Liquid Network drained of $320 million as cache bug lets attacker mint unbacked Bitcoin

53 minutes ago 1



A range-proof cache bug in the Elements codebase let an unknown actor mint unbacked L-BTC, drain 95% of the federation reserve through SideSwap, then negotiate its return on-chain via OP_RETURN messages. The network remains frozen, 598.5 BTC sits in the attacker’s wallet, and the entire federated sidechain model faces the hardest questions it has ever had to answer. Summary An unknown actor exploited a range-proof verification cache bug in Elements to create roughly 4,000 unbacked L-BTC and peg them out for real Bitcoin on Sept. 6, 2026, draining 95% of Liquid’s reserves in 23 minutes. The attacker communicated via Bitcoin OP_RETURN messages, declaring “we are whitehats,” and returned 3,400 BTC after Blockstream patched its bridge nodes, while keeping 598.5 BTC (about $47 million) as a self-declared bounty. Blockstream confirmed no federation keys were compromised, attributing the exploit to a cache-key collision in the confidential transactions verification logic that had entered the Elements master branch but never appeared in a tagged release. The Liquid Network halted block production at 04:49 UTC on Sept. 7, exchanges suspended L-BTC deposits and withdrawals, and the network r...

Read Entire Article