Blockstream’s Liquid Network, one of the oldest and most prominent Bitcoin sidechains, lost approximately 4,000 BTC, worth roughly $320 million, after hackers exploited a bug in its underlying software on September 6. The federation’s reserves cratered from over 4,200 BTC to about 197 BTC in a single stroke, making it one of the largest security breaches involving a Bitcoin-adjacent network this year.
The silver lining, if you can call it that: the attackers identified themselves as white-hat hackers and returned around 3,400 BTC after Blockstream confirmed it had patched the vulnerability. They kept approximately 598 BTC, valued at roughly $47 million, as a self-appointed bounty.
How the exploit worked
The vulnerability lived in the Elements software, the open-source codebase that powers the Liquid Network. Specifically, a range-proof verification cache bug allowed the attackers to create invalid Liquid Bitcoin (L-BTC) tokens that the system accepted as legitimate. Those fraudulent tokens were then processed through SideSwap’s Peg-out Authorization Key (PAK), which converted them into real BTC withdrawals from the federation wallet.
Critically, no federation keys were compromised during the attack. The Liquid Network operates on an 11-of-15 federation multisig model, meaning 11 out of 15 designated entities must sign off on transactions. The multisig itself held up fine. The problem was upstream: the software that validates what gets sent to the multisig in the first place.
Other assets held on the Liquid Network, including USDT and tokenized real-world assets, were not affected by the exploit. The bug was specific to L-BTC token validation.
The fallout and the freeze
Despite the partial return of funds, the Liquid Network remains paused. All activity involving L-BTC has been suspended across exchanges, and there’s no public timeline for when normal operations will resume. For a network that launched in 2018 with the explicit promise of providing faster, more confidential Bitcoin transactions for institutional traders, this is a significant credibility blow.
The federation’s reserves tell the story in stark terms. Before the attack, the wallet held over 4,200 BTC. After the white-hat return, it’s sitting at roughly 3,600 BTC, still short by the 598 BTC the hackers kept.
The incident also raises uncomfortable questions about federated sidechain architecture more broadly. Liquid’s model places trust in a relatively small group of entities to secure the bridge between Bitcoin’s main chain and the sidechain. When the software those trusted entities rely on has a critical bug, the whole model’s value proposition takes a hit.
Wider implications for Bitcoin infrastructure
The Elements codebase, while open-source and auditable, clearly needed more rigorous review of its verification logic. A cache bug in range-proof validation is exactly the kind of subtle, deeply technical flaw that can cause catastrophic damage when discovered.
The Elements codebase is used beyond just Liquid, and any project built on it will need to demonstrate that the same vulnerability doesn’t exist in their implementation.
The white-hat framing of the attack, while genuine in outcome, also sets a complicated precedent. Keeping $47 million in Bitcoin as an unsolicited bounty is a practice that exists in a legal gray zone. Whether regulators or law enforcement view it as responsible disclosure or theft with partial restitution could shape how similar incidents are handled going forward.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

51 minutes ago
13









English (US) ·