T
iTokenly

Liquid Network (Elements range-proof cache) hack — September 2026

Verified — 7 sourcesLast checked September 10, 2026

Incident facts

Date of incident
Target typeCross-chain bridge
Loss$320,000,000Price at time of incident
Recovered$270,000,000
MethodSignature verification flawElements nodes cached range-proof verifications under a key that left out the asset type and output script, so an already-verified proof could be replayed to create about 3,996 unbacked L-BTC, which were then redeemed for real bitcoin through the standard peg-out
ChainsBitcoin, Other
OutcomePartially recovered

What happened

Liquid, the Bitcoin sidechain run by a federation of companies and developed by Blockstream, lost about 3,996 BTC from its peg reserve on 6 September 2026, roughly $320m at the time. The reserve backing every L-BTC in circulation fell from about 4,205 BTC to roughly 200, around 95% of it gone. No key was stolen. The coins were created on Liquid out of nothing and then redeemed for real bitcoin through the ordinary peg-out.

The flaw was in Elements, the open-source software Liquid runs on. Nodes cache the result of verifying a range proof, the cryptographic proof that a confidential amount is valid, and the cache key was derived from the proof bytes and the hidden amount alone, without the asset type or the output script the proof belonged to. A proof that had already passed could therefore be replayed where it should have failed. The attacker seeded the cache with 68 identical range proofs over about fourteen hours, between Liquid blocks 4,049,384 and 4,050,246, then used it in block 4,050,336, at about 13:53 UTC, to create roughly 3,996 L-BTC with no bitcoin behind them. Elements 23.3.4, released on 9 September, hardens the range-proof cache keys and adds an option to switch the cache off; the federation had been running 23.3.3, released in April. Accounts differ on when the flaw entered the code.

The counterfeit coins went out through SideSwap, a federation member that holds a peg-out authorisation key and runs an automated peg-out service. The federation paid out 3,996.0183 BTC at 14:28:56 UTC, about thirty-six minutes after the coins were created, and SideSwap forwarded it to the attacker. According to The Crypto Times, the key was kept online and peg-out orders faced no meaningful size, rate, velocity or wallet-history checks, so a large order from a new wallet cleared automatically. Blockstream and SideSwap both say no key was compromised.

At 18:30 UTC the attacker wrote in a Bitcoin OP_RETURN message, 'we are whitehats. contact us on chain', and later asked for every node to be patched before anything was sent back. Blockstream patched its bridge nodes by 01:09 UTC on 7 September and confirmed it in a signed message at 09:04 UTC. At 16:09:25 UTC that day 3,400 BTC, about $270m, came back to the federation's peg wallet. The attacker kept about 598.5 BTC, some $47m, as a self-declared bounty. Ledger's chief technology officer, Charles Guillemet, said genuine white hats disclose a flaw before moving hundreds of millions in collateral, not after.

Liquid halted block production at 04:49 UTC on 7 September, and when it resumed it did so from the block before the exploit. Block 4,050,335 is still stamped 13:52:10 UTC on 6 September, but the block now at 4,050,336 is stamped 21:05:10 UTC on 9 September. The exploit block and the roughly fifteen hours of history up to the halt are no longer part of the chain, and the federation's recovery plan replays transactions verified as valid before peg-ins and peg-outs reopen. That removes the counterfeit L-BTC from Liquid, but it cannot reach bitcoin that has already left on the main chain. The federation's own incident report puts the exploit at 15:53:10 UTC, two hours later than the surviving block times and SideSwap's account.

On 10 September Liquid said it was producing blocks again, without user transactions at first and with peg operations still suspended. Adam Back, Blockstream's chief executive, said the L-BTC peg would be covered, but no mechanism or timetable has been published, so the outcome is recorded as a partial recovery rather than a reimbursement. The headline records the roughly $320m that left the reserve, and the returned 3,400 BTC is recorded separately as recovered. This is unrelated to the 2021 theft from the Liquid Global exchange, which has its own entry in this registry.

Sources

  1. The Hacker NewsSecondary · retrieved 2026-09-10
  2. crypto.newsSecondary · retrieved 2026-09-10
  3. GizmodoSecondary · retrieved 2026-09-10
  4. The Crypto TimesSecondary · retrieved 2026-09-10
  5. The Crypto BasicSecondary · retrieved 2026-09-10
  6. Elements Project, release notes for elements-23.3.4Primary · retrieved 2026-09-10
  7. Liquid block explorer, blocks 4,050,335 and 4,050,336On-chain · retrieved 2026-09-10

Changes to this entry

  • Recorded four days after the incident. The amount is the roughly $320m publishers put on the 3,996 BTC released from the peg reserve at the time; the 3,400 BTC returned on 7 September is recorded as recovered at The Crypto Basic's $270m. The rewind of Liquid's own chain was checked against the Blockstream block explorer on 10 September: block 4,050,335 is stamped 13:52:10 UTC on 6 September and the block now at 4,050,336 is stamped 21:05:10 UTC on 9 September. The federation's incident report times the exploit at 15:53:10 UTC, which the block times contradict by two hours; 13:53 UTC is used here, matching SideSwap's account. If the shortfall is made good, the outcome will be updated.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Liquid Network (Elements range-proof cache) hack — September 2026", iTokenly, accessed 2026-09-10, https://itokenly.com/hacks/liquid-network-rangeproof-cache
https://itokenly.com/hacks/liquid-network-rangeproof-cache

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.