Blockstream’s Liquid Network, a federated Bitcoin sidechain used by exchanges for fast settlement, was exploited on Sunday, September 6, 2026, when an actor minted roughly 3,996 unbacked L-BTC through a range-proof cache bug in the Elements codebase and then redeemed them for 3,996 real bitcoin worth about $320 million from the federation wallet in a single peg-out at 14:28 UTC. The withdrawn BTC represented approximately 95 percent of Liquid Network’s reported reserves, draining the sidechain from 4,205 BTC to 202 BTC in less than thirty seconds. The attacker left OP_RETURN messages in Bitcoin block 965,818 reading “we are whitehats. contact us on chain,” and the subsequent negotiation with Blockstream played out entirely on-chain over a thirty-hour window.
The vulnerability, confirmed by Blockstream and outside reviewers, was a cache-key collision in Elements’ confidential-transaction range-proof verification routine. Because the cache key omitted asset and script context, a previously verified proof could be reused in circumstances where a fresh check should have been required, allowing the attacker to construct an invalid output that federation nodes nonetheless accepted as valid. Bitcoin Core contributor Antoine Poinsot described the issue as “definitely a consensus bug,” and mempool.space’s Liquid node rejected the disputed block 4,050,336 while Blockstream’s own explorer accepted it, signaling a temporary consensus split among operators. SideSwap, the bridge exchange through which the withdrawal was routed, said the L-BTC originated from the bug in Elements rather than from a compromise of its own Peg-out Authorization Key, and Blockstream confirmed that none of its functionary signing keys were exposed.
How the Liquid Network exploit unfolded
Within thirty minutes of the drain, the white-hat messages were visible on the Bitcoin base layer, and a slow-motion negotiation began in plain sight. TRM Labs later pegged the Liquid Network incident as the largest crypto theft of 2026 at $319 million, noting that 2026 had already seen roughly $1.73 billion stolen across 333 incidents before this event. The attacker’s use of an OP_RETURN plea rather than a laundering path, combined with the rapid return of funds, framed the episode as a self-styled bug bounty. Roughly 3,400 BTC, worth about $270 million and representing 85 percent of the haul, was returned to Blockstream-controlled addresses after the bridge nodes were patched. The remaining 598.5 BTC, valued near $47 million, is still sitting in the attacker’s wallet and is widely speculated to be a self-declared reward for the disclosure, though Blockstream has not formally classified it as such.
The 3-stage Liquid Network recovery plan
On September 9, 2026, Blockstream shipped the emergency Elements v23.3.4 patch, which fixes the range-proof cache vulnerability and strengthens the cache keys used for range-proof verification. Functionary nodes began upgrading immediately, and the patch had gone through multiple rounds of internal and external review, including audits by Bitcoin Red Team and Alpen Labs. Around the patch, Blockstream published a three-stage recovery roadmap. In stage one, functionaries resume block production while peg operations remain suspended, allowing the chain to move forward without new peg-ins or peg-outs. In stage two, verified valid transactions from the disputed window are replayed so that legitimate activity is preserved on the canonical chain. In stage three, once the network state is fully restored and the remaining fund returns are confirmed, peg operations resume under the hardened code.
The first two phases are being tested in parallel on a coordinated basis, and Blockstream has declined to name a specific date for the resumption of normal operations. Users have been advised not to send bitcoin to Liquid peg-in addresses until Blockstream confirms the restart, and exchanges have been told to treat unconfirmed peg-in activity with caution. Bitcoin’s base layer was never at risk; BTC traded in a roughly $78,000 to $80,000 range during the incident with no visible market stress, and traders treated the episode as a sidechain problem rather than a Bitcoin problem. Liquid Network, the oldest Bitcoin sidechain, built in 2018 and operated by a federation of fifteen functionaries running tamper-proof hardware, now enters a tense proving period as engineers watch for any further consensus divergence between patched and unpatched nodes before peg operations can safely come back online.
Contextualizing the Liquid Network incident against prior bridge exploits helps frame its significance. With roughly $320 million in BTC withdrawn from the federation wallet, the Liquid Network drain ranks as the largest single Bitcoin-sidechain exploit on record, surpassing the $320 million Wormhole bridge hack of 2022 and approaching the $625 million Ronin bridge hack of the same year in nominal scale. TRM Labs’ designation of the event as the largest crypto theft of 2026, sitting within a year-to-date figure of about $1.73 billion stolen across 333 incidents, underscores how a single Elements codebase defect translated into one of the year’s most consequential losses despite Bitcoin’s base layer remaining untouched.
Technical analysis of the underlying bug points to a narrow but high-impact failure mode. The cache-key collision in Elements’ confidential-transaction range-proof verification routine meant that the cache key omitted asset and script context, allowing a previously verified proof to be reused in circumstances where a fresh check should have been required. That structural oversight is what let the attacker mint roughly 3,996 unbacked L-BTC and redeem them against the Liquid Network federation wallet in a single peg-out, and it is why observers such as Bitcoin Core contributor Antoine Poinsot characterized the issue as a consensus bug rather than an operational glitch.
Equally notable is the response architecture already built into the sidechain. Liquid Network, the oldest Bitcoin sidechain and built in 2018 by Blockstream, is operated by a federation of fifteen functionaries running tamper-proof hardware modules, which is why no signing key was exposed and why the recovery could be coordinated through a multi-stage patch-and-replay roadmap rather than an emergency shutdown. The combination of a constrained blast radius, an on-chain negotiation channel, and a federation model that separates consensus participation from key custody has, for now, defined the limits of the damage.
Source: crypto.news — https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/

