The Liquid Network suffered a major security breach on September 6, 2026, after attackers exploited a flaw in its Elements software.
The exploit allowed roughly 4,000 unbacked LBTC tokens to be minted and converted into real bitcoin through the network’s peg-out system.
Blockstream confirmed the Liquid Federation has since recovered most of the stolen funds, though the network remains offline while a patch is finalized.
The incident occurred at Liquid block 4,050,336, when a vulnerability in range proof verification caching went unnoticed by the system.
This flaw let attackers create LBTC that had no bitcoin reserves backing it. The unbacked tokens were then routed through SideSwap, a Liquid Federation member holding peg-out authorization.
Because the validation failure happened before the peg-out request was submitted, SideSwap’s node and the network’s functionaries treated the transaction as legitimate.
The peg-out mechanism itself worked exactly as intended, releasing bitcoin to a whitelisted address tied to SideSwap. From there, the funds were forwarded to an address controlled by the exploiters.
Blockstream clarified that no private keys were compromised during the attack. The Liquid Federation’s functionary nodes operated normally throughout the incident.
Before the breach, the Liquid reserve held close to 4,205 BTC in total. After the unauthorized peg-outs were processed, that balance dropped sharply to just 197 BTC.
Other assets issued on the Liquid Network, including USDT, were not directly affected by the vulnerability. However, those tokens remain temporarily unavailable since the entire network has been paused.
In its statement, Liquid Network said the failure came from several factors that “interacted in ways that ultimately defeated the system’s built-in redundancies.”
Shortly after the exploit, the responsible party left a message on the bitcoin mainchain. They identified themselves as white-hat security researchers and asked to coordinate with Blockstream on fixing the vulnerability. This message came before any funds had been returned to the network.
Blockstream moved quickly to contain the damage once the exploit was discovered. A patch for the Liquid Network’s bridge nodes was deployed by September 7 at 01:09 UTC. This update closed the vulnerability, preventing any further exploitation of the same flaw.
On September 7 at block 965,950, the exploiters returned 3,400 BTC to the Liquid Federation’s peg wallet. That leaves approximately 598.5 BTC, or 15% of the total taken, still outstanding.
Blockstream said discussions with the individuals involved are continuing in an effort to recover the remaining bitcoin.
Blockstream announced that an emergency release of Elements, version 23.3.4, is currently undergoing review. The update is expected within roughly 48 hours of the announcement.
Once deployed, functionary operators will apply further adjustments to restore full network operations. Liquid Network users have been told no proactive action is required to protect their existing funds at this time.
The post Liquid Network Exploit: Blockstream Recovers 3,400 BTC After $400M Bug appeared first on Blockonomi.