yet, even though he forewarned about it countless times. TBF Justin has been holding the fort in the meantime

reply

I miss him :/

reply

frozen network

reply
reply

Yikes, I mean Bitcoin University did kind of call the fuckery out about Blockstream about a million times. Hopefully they get the final 600 coins back.

reply

sounds like a very tricky inflation bug; 🙈🐞

reply

Nothing further about the neat 15% cut?

Also: did you see the comment about Bitcoin L2s done for?

reply

The implication I read is that it wasn't agreed upon.

L2s aren't done. Liquid may very well be, though.

reply

What Comes Next?

Our immediate priorities are recovering the remaining funds

reply

shocking

reply
34 sats \ 3 replies \ @ek 8 Sep

Liquid isn’t even a L2

Edit: I stand corrected by Blockstream itself:

The Liquid Network is a Bitcoin layer-2
reply

funky, fuuuuunky.

How would you classify it? 2.5? 3? A separate thing altogether?

reply

a custodian

reply
161 sats \ 0 replies \ @justin_shocknet 8 Sep -210 sats

That's how you know it's not a L2

262 sats \ 2 replies \ @justin_shocknet 8 Sep -420 sats
peg-out authorization (PAK)

Taps the sign

deleted by author