HeadlinesBriefing favicon HeadlinesBriefing.com

Liquid Network Security Incident Assessment

Hacker News •
×

On September 6, 2026, an attacker exploited a vulnerability in Elements' rangeproof verification cache on the Liquid Network, inflating LBTC supply by approximately 4,000 LBTC without bitcoin backing. The attacker moved the unbacked LBTC through Liquid's peg-out process via Side Swap, a Federation member holding a Peg-out Authorization Key (PAK), resulting in a withdrawal of approximately 4,000 BTC confirmed in Bitcoin block 965,783. Smaller peg-outs confirmed before the network was halted brought the Liquid reserve down from about 4,205 BTC to 197 BTC.

The attacker identified themselves on-chain within hours and returned 3,400 BTC on September 7, leaving approximately 602 BTC outstanding. Blockstream coordinated a halt of the Liquid bridge nodes, deployed an emergency interim patch, and shipped Elements v23.3.4 within days. All other Liquid-issued assets were unaffected but unavailable during the pause.