TL;DR
- A software bug let roughly 4,000 BTC, worth about $320 million, leave the reserves backing Liquid’s L-BTC token.
- Nobody stole any federation keys. Every signature on the payout was valid.
- The withdrawn Bitcoin has not moved, and Liquid Network’s reserve now holds about 197 BTC after the exploit.
Liquid Network disabled the bridge connecting it to Bitcoin after a $320 million exploit pulled roughly 4,000 BTC out of the reserves that back its L-BTC token. That is close to 95% of the 4,200 BTC the network held before the withdrawal. When that much Bitcoin disappears, the first suspect is usually a stolen key. That was not the case here. Bitquery, a blockchain research firm, traced the withdrawal to a software bug that let someone create L-BTC that was never backed by real Bitcoin, then exchange it for real Bitcoin anyway.
What Liquid is, in plain terms
Liquid is a sidechain, a companion network built on top of Bitcoin, developed by the company Blockstream. People send BTC into a shared reserve controlled by a group of institutions called the Liquid Federation, and receive an equal amount of a token called L-BTC in return. Moving funds requires eleven of the federation’s fifteen members to sign off. L-BTC settles faster than regular Bitcoin and can carry other assets, including tokenized dollars. Sending L-BTC back to the federation destroys the token and releases the matching BTC from the reserve. Liquid calls this process a peg-out. The federation is supposed to back every L-BTC in circulation one for one with real Bitcoin sitting in that reserve.
The withdrawal, step by step
SideSwap, a company that runs one of Liquid’s official peg-out desks, said a customer sent it 4,000 L-BTC at 14:05 UTC on September 6. SideSwap processed the order as it always does: it destroyed the L-BTC on Liquid and asked the federation to release the matching Bitcoin, using an authorization key known as a PAK that is unique to each approved desk. Twenty-three minutes later, at 14:28 UTC, the federation paid out roughly 3,996 BTC to the customer’s Bitcoin address.
SideSwap said its own PAK remained secure, and Liquid confirmed that none of its other keys were stolen either. Every signature involved in the payout was genuine. The network treated the 4,000 L-BTC as legitimate and released the Bitcoin that was supposed to back it.
>>> Read more: Bitcoin BIP-110 Proposal Divides Developers and Miners
Signs of a rehearsal
Bitquery’s investigation reaches back roughly a day before the exploit that drained Liquid Network’s reserves. The wallet behind it received about 2 BTC on September 4, from a mix of small, aged Bitcoin holdings, and converted it into L-BTC. Over the following day it made 92 test transactions on Liquid, most of them tiny.
Seventy of those transactions shared an unusual trait. Each carried a hidden amount alongside a note, written in plain text. That note identified the asset as L-BTC. Sixty-eight of them shared something more specific. Each carried the identical hidden amount and the identical cryptographic range proof, byte for byte. These proofs spread across Liquid blocks over about 14 hours. A range proof is the piece of math that lets a Liquid node confirm a hidden amount. It confirms the amount is not negative, without revealing the actual number. A negative amount would be a way to create Bitcoin that was never really there. So every node checks a range proof before it accepts a transaction. Nodes save time by remembering proofs they have already checked instead of checking them again.
Bitquery’s read is that repeating one identical proof 68 times looks like an attempt to get that exact proof lodged in the memory of every node on the network. What the wallet did with that positioning is the part the public record does not show directly, though the timing lines up closely with what happened next.
The suspected bug
SideSwap said within hours that the exploit traced back to a bug in Elements, the open-source software that runs Liquid Network. Its own system was not affected. Blockstream has not named the specific flaw.
Bitquery found a fix in the Elements codebase, first committed by a Blockstream engineer on August 3 and formally proposed as a pull request on August 31, that changed what a node’s cache remembers about a range proof it has already checked. Before the fix, the cache recorded only the proof itself. After the fix, it records the proof together with the specific asset and output it was checked against.
The pattern behaves like a guard who recognizes a badge and stops checking it. He never confirms who is wearing it or which door it is being used for. Show him that badge once, and he waves it through anywhere, on anyone. Before the fix, a node that had already verified one range proof would recognize it again. It would skip a real check the second time, even on a different transaction. That second transaction could carry a completely different amount of L-BTC. The 68 identical proofs planted across Liquid over 14 hours would have relied on exactly that gap. They marked one proof as already checked in the memory of nodes across the network. Nodes could then wave it through again once it mattered.
Nobody shipped the Fix
Developers merged the fix into Elements’ main code branch on September 2. They backported it to the older release line the next day. That was four days ahead of the exploit. Merging a fix into the source code is not the same as shipping it. Shipping means getting it to the nodes that run the network.
Software normally moves from a merged commit into a packaged release before node operators install it. That packaging step remained pending on September 6. The most recent released version of Elements dated back to April. It predated the fix by months. The nodes running Liquid that day ran that older, unpatched version. The fix had been sitting in public view on GitHub for weeks already. Anyone reading Elements’ commit history in late August could have seen what the old caching logic allowed. Blockstream folded the fix into an upcoming release candidate on September 6 at 17:21 UTC. That happened after the withdrawal had already taken place.
Blockstream has not confirmed this is the exact vulnerability the attacker exploited. The case for a connection is built on timing: the fix, the mint, and the release candidate all landed within days of each other, and no alternative explanation has surfaced.
A negotiation carried out in public
After the payout, the attackers moved the Bitcoin to a single address and wrote a short note directly into the blockchain, using a feature called OP_RETURN that lets anyone attach a small message to a transaction: “we are whitehats. contact us on chain.” Blockstream answered the same way roughly an hour later. It sent a small transaction of its own with a note asking the holder to email its security team.
Over the following hours the two sides traded seven messages this way. Galaxy Digital’s research head Alex Thorn reconstructed and published the sequence from the raw on-chain transactions. The exchange included an encrypted, signed note from Blockstream and a reply from the holder promising to return “most” of the funds once Blockstream fixed the bug and every node had the patch. Blockstream replied on September 7 that its bridge nodes were now patched and it was safe to send the funds back.
Not everyone accepts the “white hat” framing. Ledger’s chief technology officer, Charles Guillemet, wrote that draining a bridge before making any contact was not how security researchers usually behave. He raised the possibility that the actors found the bug with help from AI tools and were unfamiliar with standard disclosure practices. He offered the idea as speculation, not a confirmed explanation.
A separate party tried to take advantage of the standoff. On September 7, someone sent the holder a message impersonating Blockstream and asking for 3,900 BTC to be sent to a different address. Bitquery flagged the attempt as a likely scam, since the message carried no valid signature from Blockstream’s security key.
>>> Read more: Stefan Smith on Bitcoin and Goldfishes
Where things stand
Liquid disabled its bridge nodes within hours of the incident, stopping Bitcoin and other assets from moving between the main Bitcoin chain and Liquid. It also asked exchanges to pause L-BTC deposits and withdrawals. The other assets Liquid carries, including tokenized dollars, are not backed by the Bitcoin reserve, so the shortfall does not affect their backing.
The withdrawn Bitcoin sits untouched at the address it landed in. The federation’s reserve backing Liquid Network now holds roughly 197 BTC, about 4.7% of what it held before the exploit. The exploit destroyed the fraudulent L-BTC the moment SideSwap cashed it out, without touching the honest L-BTC already in circulation, so the total supply of L-BTC did not shrink to match the reserve. Real Bitcoin now backs only about five cents of every dollar of L-BTC outstanding.
The holder has not put a number on how much “most” means in Bitcoin. Whether Liquid absorbs the remainder as a loss or treats it as the cost of finding the bug is a decision nobody has announced.








