Liquid Network Loses 4,000 Bitcoin (BTC) to Elements Verification Exploit
An attacker minted 4,000 unbacked LBTC on Liquid Network; 3,400 BTC returned to the peg wallet while 598.5 BTC remains outstanding and talks continue.
AI SummaryAI
- Liquid Network attack minted roughly 4,000 unbacked LBTC at 15:53 UTC on September 6.
- Liquid reserves fell from about 4,205 BTC to 197 BTC after the exploit.
- Attacker returned 3,400 BTC to the federation peg wallet via mainchain block 965950.
- About 598.5 BTC, roughly 15% of the stolen amount, remained unrecovered as of September 8.
4,000 Fake LBTC Minted in Verification Flaw
Roughly 4,000 Bitcoin (BTC) was illicitly minted and drained from Liquid Network, the federated sidechain operated by Blockstream that lets users move BTC onto a faster, more confidential transaction layer. The network's official incident disclosure places the breach at 15:53 UTC on September 6, at Liquid block 4,050,336, when an attacker exploited a vulnerability in the verification process of Elements, the open-source codebase Liquid runs on, generating approximately 4,000 LBTC — the sidechain's pegged bitcoin token — with no underlying reserve BTC behind them. Liquid operates a two-way peg: funds enter through a peg-in and are redeemed by burning LBTC to release mainchain bitcoin, with redemptions normally routed through authorized members. The attacker converted the fraudulent LBTC into native bitcoin through SideSwap, a federation member holding peg-out authorization keys (PAK). Because the verification error surfaced at the transaction stage before the peg-out executed, SideSwap's node and the federation's functionary nodes accepted the withdrawal as legitimate, routing about 4,000 BTC through SideSwap's whitelisted addresses to attacker-controlled wallets. The disclosure is explicit that no functionary node was compromised and no private key leaked: the peg-out mechanism worked precisely as designed, and the failure sat in upstream validation — a rare combination of independent factors that defeated existing defenses. The reserve damage is severe. The peg wallet held roughly 4,205 BTC before the event; after the drain plus additional peg-outs processed before the halt, about 197 BTC remained, meaning roughly 95% of the backing behind LBTC vanished in a single transaction. Other assets issued on the network, such as its USDT representation, are not themselves affected by the flaw, though the network-wide halt has left them temporarily unusable. Ordinary users not running nodes need take no protective action at this time, the operator says, while the forensic investigation continues.
3,400 BTC Returned to the Peg Wallet
Recovery came within a day. Blockstream placed a patch on the bridge nodes by 01:09 UTC on September 7, shutting the path the attacker had used. Later that morning, at 09:41:26 UTC, an on-chain message stating that the fix was applied and that returning the funds would be safe was recorded on the mainchain, with a signature that verifies against Blockstream's published security key. At 16:09:25 UTC, a recovery transaction included in Bitcoin mainchain block 965950 sent 3,400 BTC back to the federation's peg wallet — covering roughly 85% of what was taken. The attacker, who left a mainchain message describing himself as a whitehat security researcher and inviting contact about the vulnerability's handling, retained about 598.5 BTC — roughly 15% of the total — and negotiations for its return were still running as of September 8. No public information confirms the remainder was an agreed bounty, and the stash now ranks the attacker's address among notable Bitcoin whales. The on-chain arithmetic is stark: approximately 3,996 BTC left reserves that had held about 4,200 BTC, a sum of roughly 49.9 billion yen at the exchange rate prevailing at the time. LBTC redemptions require burning the token to release mainchain bitcoin, a step ordinary users normally route through authorized members or businesses — which is why retail holders face no immediate action. Normalization is the next step. The team plans an emergency release of patched software, Elements v23.3.4, within 48 hours, after which functionary node operators are expected to coordinate measures including invalidation of the fraudulent peg-outs before trading resumes. As of September 8 the network was still halted: the operator's status page listed the ongoing incident, exchanges had suspended deposits and withdrawals through the bridge, and swap services stopped peg-ins and peg-outs. Full backing can only be verified once recoverable reserves are reconciled against valid LBTC balances outstanding.
Wrapped Trust, Not Proof of Work
COINOTAG's reading: the load-bearing facts here live on-chain, not in commentary. The recovery transaction in block 965950, the attacker's whitehat note and the drained balance of roughly 3,996 BTC are all independently verifiable on the Bitcoin mainchain, while the team's post-mortem fixes both root cause and remediation: a pre-peg-out verification failure in Elements, patched on the bridge and to be closed out with the v23.3.4 release. The episode underlines that L-BTC is a wrapped asset — closer in trust design to wrapped Bitcoin (WBTC) than to mainchain proof-of-work security — and anyone routing BTC through Bitcoin DeFi layers, or watching the wider Bitcoin ecosystem's sidechain experiments, should track reserve attestations rather than brand names.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


