Skip to main content
AVOID.NET
Liquid Network1 decision on this page

Audit log

Every state-changing event for Liquid Network: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-12 17:09:22Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 446,482,750
    sig
    3SgH6icKd5aU…w64wgwg8explorer ↗
    hash
    APNC1ZVurX9Z…4EYCwYHFsha256 → base58
    verifying row…full verify ↗
    canonical bytes (18931 B) ▸
    {"actor":"system:backfill","investigation_id":"b85b5bf5-6292-4c01-85bd-54529938386a","kind":"publish","page_slug":"liquid-network","published_at":"2026-09-12T17:09:22.296Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Liquid Network","sections":[{"content":"On September 6, 2026, an attacker exploited a software vulnerability in Elements, the open-source codebase underlying the Liquid Network, to mint approximately 3,998.5 to 4,000 L-BTC with no corresponding Bitcoin backing. According to TRM Labs, the unbacked L-BTC was minted at approximately 13:53 UTC, a withdrawal request was submitted through the SideSwap operator at 14:06 UTC, and the federation paid out roughly 4,000 BTC at 14:28 UTC — a total window of roughly 36 minutes from mint to payout. The withdrawal represented approximately 95% of the federation's roughly 4,200 BTC in reserves, reducing holdings to about 197-207 BTC. The federation's 11-of-15 multisig signing keys themselves were not compromised; Blockstream and multiple security researchers attributed the loss to a software bug rather than a key or custody breach. Other assets issued on Liquid, including USDT, DePix, and tokenized real-world assets, were reported unaffected.","heading":"The September 6, 2026 Exploit","severity":"critical","sources":[{"credibility":2,"name":"$320 million bitcoin exploit hits Liquid Network - CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"credibility":2,"name":"2026's Biggest Hack To Date - TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"credibility":2,"name":"Liquid Network pauses after purported 'white-hat' hackers withdraw $320 million in bitcoin - The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-09-06-liquid-network-pauses-after-purported-white-hat-hackers-withdraw-320-million-in-bitcoin-413626"}]},{"content":"Security firm SlowMist and other researchers traced the exploit to a cache key collision in Elements' range-proof verification logic. Elements caches the results of range-proof verification (used to authenticate confidential transaction amounts) for performance reasons. Prior to the version that fixed the flaw, cache keys were generated without length prefixes, meaning two different verification inputs could produce identical cache keys. This allowed an attacker-supplied invalid proof to be treated as already-verified if its key collided with a legitimate cached entry, letting fabricated L-BTC outputs pass validation. Notably, an earlier partial patch on August 3, 2026 had added fields to the cache-key hash but reportedly did not correctly bound those fields, leaving the underlying collision path exploitable; the complete fix was committed to the public Elements GitHub repository on September 1, 2026, five days before the exploit, with a descriptive commit title. Multiple sources note this sequence — a public, identifiable patch sitting in the repository for five days before any production Liquid node had deployed it — as strongly suggestive that the exploit was reverse-engineered from the published diff, though no source has confirmed the attacker's identity or method with certainty, and this remains an inference by researchers rather than a confirmed fact.","heading":"Technical root cause: cache key collision in Elements","severity":"critical","sources":[{"credibility":2,"name":"SlowMist details Liquid Network exploit, attacker mints 3,998 L-BTC in largest Bitcoin sidechain hack of 2026 - CryptoBriefing","type":"research","url":"https://cryptobriefing.com/liquid-network-exploit-slowmist-analysis/"},{"credibility":2,"name":"Analysis of the Liquid Network Cache Key Collision Vulnerability - SlowMist (Medium)","type":"research","url":"https://slowmist.medium.com/analysis-of-the-liquid-network-cache-key-collision-vulnerability-nearly-4-000-l-btc-minted-out-of-e2010c446971"},{"credibility":2,"name":"SlowMist Exposes Liquid Network Flaw: How a Cache Collision Minted 3,998 Unbacked L-BTC - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/11/slowmist-exposes-liquid-network-flaw-how-a-cache-collision-minted-3998-unbacked-l-btc/"}]},{"content":"The unbacked L-BTC was redeemed for real Bitcoin through SideSwap, an authorized third-party peg-out platform integrated with Liquid Network; SideSwap and the federation were reportedly unable to distinguish the fraudulently minted L-BTC from legitimate tokens, so the redemption was processed as a normal transaction. Liquid Network's operators disabled bridge nodes and paused block production starting September 6, 2026, instructing exchanges to suspend L-BTC deposits and withdrawals. Block production and SideSwap trading resumed on September 10, 2026, but federation peg-outs (the mechanism to redeem L-BTC for on-chain Bitcoin) remained suspended pending further security review, meaning the sidechain was effectively non-functional for withdrawals for an extended period. This left exchanges and institutional users that rely on Liquid for settlement unable to move funds for days.","heading":"Role of SideSwap and network-wide shutdown","severity":"high","sources":[{"credibility":2,"name":"L-BTC resumes trading with reserves covering just 85% of supply - CryptoSlate","type":"news_article","url":"https://cryptoslate.com/l-btc-resumes-trading-with-reserves-covering-just-85-of-supply/"},{"credibility":2,"name":"Liquid Network pauses after purported 'white-hat' hackers withdraw $320 million in bitcoin - The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-09-06-liquid-network-pauses-after-purported-white-hat-hackers-withdraw-320-million-in-bitcoin-413626"},{"credibility":1,"name":"A $320 Million Hack Exposes the Cracks in Crypto's Plumbing - Claims Journal","type":"news_article","url":"https://www.claimsjournal.com/news/national/2026/09/08/340016.htm"}]},{"content":"The attacker(s) communicated with Blockstream via on-chain OP_RETURN messages, declaring \"we are whitehats. contact us on chain\" and stating they would return the funds once the underlying bug was patched. On September 7, 2026, the attacker returned approximately 3,400 BTC (about 85% of the amount taken, roughly $268-272 million) to the Liquid federation wallet, but retained approximately 598.5 BTC (about $47 million) as a self-declared bug-bounty payment. On or around September 10, 2026, the attacker demanded via an on-chain message that Blockstream formally pay 10% of recovered funds as a bounty, reportedly threatening that refusal would \"cause all your holders a 15% loss.\" Blockstream publicly refused on September 11, 2026, stating \"Taking assets without authorization and withholding their return is a crime, not responsible disclosure,\" and that it would \"not be a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom that far exceeds their economic participation.\" Blockstream said it would work with law enforcement and forensic firms to trace the remaining funds. Some industry figures, including reporting that cites Ledger's CTO, have publicly rejected the attacker's white-hat framing, comparing the retained funds to outright theft seen in incidents like the Ronin Bridge hack; this characterization dispute is unresolved and both framings should be treated as alleged rather than established fact.","heading":"Partial return of funds and disputed 'white-hat' claim","severity":"critical","sources":[{"credibility":2,"name":"'Return the bitcoin': Blockstream refuses ransom demand for remaining 600 BTC from Liquid exploit - The Block","type":"news_article","url":"https://www.theblock.co/news/ecosystems/2026-09-11-return-the-bitcoin-blockstream-refuses-ransom-demand-for-remaining-600-btc-from-liquid-exploit-414247"},{"credibility":2,"name":"Liquid Network hack: Whitehats return 3,400 BTC - CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/08/white-hat-hackers-return-most-of-usd320m-bitcoin-taken-from-liquid-network"},{"credibility":2,"name":"Hackers Drain $320 Million From Bitcoin's Liquid Network, Keep $47 Million for Themselves in 'White Hat' Operation - Gizmodo","type":"news_article","url":"https://gizmodo.com/hackers-drain-320-million-from-bitcoins-liquid-network-keep-47-million-for-themselves-in-white-hat-operation-2000808262"}]},{"content":"As of September 10, 2026 at 22:55 UTC, on-chain data cited by CryptoSlate showed approximately 4,229 L-BTC in circulation backed by only about 3,601 BTC in reserve — roughly 85.15% collateralization, a shortfall of about 628 BTC-equivalent. Blockstream CEO Adam Back publicly stated the L-BTC-to-BTC peg would receive \"one-for-one coverage,\" but as of the most recent reporting no specific method or timeline for fully restoring the reserve had been disclosed, and SideSwap said it lacked insight into how or when restoration would occur. Federation peg-outs remained suspended during the security review, meaning L-BTC holders could not redeem for on-chain Bitcoin even after trading nominally resumed, so market pricing during this period reflected speculative confidence in an eventual fix rather than a guaranteed redemption right.","heading":"Ongoing reserve shortfall and network status","severity":"high","sources":[{"credibility":2,"name":"L-BTC resumes trading with reserves covering just 85% of supply - CryptoSlate","type":"news_article","url":"https://cryptoslate.com/l-btc-resumes-trading-with-reserves-covering-just-85-of-supply/"},{"credibility":2,"name":"Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"}]},{"content":"Liquid Network is a Bitcoin sidechain launched by Blockstream in 2018, designed to allow faster, confidential settlement of Bitcoin and tokenized assets among exchanges, market makers, and institutions. It is secured by a federation — reported as 80-plus exchanges, infrastructure firms, and asset managers signing an 11-of-15 multisig — that locks Bitcoin on the mainchain and issues a 1:1-pegged representation, L-BTC, on the sidechain. This federated custody model is a known structural trust assumption distinct from Bitcoin's base-layer proof-of-work security, and the September 2026 incident is described by multiple outlets as the largest security breach involving a Bitcoin sidechain to date, occurring at the software-validation layer rather than through compromise of the federation's signing keys.","heading":"Background on Liquid Network and Blockstream","severity":"medium","sources":[{"credibility":2,"name":"2026's Biggest Hack To Date - TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"credibility":2,"name":"$320 million bitcoin exploit hits Liquid Network - CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"}]}],"sources_used":[{"credibility":2,"name":"$320 million bitcoin exploit hits Liquid Network - CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"credibility":2,"name":"Liquid Network hack: Whitehats return 3,400 BTC - CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/08/white-hat-hackers-return-most-of-usd320m-bitcoin-taken-from-liquid-network"},{"credibility":2,"name":"2026's Biggest Hack To Date - TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"credibility":2,"name":"SlowMist details Liquid Network exploit, attacker mints 3,998 L-BTC in largest Bitcoin sidechain hack of 2026 - CryptoBriefing","type":"research","url":"https://cryptobriefing.com/liquid-network-exploit-slowmist-analysis/"},{"credibility":2,"name":"Analysis of the Liquid Network Cache Key Collision Vulnerability - SlowMist (Medium)","type":"research","url":"https://slowmist.medium.com/analysis-of-the-liquid-network-cache-key-collision-vulnerability-nearly-4-000-l-btc-minted-out-of-e2010c446971"},{"credibility":2,"name":"SlowMist Exposes Liquid Network Flaw: How a Cache Collision Minted 3,998 Unbacked L-BTC - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/11/slowmist-exposes-liquid-network-flaw-how-a-cache-collision-minted-3998-unbacked-l-btc/"},{"credibility":2,"name":"Liquid Network pauses after purported 'white-hat' hackers withdraw $320 million in bitcoin - The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-09-06-liquid-network-pauses-after-purported-white-hat-hackers-withdraw-320-million-in-bitcoin-413626"},{"credibility":2,"name":"'Return the bitcoin': Blockstream refuses ransom demand for remaining 600 BTC from Liquid exploit - The Block","type":"news_article","url":"https://www.theblock.co/news/ecosystems/2026-09-11-return-the-bitcoin-blockstream-refuses-ransom-demand-for-remaining-600-btc-from-liquid-exploit-414247"},{"credibility":2,"name":"L-BTC resumes trading with reserves covering just 85% of supply - CryptoSlate","type":"news_article","url":"https://cryptoslate.com/l-btc-resumes-trading-with-reserves-covering-just-85-of-supply/"},{"credibility":2,"name":"Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"credibility":1,"name":"A $320 Million Hack Exposes the Cracks in Crypto's Plumbing - Claims Journal","type":"news_article","url":"https://www.claimsjournal.com/news/national/2026/09/08/340016.htm"},{"credibility":2,"name":"Hackers Drain $320 Million From Bitcoin's Liquid Network, Keep $47 Million for Themselves in 'White Hat' Operation - Gizmodo","type":"news_article","url":"https://gizmodo.com/hackers-drain-320-million-from-bitcoins-liquid-network-keep-47-million-for-themselves-in-white-hat-operation-2000808262"},{"credibility":1,"name":"Bitcoin Hack Drains $320 Million From Crypto Network - Bloomberg","type":"news_article","url":"https://www.bloomberg.com/news/articles/2026-09-07/bitcoin-network-says-320-million-stolen-in-latest-crypto-hack"}],"summary":"Liquid Network is a Bitcoin sidechain developed and operated by Blockstream, secured by a federation of exchanges and institutions. On September 6, 2026, an attacker exploited a cache key collision bug in the Elements codebase to mint approximately 4,000 unbacked L-BTC and redeem them for real Bitcoin via the SideSwap peg-out platform, draining roughly 95% of the Liquid Federation's reserves (about $320 million) in under 40 minutes. The attacker, claiming to be a white-hat, returned about 3,400 BTC after Blockstream patched the bug but retained roughly 598.5 BTC (~$47 million) as a self-declared bounty that Blockstream has publicly refused to honor, leaving the network's reserves under-collateralized and exchanges facing an extended service disruption.","timeline":[{"date":"2018","event":"Blockstream launches the Liquid Network, a federated Bitcoin sidechain for exchanges and institutions.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"date":"2026-08","date_original":"2026-08-03","event":"An earlier, incomplete patch to the Elements cache-key hashing logic is applied, but reportedly does not fully close the boundary condition later exploited.","source":"CryptoBriefing (SlowMist analysis)","source_url":"https://cryptobriefing.com/liquid-network-exploit-slowmist-analysis/"},{"date":"2026-09","date_original":"2026-09-01","event":"The complete fix for the cache key collision bug is publicly committed to the Elements GitHub repository with a descriptive commit title, five days before it is exploited in production.","source":"Scout research summary citing Elements GitHub repository","source_url":"https://cryptobriefing.com/liquid-network-exploit-slowmist-analysis/"},{"date":"2026-09-06","date_evidence":"Liquid Network pauses after purported 'white-hat' hackers withdraw $320 million in bitcoin (article dated 2026-09-06)","event":"Attacker mints roughly 4,000 unbacked L-BTC (~13:53 UTC) and redeems them for real Bitcoin via SideSwap (payout ~14:28 UTC), draining about 95% of the Liquid Federation's reserves (~$320 million); Blockstream halts block production and instructs exchanges to suspend L-BTC deposits/withdrawals.","source":"The Block","source_url":"https://www.theblock.co/news/defi/2026-09-06-liquid-network-pauses-after-purported-white-hat-hackers-withdraw-320-million-in-bitcoin-413626"},{"date":"2026-09-07","date_evidence":"White-hat hackers return most of $320M bitcoin taken from Liquid Network (article dated 2026-09-08 reporting the return occurred September 7)","event":"Attacker returns approximately 3,400 BTC (~85% of stolen funds) to the Liquid federation wallet after Blockstream patches the vulnerability, retaining roughly 598.5 BTC (~$47 million).","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2026/09/08/white-hat-hackers-return-most-of-usd320m-bitcoin-taken-from-liquid-network"},{"date":"2026-09","date_original":"2026-09-10","event":"Liquid Network resumes block production and SideSwap reopens trading; federation peg-outs remain suspended, and on-chain reserves cover only about 85% of outstanding L-BTC supply.","source":"CryptoSlate","source_url":"https://cryptoslate.com/l-btc-resumes-trading-with-reserves-covering-just-85-of-supply/"},{"date":"2026-09-11","date_evidence":"'Return the bitcoin': Blockstream refuses ransom demand for remaining 600 BTC from Liquid exploit (article dated 2026-09-11, Friday)","event":"Blockstream publicly refuses the attacker's demand for a 10% bounty on recovered funds, calling it extortion and vowing to pursue the remaining ~598.5 BTC with law enforcement and forensic firms.","source":"The Block","source_url":"https://www.theblock.co/news/ecosystems/2026-09-11-return-the-bitcoin-blockstream-refuses-ransom-demand-for-remaining-600-btc-from-liquid-exploit-414247"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision f9a22680-aa05-40e5-a95f-9c8624829d96
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.