Liquid Network / Elements Cache-Bug Exploit (September 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·5sh8WP…4eAoSummary
On September 6, 2026, an unidentified attacker exploited an ambiguous cache-key encoding flaw in the open-source Elements software underpinning Blockstream's Liquid Network sidechain. Approximately 3,998.5 unbacked L-BTC (valued at roughly $320 million) were minted and pegged out for native Bitcoin, draining an estimated 95% of the federation's reserves. The attacker returned 3,400 BTC on September 7 and retained 598.5 BTC (~$47 million), characterizing the retention as a 15% bounty; Blockstream's September 11 public statement rejects this characterization and refuses to treat the incident as a white-hat disclosure, stating the retained funds constitute theft.
Connected Entities
1 entitiesTimeline(9 events)
1 September 2026
A fix for the rangeproof cache-key collision bug was reportedly merged to the Elements development branch. No tagged release contained it; production nodes remained on the vulnerable build.
CryptoSlate / on-chain researcher Mononaut6 September 2026
Between approximately 11:30 and 13:16 UTC, the attacker executed a series of dry-run peg-out transactions on the Liquid Network, testing the exploit mechanism.
CryptoSlate / CertiK6 September 2026
At 13:52:10 UTC, the attacker broadcast setup (cache-priming) transactions. At 13:53:10 UTC, the malicious inflation transaction was submitted at Liquid block 4,050,336, exploiting the cache-key collision to create approximately 3,998.5 unbacked L-BTC.
CertiK Liquid Network Incident Analysis6 September 2026
At 14:06:10 UTC, the second (main) peg-out of 3,996.02 L-BTC was submitted via SideSwap. At 14:28:56 UTC, the attacker received 3,996.02 BTC on Bitcoin mainnet. Federation reserves fell from approximately 4,205 BTC to 197 BTC — a 95% drain.
CertiK / crypto.news7 September 2026
Blockstream deployed emergency security patch at approximately 01:09 UTC, updating functionary and bridge nodes to a hardened Elements build (emergency release Elements v23.3.4 announced).
Liquid Network official incident report (X/@Liquid_BTC)7 September 2026
The attacker returned 3,400 BTC to the Liquid Federation wallet at approximately 16:09–18:09 UTC, retaining 598.5 BTC. On-chain messages identified the actors as 'whitehats' and demanded a 10% bounty from Blockstream's corporate treasury.
The Hacker News / Blockonomi8 September 2026
Liquid Network published its official incident report at 19:10 UTC. Report confirms no private keys compromised, describes the exploit as a rangeproof verification cache flaw, announces Elements v23.3.4 emergency release, and states restoration goal of 1:1 BTC backing.
Liquid Network official incident report (X/@Liquid_BTC)10 September 2026
Liquid Network resumed block production, initially without transactions, following patching of all functionary and bridge nodes.
Crypto Briefing11 September 2026
Blockstream issued a public statement rejecting the white-hat characterization, refusing to pay the attacker's demanded bounty, characterizing the retained 598.5 BTC as theft, and announcing engagement of law enforcement and blockchain forensic specialists.
Blockonomi / The Record (Recorded Future News)Decision Log
- hash: 3WxgEuF5WmzZqEw79Y5ty3hxeRnMBTrQ9cB465ZeAife
This investigation is cryptographically anchored to the Solana blockchain (1 event). 0 of 17 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/11/2026, 5:41:48 PM
last updated: 9/11/2026, 5:42:00 PM
avoid.net — verified advice for a post-truth world