← Liquid Network / Elements Cache-Bug Exploit (September 2026)1 decision on this page
Audit log
Every state-changing event for Liquid Network / Elements Cache-Bug Exploit (September 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-11 17:42:00ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 446,216,376
- sig
5sh8WPhvxDMd…gwzR4eAoexplorer ↗- hash
3WxgEuF5WmzZ…65ZeAifesha256 → base58
verifying row…full verify ↗canonical bytes (23786 B) ▸
{"actor":"system:backfill","investigation_id":"196749fe-765a-46f0-ae2c-ff225f75a1c9","kind":"publish","page_slug":"liquid-network-elements-cache-bug-exploit-september-2026","published_at":"2026-09-11T17:42:00.709Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Liquid Network / Elements Cache-Bug Exploit (September 2026)","sections":[{"content":"On September 6, 2026 at approximately 15:53:10 UTC, beginning at Liquid block 4,050,336, an attacker exploited a vulnerability in the open-source Elements software used by the Liquid Network to validate Confidential Transactions. The vulnerability allowed the attacker to create approximately 3,998.5 L-BTC tokens that were not backed by any Bitcoin held in the federation's reserve. The attacker then used SideSwap's peg-out authorization to convert the fraudulent L-BTC into native Bitcoin. The main peg-out of 3,996.02 L-BTC completed at 14:28:56 UTC, and reserve holdings fell from approximately 4,205 BTC to 197 BTC — a reduction of roughly 95%. Blockstream confirmed that no federation private keys were compromised; the exploit was a software-level validation bypass, not a cryptographic key theft. The Liquid Network halted block production and exchanges suspended L-BTC deposits and withdrawals. Other assets on the network, including USDT and tokenized real-world assets, were reportedly unaffected.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"Liquid Network official incident report (X/@Liquid_BTC, September 8, 2026)","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":2,"name":"Liquid Network drained of $320M in cache bug exploit — crypto.news","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"},{"credibility":2,"name":"Liquid Network suffers $320M hack as 4,000 BTC drained from federation wallet — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/liquid-network-320m-hack-bitcoin-sidechain/"},{"credibility":2,"name":"Liquid Network Exploit Drained $316M Via Software Bug, Not Stolen Keys — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/326941/20260908/liquid-network-exploit-drained-316m-via-software-bug-not-stolen-keys.htm"}]},{"content":"Security researchers at CertiK and independent analysts identified the root cause as an ambiguous cache-key encoding in Elements' rangeproof verification logic. Liquid's Confidential Transactions use zero-knowledge range proofs to verify that hidden transaction amounts are valid without revealing the values. The caching layer constructed cache keys by concatenating four fields — rangeproof (P), value commitment (C), asset generator (X), and script (S) — into a single SHA-256 stream without length-encoding the variable-length fields. Because no delimiters separated the fields, distinct input tuples could produce identical byte streams, yielding matching cache keys despite representing different cryptographic inputs. An attacker who primed the cache with a legitimately valid transaction could then submit a second, invalid transaction whose cache key collided with the first; the cache returned a 'verified' result for the second transaction without performing any cryptographic check. CertiK described the attack as a four-stage sequence: cache priming via setup transactions; submission of a malicious inflation transaction that reused the cached validation result; creation of unauthorized L-BTC; and peg-out via SideSwap to convert fraudulent L-BTC to native Bitcoin. On-chain analysis reported by CryptoSlate noted that a fix for the bug had been merged to the Elements development branch on approximately September 1–3, 2026, but had not been included in any tagged release, meaning every production federation node was still running vulnerable code at the time of the exploit.","heading":"Technical Root Cause: Elements Rangeproof Cache-Key Collision","severity":"critical","sources":[{"credibility":2,"name":"Liquid Network Incident Analysis — CertiK","type":"research","url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"credibility":2,"name":"Tokens created out of thin air may explain how $320 million in Bitcoin left the Liquid sidechain — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/tokens-created-out-of-thin-air-may-explain-how-320-million-in-bitcoin-left-a-sidechain/"},{"credibility":3,"name":"Liquid Network Hack Explained: Inside the $320M Attack Path No Scan Would Have Caught — CodeAnt","type":"research","url":"https://codeant.ai/blogs/liquid-network-hack-attack-path-validation"}]},{"content":"Following the exploit, the attacker embedded messages in Bitcoin OP_RETURN fields identifying themselves as 'whitehats' and inviting Blockstream to contact them on-chain. Messages included 'we are whitehats. contact us on chain' and 'Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched.' On September 7, 2026, the attacker returned 3,400 BTC (approximately $265–268 million at prevailing prices) to the Liquid Federation wallet at approximately 16:09–18:09 UTC. The attacker retained 598.5 BTC — approximately 15% of the total withdrawn — and according to reporting by Blockonomi and Recorded Future News, demanded a 10% bounty from Blockstream's corporate treasury, threatening to impose a permanent 15% loss on Liquid users if demands were refused. No formal bug bounty agreement existed between the attacker and Blockstream before the exploit. Charles Guillemet, CTO of Ledger, was quoted as disputing the white-hat characterization and suggesting the conduct resembled extortion. The Recorded Future/The Record article noted blockchain-embedded PGP-encrypted content requiring Blockstream to respond before full fund return.","heading":"Attacker Communications and Alleged White-Hat Claims","severity":"high","sources":[{"credibility":2,"name":"'White hat' hackers take $47 million bounty after $320 million crypto theft — The Record (Recorded Future News)","type":"news_article","url":"https://therecord.media/liquid-network-blockstream-crypto-theft-hackers-keep-reward"},{"credibility":2,"name":"Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html"},{"credibility":2,"name":"Blockstream Takes Hard Stance Against Liquid Network Hackers Demanding Ransom for 598 BTC — Blockonomi","type":"news_article","url":"https://blockonomi.com/blockstream-takes-hard-stance-against-liquid-network-hackers-demanding-ransom-for-598-btc"},{"credibility":1,"name":"$320 million bitcoin exploit hits Liquid Network — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"}]},{"content":"On September 11, 2026, Blockstream issued a public statement explicitly rejecting the attacker's white-hat characterization. The company stated: 'Unauthorized asset seizure and conditional withholding constitutes criminal activity, not responsible disclosure.' Blockstream declared it would 'not pay a ransom for the return of stolen funds' and characterized the 598.5 BTC still held by the attacker as theft. The company announced it would engage law enforcement, cryptocurrency exchanges, financial service providers, and blockchain forensic specialists to trace and recover the outstanding assets. As of September 11, 2026, the 598.5 BTC remains in an address controlled by the attacker and no court proceedings or law enforcement charges had been publicly announced. This page will be updated as the legal and recovery status develops.","heading":"Blockstream's September 11 Response and Legal Posture","severity":"high","sources":[{"credibility":2,"name":"Blockstream Takes Hard Stance Against Liquid Network Hackers Demanding Ransom for 598 BTC — Blockonomi","type":"news_article","url":"https://blockonomi.com/blockstream-takes-hard-stance-against-liquid-network-hackers-demanding-ransom-for-598-btc"},{"credibility":2,"name":"'White hat' hackers take $47 million bounty after $320 million crypto theft — The Record (Recorded Future News)","type":"news_article","url":"https://therecord.media/liquid-network-blockstream-crypto-theft-hackers-keep-reward"}]},{"content":"Blockstream deployed a security patch on September 7, 2026 at approximately 01:09 UTC, updating all functionary and bridge nodes to a hardened version of Elements. An emergency release, Elements v23.3.4, was committed within 48 hours of the incident. The patch addressed the cache-key construction flaw by adding proper length delimiters to the field concatenation used to build rangeproof verification cache keys. Block production resumed on September 10, 2026, initially producing blocks without transactions as a precautionary measure while the network was monitored. Peg operations and full transaction functionality remained paused at the time of the Liquid Network's September 8 incident report. Both Halborn and CertiK confirmed that the patched version closes the specific cache-collision vector exploited in this incident. The Liquid Network official report characterized the exploit as resulting from 'several individually low-probability factors' interacting together and stated the goal of resumption was '1:1 backing for BTC.'","heading":"Patch Deployment and Network Restart","severity":"medium","sources":[{"credibility":2,"name":"Liquid Network official incident report (X/@Liquid_BTC, September 8, 2026)","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":2,"name":"Liquid Network resumes block production after $320M Bitcoin drain — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/liquid-network-resumes-after-320m-exploit/"},{"credibility":2,"name":"Explained: The Liquid Network Hack (September 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-liquid-network-hack-september-2026"}]},{"content":"The Liquid Network is a Bitcoin sidechain operated by a federation of financial institutions and exchanges. As of Q1 2026, the federation comprised 87 member organizations with 15 active signers required to achieve an 11-of-15 multisig threshold for block validation. In this incident, no federation member's private keys were stolen or compromised. The attack operated at the transaction validation layer — the cache-key collision caused Liquid nodes to treat an invalid transaction as already-verified, bypassing the rangeproof check before the transaction ever reached the multisig signing layer. SideSwap, a Liquid Federation member holding a peg-out authorization (PAK) key, processed the peg-out because the malicious L-BTC appeared valid to all nodes running the vulnerable Elements build. Bitcoin's base layer was not affected; the exploit was confined entirely to the Elements sidechain layer. L-BTC deposits and withdrawals were suspended by major exchanges upon detection of the anomaly.","heading":"Federation Architecture and Scope of Compromise","severity":"high","sources":[{"credibility":3,"name":"Liquid Network Hack: $320M Bitcoin Sidechain Exploit [2026] — Shattered.io","type":"research","url":"https://shattered.io/liquid-network-320-million-hack-2026/"},{"credibility":2,"name":"Liquid Network Exploit Drained $316M Via Software Bug, Not Stolen Keys — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/326941/20260908/liquid-network-exploit-drained-316m-via-software-bug-not-stolen-keys.htm"},{"credibility":2,"name":"Tokens created out of thin air may explain how $320 million in Bitcoin left the Liquid sidechain — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/tokens-created-out-of-thin-air-may-explain-how-320-million-in-bitcoin-left-a-sidechain/"}]},{"content":"As of September 11, 2026 — the date of Blockstream's public rejection of the attacker's demands — 598.5 BTC (approximately $47 million at $78,000–$80,000 per BTC) remains in an address controlled by the attacker. No court has adjudicated ownership of these funds. Blockstream has characterized the retained amount as stolen property and announced a law-enforcement-led recovery effort. The attacker has not returned the 598.5 BTC as of the publication of this investigation. Samson Mow, CEO of JAN3 and a former Blockstream executive, was quoted estimating the unreturned amount in media coverage. The status of Blockstream's engagement with law enforcement or blockchain forensic firms has not been publicly detailed as of September 11, 2026.","heading":"Outstanding Funds and Recovery Status","severity":"high","sources":[{"credibility":2,"name":"Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html"},{"credibility":2,"name":"Blockstream Takes Hard Stance Against Liquid Network Hackers Demanding Ransom for 598 BTC — Blockonomi","type":"news_article","url":"https://blockonomi.com/blockstream-takes-hard-stance-against-liquid-network-hackers-demanding-ransom-for-598-btc"},{"credibility":2,"name":"'White hat' hackers take $47 million bounty after $320 million crypto theft — The Record (Recorded Future News)","type":"news_article","url":"https://therecord.media/liquid-network-blockstream-crypto-theft-hackers-keep-reward"}]},{"content":"Multiple security researchers characterized the cache-key collision as a long-standing architectural flaw in the Elements codebase, described in some analyses as originating in the 0.x era of the software. The vulnerability existed in the production codebase for an extended period before the fix was authored. Notably, the fix was reportedly merged to the Elements development branch on approximately September 1–3, 2026 — several days before the exploit — but was not included in any tagged release and was therefore not deployed by federation nodes. This gap between fix authorship and production deployment is a distinct contributing factor to the severity of the incident. CertiK's analysis noted that the class of bug — insufficient input delimitation in cache-key construction for cryptographic verification — is a category that standard automated security scanners would not reliably detect, because it requires understanding the semantic relationship between the caching layer and the underlying cryptographic primitive. The Bitcoin base layer itself has no architectural relationship to the flaw; the vulnerability was specific to the Elements sidechain implementation.","heading":"Broader Context: Elements Software Architecture Risk","severity":"high","sources":[{"credibility":2,"name":"Liquid Network Incident Analysis — CertiK","type":"research","url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"credibility":3,"name":"Liquid Network Hack Explained: Inside the $320M Attack Path No Scan Would Have Caught — CodeAnt","type":"research","url":"https://codeant.ai/blogs/liquid-network-hack-attack-path-validation"},{"credibility":2,"name":"Tokens created out of thin air may explain how $320 million in Bitcoin left the Liquid sidechain — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/tokens-created-out-of-thin-air-may-explain-how-320-million-in-bitcoin-left-a-sidechain/"}]}],"sources_used":[{"credibility":2,"name":"Liquid Network official incident report (X/@Liquid_BTC, September 8, 2026)","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":2,"name":"Liquid Network drained of $320M in cache bug exploit — crypto.news","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"},{"credibility":1,"name":"$320 million bitcoin exploit hits Liquid Network. Hacker makes conditional offer — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"credibility":2,"name":"Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html"},{"credibility":2,"name":"Explained: The Liquid Network Hack (September 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-liquid-network-hack-september-2026"},{"credibility":2,"name":"Liquid Network Incident Analysis — CertiK","type":"research","url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"credibility":1,"name":"Hackers Drain $320 Million From Bitcoin's Liquid Network — Bloomberg","type":"news_article","url":"https://www.bloomberg.com/news/articles/2026-09-07/bitcoin-network-says-320-million-stolen-in-latest-crypto-hack"},{"credibility":2,"name":"'White hat' hackers take $47 million bounty after $320 million crypto theft — The Record (Recorded Future News)","type":"news_article","url":"https://therecord.media/liquid-network-blockstream-crypto-theft-hackers-keep-reward"},{"credibility":2,"name":"Blockstream Takes Hard Stance Against Liquid Network Hackers Demanding Ransom for 598 BTC — Blockonomi","type":"news_article","url":"https://blockonomi.com/blockstream-takes-hard-stance-against-liquid-network-hackers-demanding-ransom-for-598-btc"},{"credibility":2,"name":"Tokens created out of thin air may explain how $320 million in Bitcoin left the Liquid sidechain — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/tokens-created-out-of-thin-air-may-explain-how-320-million-in-bitcoin-left-a-sidechain/"},{"credibility":2,"name":"Liquid Network suffers $320M hack as 4,000 BTC drained from federation wallet — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/liquid-network-320m-hack-bitcoin-sidechain/"},{"credibility":2,"name":"Liquid Network resumes block production after $320M Bitcoin drain — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/liquid-network-resumes-after-320m-exploit/"},{"credibility":2,"name":"Liquid Network Exploit Drained $316M Via Software Bug, Not Stolen Keys — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/326941/20260908/liquid-network-exploit-drained-316m-via-software-bug-not-stolen-keys.htm"},{"credibility":2,"name":"Attackers Drained 4,000 Bitcoin From Blockstream's Liquid Network — 247 Wall St.","type":"news_article","url":"https://247wallst.com/investing/cryptocurrency/2026/09/08/attackers-drained-4000-bitcoin-from-blockstreams-liquid-network-they-say-they-are-white-hats-and-want-to-give-it-back/"},{"credibility":3,"name":"Liquid Network Hack: $320M Bitcoin Sidechain Exploit [2026] — Shattered.io","type":"research","url":"https://shattered.io/liquid-network-320-million-hack-2026/"},{"credibility":2,"name":"Hackers Drain $320 Million From Bitcoin's Liquid Network — Gizmodo","type":"news_article","url":"https://gizmodo.com/hackers-drain-320-million-from-bitcoins-liquid-network-keep-47-million-for-themselves-in-white-hat-operation-2000808262"},{"credibility":3,"name":"Liquid Network Hack Explained: Inside the $320M Attack Path No Scan Would Have Caught — CodeAnt","type":"research","url":"https://codeant.ai/blogs/liquid-network-hack-attack-path-validation"}],"summary":"On September 6, 2026, an unidentified attacker exploited an ambiguous cache-key encoding flaw in the open-source Elements software underpinning Blockstream's Liquid Network sidechain. Approximately 3,998.5 unbacked L-BTC (valued at roughly $320 million) were minted and pegged out for native Bitcoin, draining an estimated 95% of the federation's reserves. The attacker returned 3,400 BTC on September 7 and retained 598.5 BTC (~$47 million), characterizing the retention as a 15% bounty; Blockstream's September 11 public statement rejects this characterization and refuses to treat the incident as a white-hat disclosure, stating the retained funds constitute theft.","timeline":[{"date":"2026-09-01","event":"A fix for the rangeproof cache-key collision bug was reportedly merged to the Elements development branch. No tagged release contained it; production nodes remained on the vulnerable build.","source":"CryptoSlate / on-chain researcher Mononaut","source_url":"https://cryptoslate.com/tokens-created-out-of-thin-air-may-explain-how-320-million-in-bitcoin-left-a-sidechain/"},{"date":"2026-09-06","event":"Between approximately 11:30 and 13:16 UTC, the attacker executed a series of dry-run peg-out transactions on the Liquid Network, testing the exploit mechanism.","source":"CryptoSlate / CertiK","source_url":"https://cryptoslate.com/tokens-created-out-of-thin-air-may-explain-how-320-million-in-bitcoin-left-a-sidechain/"},{"date":"2026-09-06","event":"At 13:52:10 UTC, the attacker broadcast setup (cache-priming) transactions. At 13:53:10 UTC, the malicious inflation transaction was submitted at Liquid block 4,050,336, exploiting the cache-key collision to create approximately 3,998.5 unbacked L-BTC.","source":"CertiK Liquid Network Incident Analysis","source_url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"date":"2026-09-06","event":"At 14:06:10 UTC, the second (main) peg-out of 3,996.02 L-BTC was submitted via SideSwap. At 14:28:56 UTC, the attacker received 3,996.02 BTC on Bitcoin mainnet. Federation reserves fell from approximately 4,205 BTC to 197 BTC — a 95% drain.","source":"CertiK / crypto.news","source_url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"date":"2026-09-07","event":"Blockstream deployed emergency security patch at approximately 01:09 UTC, updating functionary and bridge nodes to a hardened Elements build (emergency release Elements v23.3.4 announced).","source":"Liquid Network official incident report (X/@Liquid_BTC)","source_url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"date":"2026-09-07","event":"The attacker returned 3,400 BTC to the Liquid Federation wallet at approximately 16:09–18:09 UTC, retaining 598.5 BTC. On-chain messages identified the actors as 'whitehats' and demanded a 10% bounty from Blockstream's corporate treasury.","source":"The Hacker News / Blockonomi","source_url":"https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html"},{"date":"2026-09-08","event":"Liquid Network published its official incident report at 19:10 UTC. Report confirms no private keys compromised, describes the exploit as a rangeproof verification cache flaw, announces Elements v23.3.4 emergency release, and states restoration goal of 1:1 BTC backing.","source":"Liquid Network official incident report (X/@Liquid_BTC)","source_url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"date":"2026-09-10","event":"Liquid Network resumed block production, initially without transactions, following patching of all functionary and bridge nodes.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/liquid-network-resumes-after-320m-exploit/"},{"date":"2026-09-11","event":"Blockstream issued a public statement rejecting the white-hat characterization, refusing to pay the attacker's demanded bounty, characterizing the retained 598.5 BTC as theft, and announcing engagement of law enforcement and blockchain forensic specialists.","source":"Blockonomi / The Record (Recorded Future News)","source_url":"https://blockonomi.com/blockstream-takes-hard-stance-against-liquid-network-hackers-demanding-ransom-for-598-btc"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 1f279288-3ff5-4353-a99b-31134a8e7a00
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.