Skip to content
Est. MMXXVIVol. VI · № 329RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 327Bridge Exploit

Liquid Network Range-Proof Cache Exploit

An attacker exploited a range-proof caching bug in Liquid's Elements software to mint about 4,000 unbacked L-BTC and peg them out for roughly $319 million in real bitcoin.

Date
Status
Partially Recovered

On September 6, 2026, the Liquid Network — the Bitcoin sidechain built by Blockstream — was drained of approximately 4,000 BTC, worth roughly $319 million, after an attacker exploited a validation bug to mint unbacked pegged bitcoin and redeem it for the real thing. It was the largest crypto theft of 2026 at the time.

What happened

Liquid is a federated two-way-peg sidechain: bitcoin locked with the federation is represented one-for-one by L-BTC, and holders peg out to withdraw real BTC from the reserve. The attack targeted the peg's integrity. A flaw in the range-proof verification cache of the open-source Elements node software let a confidential-transaction proof that had been verified in one context be reused to validate a different, fresh issuance — because the cache key omitted the asset and script context. In Liquid block 4,050,336, that let a single transaction inflate the L-BTC supply by about 4,000 coins with no bitcoin behind them. The attacker routed the unbacked L-BTC through the standard peg-out path via a federation member holding a Peg-out Authorization Key, producing a withdrawal of roughly 4,000 BTC on the Bitcoin mainchain. The reserve, which had held about 4,205 BTC, fell to 197 BTC before operators halted the network. A fix for the cache defect had been merged to public Elements branches days earlier but was not yet in any tagged release, so every production build the federation ran remained exploitable.

Aftermath

The perpetrators embedded an on-chain message declaring "we are whitehats. contact us on chain," and negotiated with Blockstream via on-chain messaging. After the team confirmed the bug had been patched, the attackers returned about 3,400 BTC — roughly $272 million, or 85% of the take — while keeping approximately 598 BTC (~$47 million) as a self-appointed bug bounty. The addresses were labelled by investigators but no identity was confirmed. Blockstream published a security-incident assessment detailing the range-proof cache root cause and the disclosure timeline.

Why it matters

Liquid joins the lineage of peg and bridge failures where the vulnerability was not in a user's contract but in the machinery that mints and redeems cross-chain value — the same unbacked-mint-then-withdraw pattern seen at Wormhole, Qubit Finance, Meter and Poly Network. The near-total return, like Poly Network's, shows how difficult moving nine figures of tainted bitcoin has become and how often large exploits now resolve as white-hat settlements. It also underscores a quieter hazard: a security fix merged to a public branch but not yet released is a roadmap for anyone reading the repository.

Sources & on-chain evidence

  1. [01]trmlabs.comhttps://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds
  2. [02]blog.blockstream.comhttps://blog.blockstream.com/liquid-network-security-incident-assessment/
  3. [03]crypto.newshttps://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/
  4. [04]cryptobriefing.comhttps://cryptobriefing.com/liquid-network-320m-hack-bitcoin-sidechain/
  5. [05]shattered.iohttps://shattered.io/liquid-network-320-million-hack-2026/

Related filings