Skip to main content
AVOID.NET
Liquid Network (Blockstream)1 decision on this page

Audit log

Every state-changing event for Liquid Network (Blockstream): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-11 12:06:14Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 446,152,932
    sig
    4XfiSkxamhtm…X7S5bxaaexplorer ↗
    hash
    8dt92xn1AADt…wvzCZmgWsha256 → base58
    verifying row…full verify ↗
    canonical bytes (28354 B) ▸
    {"actor":"system:backfill","investigation_id":"1f30b31e-050e-4ea9-8d70-49ddd7982cf3","kind":"publish","page_slug":"liquid-network-blockstream","published_at":"2026-09-11T12:06:14.675Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Liquid Network / Blockstream","sections":[{"content":"At 15:53:10 UTC on September 6, 2026 (Liquid block 4,050,336), an unknown actor exploited a vulnerability in the open-source Elements software that underpins the Liquid Network sidechain. The flaw resided in how Liquid nodes cache range-proof verifications used in confidential transactions. By exploiting the bug, the attacker created approximately 3,998.5 unbacked L-BTC tokens — Liquid's representation of Bitcoin — and then redeemed them through the SideSwap peg-out service, a Liquid Federation member holding a Peg-out Authorization Key (PAK). The federation's 11-of-15 multisig produced valid signatures because, from its vantage point, the peg-out appeared to be a legitimate authorized withdrawal. The federation reserve dropped from approximately 4,205 BTC to 197–202 BTC within minutes, representing a loss of roughly 95% of holdings. No private keys were compromised; the failure occurred at the software validation layer, above the cryptographic signing layer. Blockstream confirmed this characterization in its official incident report published September 8, 2026.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"Liquid Network Official Incident Report — X (@Liquid_BTC), September 8, 2026","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":2,"name":"Liquid Network drained of $320M in cache bug exploit — crypto.news","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"},{"credibility":2,"name":"Liquid Network Incident Analysis — CertiK","type":"research","url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"credibility":1,"name":"$320 million bitcoin exploit hits Liquid Network — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"}]},{"content":"According to analysis published by CertiK and reported across multiple technical sources, the vulnerability stemmed from an ambiguous cache-key encoding in the rangeproof verification cache within the Elements codebase. The cache key was derived solely from the proof bytes and the hidden commitment amount; it omitted asset type and scriptPubKey context. Because variable-length fields were concatenated into a SHA-256 stream without length delimiters, an attacker could shift bytes across field boundaries to engineer a cache-key collision — causing the system to treat two fundamentally different verification contexts as identical.\n\nThe attack unfolded in phases. First, the attacker submitted crafted setup transactions containing OP_RETURN scripts embedding specific cryptographic material (commitment values and asset generators), which populated the verification cache with a valid entry. Second, a malicious inflation transaction was submitted that reused the cached positive verification result by exploiting the collision, bypassing the actual rangeproof check. Because bypassing a rangeproof check allows an otherwise balanced Pedersen commitment equation to become an inflation mechanism, the attacker was able to create L-BTC with no corresponding BTC backing. Third, those unbacked tokens were routed through SideSwap's PAK-authorized peg-out pathway, which processed the request as legitimate.\n\nIndependent analysis cited in multiple sources noted that the fix for the rangeproof cache bug was publicly committed to the Elements GitHub repository on September 1, 2026 — five days before the exploit — with a descriptive commit title identifying the vulnerable code path. The commit was merged to the main branch on September 2. Federation nodes were running Elements v23.3.3, released April 13, 2026, which predated the fix by nearly five months and had not been updated to incorporate the patch. Independent researchers and multiple news outlets have suggested the attacker may have identified the vulnerability by reviewing the public fix commit, though this has not been confirmed by Blockstream.","heading":"Technical Root Cause: Cache-Key Collision in Range-Proof Verification","severity":"critical","sources":[{"credibility":2,"name":"Liquid Network Incident Analysis — CertiK","type":"research","url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"credibility":2,"name":"Analysis of the Liquid Network Cache Key Collision Vulnerability — SlowMist on Medium","type":"research","url":"https://slowmist.medium.com/analysis-of-the-liquid-network-cache-key-collision-vulnerability-nearly-4-000-l-btc-minted-out-of-e2010c446971"},{"credibility":2,"name":"Explained: The Liquid Network Hack, September 2026 — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-liquid-network-hack-september-2026"},{"credibility":2,"name":"Liquid Network drained of $320M in cache bug exploit — crypto.news","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"}]},{"content":"The Liquid Network's peg-out mechanism requires authorization via a Peg-out Authorization Key (PAK) held by a registered federation member. SideSwap, a decentralized exchange operating as a federation member, held such a PAK key. According to multiple sources, SideSwap's PAK key was connected to the internet at the time of the exploit and lacked automated velocity checks or per-wallet volume thresholds. SideSwap published a post-mortem on September 9, 2026, acknowledging these operational oversights.\n\nThe Liquid federation's 11-of-15 multisig functionaries signed the peg-out because the transaction appeared fully authorized from their perspective — the fraudulent L-BTC had passed (via the cache collision) the software validation layer that normally gates federation signing. No functionary keys were stolen or misused. Security researchers and commentators have noted this as a structural design concern: the 11-of-15 threshold protection, while robust against key compromise, did not protect against flawed software validation sitting above the signing layer. Critics characterized this as revealing that Liquid's security model depended on correct software behavior at a layer that the federation's cryptographic guarantees do not cover.","heading":"SideSwap PAK Pathway and Federation Multisig Behavior","severity":"high","sources":[{"credibility":2,"name":"Liquid Network Hack: $320M Bitcoin Sidechain Exploit — shattered.io","type":"news_article","url":"https://shattered.io/liquid-network-320-million-hack-2026/"},{"credibility":2,"name":"$320M Bitcoin Hack: What Really Happened to Liquid Network — Bitcoin Foundation","type":"news_article","url":"https://bitcoinfoundation.org/news/bitcoin/320m-bitcoin-hack-what-really-happened-to-liquid-network/"},{"credibility":2,"name":"Liquid Network Exploit Drained $316M Via Software Bug, Not Stolen Keys — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/326941/20260908/liquid-network-exploit-drained-316m-via-software-bug-not-stolen-keys.htm"}]},{"content":"The attacker communicated with Blockstream and the public via OP_RETURN messages embedded in Bitcoin mainchain transactions, identifying themselves as white-hat security researchers. In messages reported across multiple outlets, the attacker wrote 'we are whitehats' and 'Please fix the bug first,' conditional on confirming the vulnerability had been patched before any return of funds. PGP-encrypted messages were also reportedly exchanged with Blockstream. Blockstream characterized the claim as 'purported white hat' status and did not independently verify it publicly at the time of its incident report.\n\nSecurity researchers and commentators questioned the white-hat characterization. One researcher cited by Gizmodo argued: 'If you exploit vuln, steal 4k BTC and demand a fix for ransom, that's EXTORTION,' noting this could carry felony charges. Blockstream rejected what was described as a demand for a 10% bounty. The attacker ultimately returned 3,400 BTC on September 7, 2026, retaining 598.5 BTC (~$47M, approximately 15% of the total taken) as a self-declared bounty. No formal legal agreement, bug bounty program, or negotiated settlement has been publicly confirmed; Blockstream committed to covering the reserve gap rather than passing losses to L-BTC holders. Whether the retained 598.5 BTC constitutes a legal bounty, extortion, or theft remains legally unresolved as of this writing.","heading":"Attacker Communications and Claimed White-Hat Status","severity":"high","sources":[{"credibility":2,"name":"Hackers Drain $320 Million From Bitcoin's Liquid Network, Keep $47 Million for Themselves — Gizmodo","type":"news_article","url":"https://gizmodo.com/hackers-drain-320-million-from-bitcoins-liquid-network-keep-47-million-for-themselves-in-white-hat-operation-2000808262"},{"credibility":1,"name":"$320 million bitcoin exploit hits Liquid Network — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"credibility":2,"name":"Blockstream confirms bridge nodes patched, funds safe to return — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/blockstream-liquid-network-exploit-funds-return/"},{"credibility":2,"name":"Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"}]},{"content":"Blockstream deployed an emergency patch to its bridge nodes on September 7, 2026 at 01:09 UTC, closing the vulnerability. The emergency Elements v23.3.4 release — described as hardening the cache keys used for range proofs — was deployed on September 9 at 13:30 UTC following review by Blockstream's internal team, the Bitcoin Red Team, and Alpen Labs. Block production resumed on September 10 at 12:26 UTC, initially without user transactions as a precautionary measure to validate the patched software before processing real value. As of September 10, user transactions, peg-in, and PAK-authorized peg-out operations remained suspended pending network stabilization.\n\nBlockstream CEO Adam Back publicly committed that the 1:1 LBTC-to-BTC peg would be covered, urging L-BTC holders not to panic-sell on secondary markets during the suspension. Blockstream announced a three-stage recovery plan: Stage 1 (block production without transactions), Stage 2 (replay of verified valid transactions), and Stage 3 (resumption of peg operations). No stage would advance until deemed safe by the federation. Blockstream indicated a comprehensive post-mortem would follow but had not published a full technical post-mortem as of September 11, 2026.","heading":"Blockstream Response and Patch Deployment","severity":"high","sources":[{"credibility":2,"name":"Liquid Network Restarts Blocks After $320M Drain and Patch — SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/liquid-network-resumes-block-production-emergency-patch-september-2026/"},{"credibility":2,"name":"Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"credibility":2,"name":"Liquid Network Official Incident Report — X (@Liquid_BTC), September 8, 2026","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"}]},{"content":"A significant concern raised by independent analysts is that the fix for the rangeproof cache bug was publicly committed to the Elements GitHub repository on September 1, 2026 — five days before the exploit — with a descriptive commit title that identified the precise vulnerable code path. The commit was merged to the main branch on September 2. Federation production nodes were running Elements v23.3.3 (released April 13, 2026), which did not include the fix. No coordinated disclosure process, security advisory, or embargo appears to have been in place to prevent the public commit from telegraphing the vulnerability before production nodes could be updated.\n\nMultiple independent sources noted this as a potential factor in the timing of the attack, suggesting the attacker may have reverse-engineered the exploit from the public patch. Blockstream has not publicly confirmed or denied this inference as of September 11, 2026. This disclosure gap — fixing a critical vulnerability in a public repository without patching production nodes and without an accompanying security advisory — has drawn criticism from security researchers.","heading":"Responsible Disclosure and Pre-Exploit Commit Exposure","severity":"high","sources":[{"credibility":2,"name":"Liquid Network drained of $320M in cache bug exploit — crypto.news","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"},{"credibility":2,"name":"Analysis of the Liquid Network Cache Key Collision Vulnerability — SlowMist on Medium","type":"research","url":"https://slowmist.medium.com/analysis-of-the-liquid-network-cache-key-collision-vulnerability-nearly-4-000-l-btc-minted-out-of-e2010c446971"},{"credibility":2,"name":"Liquid Network Hack: $320M Bitcoin Sidechain Exploit — shattered.io","type":"news_article","url":"https://shattered.io/liquid-network-320-million-hack-2026/"}]},{"content":"Prior to the exploit, the Liquid federation reserve held approximately 4,205 BTC. Following the peg-out, the reserve dropped to approximately 197–202 BTC — a reduction of roughly 95%. The attacker returned 3,400 BTC on September 7, restoring the reserve to roughly 3,597–3,602 BTC. The outstanding 598.5 BTC (~$47M at time of exploit) represents the gap between the restored reserve and full backing for circulating L-BTC supply. Blockstream's public commitment from Adam Back — that the 1:1 peg will be 'covered' — means the company has pledged to absorb this shortfall rather than impose losses on L-BTC holders, though the mechanism and timeline for that coverage had not been formally disclosed as of September 11, 2026. USDT and other Liquid-issued assets were unaffected by the vulnerability itself but remained temporarily unavailable due to the network-wide pause in operations.","heading":"Financial Impact and Reserve Coverage","severity":"high","sources":[{"credibility":2,"name":"Liquid Network Exploit: Blockstream Recovers 3,400 BTC After $400M Bug — Blockonomi","type":"news_article","url":"https://blockonomi.com/liquid-network-exploit-blockstream-recovers-3400-btc-after-400m-bug"},{"credibility":2,"name":"Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"credibility":2,"name":"Liquid Network drained of $320M in cache bug exploit — crypto.news","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"}]},{"content":"The Liquid Network exploit occurred in proximity to a separate, unrelated incident affecting the Coldcard hardware wallet, manufactured by Coinkite. Beginning approximately July 30, 2026, an attacker exploited a firmware flaw traced to a March 2021 release in which a build configuration error caused seed generation to fall back on a weak software random number generator. Galaxy Research's running estimate placed Coldcard-related losses near 1,816 BTC (~$116M) drained from more than 5,200 addresses as of early September 2026, according to TRM Labs reporting. The two incidents are technically unrelated but occurred within weeks of each other, and commentators noted the combined effect on Bitcoin self-custody and infrastructure confidence. Crypto hacks in the first week of September 2026 totaled approximately $322M, with the Liquid Network incident accounting for the overwhelming majority, per CryptoTimes.","heading":"Broader Context: Simultaneous Bitcoin Infrastructure Incidents","severity":"medium","sources":[{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the $116M Coldcard Hack — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"Crypto Hacks Reached $322M in September's First Week — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/07/crypto-hacks-cross-322m-in-septembers-first-week-as-liquid-network-alone-loses-320m/"},{"credibility":3,"name":"Blockstream, Liquid Network and Coldcard: A $320 Million Hack Exposes the Cracks in Crypto's Plumbing — Rankiteo Blog","type":"news_article","url":"https://blog.rankiteo.com/blo1788885195-blockstream-liquid-network-coldcard-breach-september-2026/"}]},{"content":"As of September 11, 2026, no regulatory action has been announced by the SEC, CFTC, FinCEN, or any other jurisdiction in connection with the Liquid Network exploit. Analysts cited in reporting noted that Liquid itself is not a regulated custodian in most jurisdictions, and predicted regulatory attention — if any — would focus on exchange disclosure practices around suspended L-BTC withdrawals rather than on Blockstream directly. The legal status of the attacker's retained 598.5 BTC is unresolved: the self-declared 'white-hat bounty' was not negotiated through a formal bug bounty program, and at least one security researcher has publicly characterized the conduct as extortion. No criminal charges or civil proceedings have been reported. This section reflects the state of public information as of the investigation date and should be updated if regulatory or legal actions materialize.","heading":"Regulatory and Legal Status","severity":"medium","sources":[{"credibility":2,"name":"Liquid Network Hack: $320M Bitcoin Sidechain Exploit — shattered.io","type":"news_article","url":"https://shattered.io/liquid-network-320-million-hack-2026/"},{"credibility":2,"name":"Hackers Drain $320 Million From Bitcoin's Liquid Network, Keep $47 Million — Gizmodo","type":"news_article","url":"https://gizmodo.com/hackers-drain-320-million-from-bitcoins-liquid-network-keep-47-million-for-themselves-in-white-hat-operation-2000808262"},{"credibility":2,"name":"$320 Million Bitcoin Hack Hits Liquid Crypto Network — PYMNTS.com","type":"news_article","url":"https://www.pymnts.com/cryptocurrency/2026/hackers-take-320-million-dollars-from-liquid-network-blockchain/"}]}],"sources_used":[{"credibility":2,"name":"Liquid Network Official Incident Report — X (@Liquid_BTC), September 8, 2026","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":1,"name":"$320 million bitcoin exploit hits Liquid Network — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"credibility":2,"name":"Liquid Network drained of $320M in cache bug exploit — crypto.news","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"},{"credibility":2,"name":"Liquid Network Exploit Drained $316M Via Software Bug, Not Stolen Keys — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/326941/20260908/liquid-network-exploit-drained-316m-via-software-bug-not-stolen-keys.htm"},{"credibility":2,"name":"Explained: The Liquid Network Hack, September 2026 — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-liquid-network-hack-september-2026"},{"credibility":2,"name":"Liquid Network Incident Analysis — CertiK","type":"research","url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"credibility":2,"name":"Analysis of the Liquid Network Cache Key Collision Vulnerability — SlowMist on Medium","type":"research","url":"https://slowmist.medium.com/analysis-of-the-liquid-network-cache-key-collision-vulnerability-nearly-4-000-l-btc-minted-out-of-e2010c446971"},{"credibility":2,"name":"Liquid Network Restarts Blocks After $320M Drain and Patch — SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/liquid-network-resumes-block-production-emergency-patch-september-2026/"},{"credibility":2,"name":"Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"credibility":2,"name":"Liquid Network Exploit: Blockstream Recovers 3,400 BTC After $400M Bug — Blockonomi","type":"news_article","url":"https://blockonomi.com/liquid-network-exploit-blockstream-recovers-3400-btc-after-400m-bug"},{"credibility":2,"name":"Blockstream confirms bridge nodes patched, funds safe to return — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/blockstream-liquid-network-exploit-funds-return/"},{"credibility":2,"name":"Hackers Drain $320 Million From Bitcoin's Liquid Network, Keep $47 Million — Gizmodo","type":"news_article","url":"https://gizmodo.com/hackers-drain-320-million-from-bitcoins-liquid-network-keep-47-million-for-themselves-in-white-hat-operation-2000808262"},{"credibility":2,"name":"$320M Bitcoin Hack: What Really Happened to Liquid Network — Bitcoin Foundation","type":"news_article","url":"https://bitcoinfoundation.org/news/bitcoin/320m-bitcoin-hack-what-really-happened-to-liquid-network/"},{"credibility":2,"name":"Liquid Network Hack: $320M Bitcoin Sidechain Exploit — shattered.io","type":"news_article","url":"https://shattered.io/liquid-network-320-million-hack-2026/"},{"credibility":2,"name":"$320 Million Bitcoin Hack Hits Liquid Crypto Network — PYMNTS.com","type":"news_article","url":"https://www.pymnts.com/cryptocurrency/2026/hackers-take-320-million-dollars-from-liquid-network-blockchain/"},{"credibility":2,"name":"Crypto Hacks Reached $322M in September's First Week — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/07/crypto-hacks-cross-322m-in-septembers-first-week-as-liquid-network-alone-loses-320m/"},{"credibility":2,"name":"The Largest Hardware Wallet Exploit of 2026: Inside the $116M Coldcard Hack — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":3,"name":"Blockstream, Liquid Network and Coldcard: A $320 Million Hack Exposes the Cracks — Rankiteo Blog","type":"news_article","url":"https://blog.rankiteo.com/blo1788885195-blockstream-liquid-network-coldcard-breach-september-2026/"}],"summary":"On September 6, 2026, an attacker exploited a cache-key collision bug in Blockstream's open-source Elements software to mint approximately 4,000 unbacked L-BTC and peg them out through the SideSwap service, draining roughly 95% of the Liquid Network federation reserve (~$320M) in under 30 minutes. The attacker, communicating via Bitcoin OP_RETURN messages and claiming white-hat status, returned 3,400 BTC after Blockstream patched its bridge nodes but retained 598.5 BTC (~$47M) as a self-declared bounty. As of the investigation date (September 11, 2026), the network has resumed block production under Elements v23.3.4 but peg operations and user transactions remain suspended pending full stabilization.","timeline":[{"date":"2026-09-01","event":"A fix for the rangeproof cache bug was publicly committed to the Elements GitHub repository with a descriptive commit title identifying the vulnerable code path.","source":"crypto.news / SlowMist analysis","source_url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"},{"date":"2026-09-02","event":"The vulnerability fix commit was merged into the Elements main branch. No production federation nodes had been updated to include the fix.","source":"crypto.news / independent analyst reporting","source_url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"},{"date":"2026-09-06","event":"At 13:52:10 UTC, attacker submitted setup transactions to prime the rangeproof verification cache. At 13:53:10 UTC, the inflation transaction was submitted exploiting the cache collision.","source":"CertiK Liquid Network Incident Analysis","source_url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"date":"2026-09-06","event":"Between 14:00 and 14:06 UTC, peg-out transactions were submitted. At 14:28:56 UTC (Bitcoin block 965,783 / Liquid block 4,050,336), approximately 3,996–3,998.5 BTC exited the federation reserve through SideSwap's PAK-authorized peg-out, collapsing reserves from ~4,205 BTC to ~197–202 BTC.","source":"Liquid Network Official Incident Report; CertiK; CoinDesk","source_url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"date":"2026-09-07","event":"Blockstream deployed an emergency patch to bridge nodes at 01:09 UTC, closing the vulnerability. Liquid Network paused block production at 04:49 UTC.","source":"Liquid Network Official Incident Report","source_url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"date":"2026-09-07","event":"Attacker communicated via Bitcoin OP_RETURN messages and reportedly PGP-encrypted messages, claiming white-hat status and making return of funds conditional on confirmed patching. Blockstream confirmed bridge nodes were patched and safe for funds to be returned.","source":"CoinDesk; CryptoBriefing","source_url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"date":"2026-09-07","event":"At 16:09:25 UTC (Bitcoin block 965,950), the attacker returned 3,400 BTC to the Liquid Federation peg wallet. 598.5 BTC (~$47M) was retained as a self-declared bounty.","source":"Liquid Network Official Incident Report; Blockonomi","source_url":"https://blockonomi.com/liquid-network-exploit-blockstream-recovers-3400-btc-after-400m-bug"},{"date":"2026-09-08","event":"Blockstream published official incident report at 19:10 UTC. Blockstream CEO Adam Back publicly stated the 1:1 LBTC-to-BTC peg would be covered and urged holders not to panic-sell.","source":"Liquid Network Official Incident Report; CryptoTimes","source_url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"date":"2026-09-09","event":"SideSwap published a post-mortem acknowledging operational oversights including keeping the PAK key internet-connected and lacking automated velocity checks. Blockstream deployed Elements v23.3.4 at 13:30 UTC following review by internal teams, the Bitcoin Red Team, and Alpen Labs.","source":"SpendNode; CryptoTimes","source_url":"https://www.spendnode.io/blog/liquid-network-resumes-block-production-emergency-patch-september-2026/"},{"date":"2026-09-10","event":"Liquid Network resumed block production at 12:26 UTC under Elements v23.3.4, initially producing empty blocks without user transactions. Peg-in and peg-out operations remained suspended.","source":"CryptoTimes; SpendNode","source_url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"date":"2026-09-11","event":"As of this investigation date, user transactions and peg operations remain suspended. No full technical post-mortem from Blockstream has been published. No regulatory actions have been announced. The legal status of the retained 598.5 BTC is unresolved.","source":"CryptoTimes; investigator assessment","source_url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision b58a66c2-67ba-4988-acb6-c31d55b6ca41
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.