Liquid Network Bitcoin Hack: Hacker Return 3400 BTC, Demand 10% Bounty

10-Sep-2026 CoinGabbar

Liquid Network Bitcoin Exploit: 3400 BTC Returned, 10% Bounty Demanded

Bitcoin's Liquid sidechain suffered a serious security breach on September 6, 2026, after attackers found a way to mint bitcoin-backed tokens without putting up any real collateral. 

The flaw sat inside Elements, the open-source software that powers Liquid network, and specifically involved how nodes cache the verification of range proofs, a technical check meant to confirm that transaction amounts are valid.

Using this gap, the attacker created roughly 4,000 unbacked LBTC and converted it into real bitcoin. Crucially, no private keys or Liquid Federation signing keys were touched in the process. 

Before the incident, Liquid Network bitcoin reserve stood at about 4,205 coins. After the fraudulent peg-out and a few additional transactions processed before the network was halted, that reserve dropped to just 197 coins.

At a Glance

  • Date: September 6, 2026, Elements software bug exploited

  • Cause: Flaw in range-proof verification caching

  • Impact: ~4,000 unbacked LBTC created, converted to BTC

  • Reserve drop: ~4,205 token fell to ~197 token

  • Keys: No private or Federation keys compromised

  • Recovery: ~3,400 tokens returned; ~598.5 tokens still outstanding

  • Attackers' demand: 10% bug bounty from Blockstream, or 15% loss threat

  • Fix: Elements v23.3.4 patch released September 9

  • Status: Network paused, recovery plan underway in stages

How Attackers Minted Unbacked LBTC and Converted It to BTC?

The exploit worked because the flawed verification cache allowed newly created LBTC to appear valid even though no equivalent bitcoin backed it. The attacker then routed these tokens through SideSwap, a Liquid Federation member that operates a peg-out authorization key, or PAK, used to convert LBTC back into bitcoin.

That authorization key itself was never compromised. Because the validation failure happened earlier in the process, both SideSwap's systems and the Liquid Network's functionary nodes treated the tokens as legitimate. 

As a result, functionaries processed the withdrawal exactly as the protocol is designed to, releasing close to 4,000 BTC to the address SideSwap forwarded funds to.

Liquid Network Exploit

Source: Official Liquid Network News

SideSwap Says Operational Gaps Amplified the Liquid Network Loss

SideSwap has publicly acknowledged that while the underlying bug originated in Elements and not in its own infrastructure, two of its operational choices made the damage worse. Its peg-out authorization key stayed online at all times, and payouts to customers were forwarded automatically rather than being reviewed. 

The platform also had no checks in place for unusually large, fast, or suspicious peg-out requests, which let the roughly 4,000 LBTC withdrawal pass through unnoticed until it was too late.

SideSwap Says Operational Gaps Amplified the Liquid Network Loss

Source: Sideswap Post

Liquid Attackers Demand 10% Bug Bounty From Blockstream

In a new on-chain message, the individuals behind the exploit described themselves as white-hat security researchers. They alleged that Blockstream had spent only around $1.5 million, possibly nothing at all, to secure roughly $5 billion in assets. 

Based on that claim, they are demanding that Blockstream pay a 10% bug bounty out of its own funds, warning that refusal would result in a 15% loss for LBTC holders. 

The group also threatened to publish a private key that could decrypt earlier communications with Blockstream. These statements come directly from the attackers and remain unverified allegations rather than confirmed facts.

Liquid Attackers Demand 10% Bug Bounty From Blockstream

Source: Bitcoin News

3400 BTC Returned as Around 600 BTC Remains Outstanding

On September 7, the attackers returned approximately 3,400 BTC to the Liquid Federation. According to Liquid's official incident report, about 598.5 BTC, roughly 15% of the total taken, is still outstanding. 

Blockstream and the parties claiming responsibility are reportedly continuing discussions over the remaining funds, which the Federation now lists as an immediate priority.

Key Detail

Information

Exploit date

September 6, 2026

Vulnerability

Elements range-proof verification cache issue

Unbacked LBTC created

~4,000 LBTC

BTC released

~4,000 coins

Bitcoin (BTC) returned

~3,400 coins

BTC still outstanding

~598.5 coins

Liquid status

Network operations paused

Emergency fix

Elements v23.3.4

Attackers' claim

Self-described white-hat researchers

Bounty demand

10% bug bounty

Liquid Network Paused as Blockstream Deploys Elements v23.3.4 Fix

Liquid remains suspended while recovery work continues. Blockstream released Elements v23.3.4 on September 9 as an emergency patch addressing the cache vulnerability and strengthening how range proofs are verified. 

Functionary nodes are now being upgraded to the new version. The update closes the door on this specific exploit, though recovering the outstanding bitcoin remains a separate, ongoing effort.

Liquid Recovery Plan: Block Production First, Peg-Outs Later

Blockstream has outlined a three-stage path back to normal operations: resuming block production while peg-in and peg-out functions stay paused, replaying transactions already confirmed as valid, and only then restoring peg operations once the network state and 1:1 bitcoin backing are fully verified. 

The first two stages are being tested in parallel, and Blockstream has cautioned that the sequence could shift depending on results, with no stage advancing until deemed safe.

What the Liquid Exploit Means for BTC Holders and Liquid Users

For now, Liquid users cannot transact normally on the network. Other Liquid-issued assets, including USDT, were not directly affected by the vulnerability itself, though related services remain unavailable during the pause. 

According to official guidance, users do not need to take any proactive steps to protect their funds. Liquid and Blockstream have also warned about fake recovery websites and phishing attempts capitalizing on the incident, urging users to rely only on official channels.

The bottom line: the vulnerability has been patched, 3,400 Bitcoins has already been recovered, but around 600 BTC remains unresolved, and full restoration of the Liquid Network depends on the outcome of ongoing recovery and validation work.

Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency markets are volatile and carry significant risk. Readers should conduct their own research and consult a qualified professional before making any financial decisions.

Also read: Robinhood (HOOD) Stock Jumps 25% in a Month, and Analysts Think There’s More to Come
WHAT'S YOUR OPINION?
Related News