Blockstream's Liquid Network Hit by 4,000 BTC Exploit; Whitehats Return Most Funds

AI Market Summary
A critical Elements software bug enabled issuance of invalid LBTC that was converted into real BTC withdrawals from Liquid's federation wallet, briefly draining ~4,000 BTC before a partial whitehat return. Even with most funds restored, ~598 BTC remains missing and the network is paused, suspending LBTC activity. The episode undermines confidence in federated Bitcoin sidechains and raises broader security and governance scrutiny for Bitcoin-adjacent infrastructure.
Impact level
● High
Affected assets
BTC/USDT-1.20%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Blockstream's Liquid Network, one of Bitcoin's longest-running and best-known sidechains, suffered a major security incident on Sept. 6 after attackers exploited a flaw in its underlying software. About 4,000 BTC—roughly $320 million at the time—was drained as the federation's reserves plunged from more than 4,200 BTC to around 197 BTC in a single event, marking one of the largest breaches involving a Bitcoin-adjacent network this year. The attackers later claimed to be whitehat hackers. After Blockstream said it had patched the vulnerability, roughly 3,400 BTC was returned. About 598 BTC, valued at around $47 million, was retained as a self-declared bounty. Elements bug enabled counterfeit LBTC The issue originated in Elements, the open-source codebase that powers the Liquid Network. A rangeproof verification cache bug allowed the attackers to mint invalid Liquid Bitcoin (LBTC) that the system treated as legitimate. Those counterfeit tokens were then routed through SideSwap's Pegout Authorization Key (PAK) process, which ultimately enabled withdrawals of real BTC from the federation wallet. Blockstream said no federation keys were compromised. Liquid runs on an 11-of-15 federation multisig design, requiring 11 of 15 member entities to sign transactions. The multisig mechanism functioned as intended; the failure occurred earlier in the flow, in the software responsible for validating what was being presented to the multisig for authorization. Other Liquid-issued assets, including USDT and tokenized real-world assets, were not affected. The bug was specific to LBTC validation. Network remains paused Despite the partial recovery of funds, Liquid remains paused and LBTC-related activity is suspended across exchanges. No public timeline has been provided for a full resumption of operations. Launched in 2018 to offer faster and more confidential Bitcoin transactions aimed at institutional traders, Liquid now faces a significant hit to credibility. The federation's reserves underscore the impact: the wallet held more than 4,200 BTC before the attack and sits near 3,600 BTC after the return, still short by the 598 BTC kept by the attackers. The incident also renews scrutiny of federated sidechain architecture. Liquid relies on a relatively small set of entities to secure the bridge between Bitcoin's main chain and the sidechain. A critical bug in the software those entities depend on can undermine the model's core trust assumptions. Broader implications for Bitcoin infrastructure Elements is open-source and auditable, but the exploit highlights the need for more rigorous review of verification logic. A cache bug in rangeproof validation is the kind of subtle, highly technical flaw that can lead to outsized losses once discovered. Because Elements is used beyond Liquid, other projects built on the codebase will face pressure to prove the same vulnerability is not present in their implementations. The whitehat framing introduces its own complications. Retaining $47 million worth of BTC as an unsolicited bounty sits in a legal gray area. How regulators and law enforcement interpret the action—responsible disclosure versus theft with partial restitution—could influence how similar incidents are treated in the future.