Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#1
Score
Cluster
mainnet-beta
Slot
446482750
Off-chain at
2026-09-12T17:09:22.465Z
Anchored at
Block time

Independent verification

1. Database (off-chain)
APNC1ZVurX9Zmo8mTyXi9c5MsV4PonRErir24EYCwYHF
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (18931 chars)
{"actor":"system:backfill","investigation_id":"b85b5bf5-6292-4c01-85bd-54529938386a","kind":"publish","page_slug":"liquid-network","published_at":"2026-09-12T17:09:22.296Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Liquid Network","sections":[{"content":"On September 6, 2026, an attacker exploited a software vulnerability in Elements, the open-source codebase underlying the Liquid Network, to mint approximately 3,998.5 to 4,000 L-BTC with no corresponding Bitcoin backing. According to TRM Labs, the unbacked L-BTC was minted at approximately 13:53 UTC, a withdrawal request was submitted through the SideSwap operator at 14:06 UTC, and the federation paid out roughly 4,000 BTC at 14:28 UTC — a total window of roughly 36 minutes from mint to payout. The withdrawal represented approximately 95% of the federation's roughly 4,200 BTC in reserves, reducing holdings to about 197-207 BTC. The federation's 11-of-15 multisig signing keys themselves were not compromised; Blockstream and multiple security researchers attributed the loss to a software bug rather than a key or custody breach. Other assets issued on Liquid, including USDT, DePix, and tokenized real-world assets, were reported unaffected.","heading":"The September 6, 2026 Exploit","severity":"critical","sources":[{"credibility":2,"name":"$320 million bitcoin exploit hits Liquid Network - CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"credibility":2,"name":"2026's Biggest Hack To Date - TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"credibility":2,"name":"Liquid Network pauses after purported 'white-hat' hackers withdraw $320 million in bitcoin - The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-09-06-liquid-network-pauses-after-purported-white-hat-hackers-withdraw-320-million-in-bitcoin-413626"}]},{"content":"Security firm SlowMist and other researchers traced the exploit to a cache key collision in Elements' range-proof verification logic. Elements caches the results of range-proof verification (used to authenticate confidential transaction amounts) for performance reasons. Prior to the version that fixed the flaw, cache keys were generated without length prefixes, meaning two different verification inputs could produce identical cache keys. This allowed an attacker-supplied invalid proof to be treated as already-verified if its key collided with a legitimate cached entry, letting fabricated L-BTC outputs pass validation. Notably, an earlier partial patch on August 3, 2026 had added fields to the cache-key hash but reportedly did not correctly bound those fields, leaving the underlying collision path exploitable; the complete fix was committed to the public Elements GitHub repository on September 1, 2026, five days before the exploit, with a descriptive commit title. Multiple sources note this sequence — a public, identifiable patch sitting in the repository for five days before any production Liquid node had deployed it — as strongly suggestive that the exploit was reverse-engineered from the published diff, though no source has confirmed the attacker's identity or method with certainty, and this remains an inference by researchers rather than a confirmed fact.","heading":"Technical root cause: cache key collision in Elements","severity":"critical","sources":[{"credibility":2,"name":"SlowMist details Liquid Network exploit, attacker mints 3,998 L-BTC in largest Bitcoin sidechain hack of 2026 - CryptoBriefing","type":"research","url":"https://cryptobriefing.com/liquid-network-exploit-slowmist-analysis/"},{"credibility":2,"name":"Analysis of the Liquid Network Cache Key Collision Vulnerability - SlowMist (Medium)","type":"research","url":"https://slowmist.medium.com/analysis-of-the-liquid-network-cache-key-collision-vulnerability-nearly-4-000-l-btc-minted-out-of-e2010c446971"},{"credibility":2,"name":"SlowMist Exposes Liquid Network Flaw: How a Cache Collision Minted 3,998 Unbacked L-BTC - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/11/slowmist-exposes-liquid-network-flaw-how-a-cache-collision-minted-3998-unbacked-l-btc/"}]},{"content":"The unbacked L-BTC was redeemed for real Bitcoin through SideSwap, an authorized third-party peg-out platform integrated with Liquid Network; SideSwap and the federation were reportedly unable to distinguish the fraudulently minted L-BTC from legitimate tokens, so the redemption was processed as a normal transaction. Liquid Network's operators disabled bridge nodes and paused block production starting September 6, 2026, instructing exchanges to suspend L-BTC deposits and withdrawals. Block production and SideSwap trading resumed on September 10, 2026, but federation peg-outs (the mechanism to redeem L-BTC for on-chain Bitcoin) remained suspended pending further security review, meaning the sidechain was effectively non-functional for withdrawals for an extended period. This left exchanges and institutional users that rely on Liquid for settlement unable to move funds for days.","heading":"Role of SideSwap and network-wide shutdown","severity":"high","sources":[{"credibility":2,"name":"L-BTC resumes trading with reserves covering just 85% of supply - CryptoSlate","type":"news_article","url":"https://cryptoslate.com/l-btc-resumes-trading-with-reserves-covering-just-85-of-supply/"},{"credibility":2,"name":"Liquid Network pauses after purported 'white-hat' hackers withdraw $320 million in bitcoin - The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-09-06-liquid-network-pauses-after-purported-white-hat-hackers-withdraw-320-million-in-bitcoin-413626"},{"credibility":1,"name":"A $320 Million Hack Exposes the Cracks in Crypto's Plumbing - Claims Journal","type":"news_article","url":"https://www.claimsjournal.com/news/national/2026/09/08/340016.htm"}]},{"content":"The attacker(s) communicated with Blockstream via on-chain OP_RETURN messages, declaring \"we are whitehats. contact us on chain\" and stating they would return the funds once the underlying bug was patched. On September 7, 2026, the attacker returned approximately 3,400 BTC (about 85% of the amount taken, roughly $268-272 million) to the Liquid federation wallet, but retained approximately 598.5 BTC (about $47 million) as a self-declared bug-bounty payment. On or around September 10, 2026, the attacker demanded via an on-chain message that Blockstream formally pay 10% of recovered funds as a bounty, reportedly threatening that refusal would \"cause all your holders a 15% loss.\" Blockstream publicly refused on September 11, 2026, stating \"Taking assets without authorization and withholding their return is a crime, not responsible disclosure,\" and that it would \"not be a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom that far exceeds their economic participation.\" Blockstream said it would work with law enforcement and forensic firms to trace the remaining funds. Some industry figures, including reporting that cites Ledger's CTO, have publicly rejected the attacker's white-hat framing, comparing the retained funds to outright theft seen in incidents like the Ronin Bridge hack; this characterization dispute is unresolved and both framings should be treated as alleged rather than established fact.","heading":"Partial return of funds and disputed 'white-hat' claim","severity":"critical","sources":[{"credibility":2,"name":"'Return the bitcoin': Blockstream refuses ransom demand for remaining 600 BTC from Liquid exploit - The Block","type":"news_article","url":"https://www.theblock.co/news/ecosystems/2026-09-11-return-the-bitcoin-blockstream-refuses-ransom-demand-for-remaining-600-btc-from-liquid-exploit-414247"},{"credibility":2,"name":"Liquid Network hack: Whitehats return 3,400 BTC - CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/08/white-hat-hackers-return-most-of-usd320m-bitcoin-taken-from-liquid-network"},{"credibility":2,"name":"Hackers Drain $320 Million From Bitcoin's Liquid Network, Keep $47 Million for Themselves in 'White Hat' Operation - Gizmodo","type":"news_article","url":"https://gizmodo.com/hackers-drain-320-million-from-bitcoins-liquid-network-keep-47-million-for-themselves-in-white-hat-operation-2000808262"}]},{"content":"As of September 10, 2026 at 22:55 UTC, on-chain data cited by CryptoSlate showed approximately 4,229 L-BTC in circulation backed by only about 3,601 BTC in reserve — roughly 85.15% collateralization, a shortfall of about 628 BTC-equivalent. Blockstream CEO Adam Back publicly stated the L-BTC-to-BTC peg would receive \"one-for-one coverage,\" but as of the most recent reporting no specific method or timeline for fully restoring the reserve had been disclosed, and SideSwap said it lacked insight into how or when restoration would occur. Federation peg-outs remained suspended during the security review, meaning L-BTC holders could not redeem for on-chain Bitcoin even after trading nominally resumed, so market pricing during this period reflected speculative confidence in an eventual fix rather than a guaranteed redemption right.","heading":"Ongoing reserve shortfall and network status","severity":"high","sources":[{"credibility":2,"name":"L-BTC resumes trading with reserves covering just 85% of supply - CryptoSlate","type":"news_article","url":"https://cryptoslate.com/l-btc-resumes-trading-with-reserves-covering-just-85-of-supply/"},{"credibility":2,"name":"Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"}]},{"content":"Liquid Network is a Bitcoin sidechain launched by Blockstream in 2018, designed to allow faster, confidential settlement of Bitcoin and tokenized assets among exchanges, market makers, and institutions. It is secured by a federation — reported as 80-plus exchanges, infrastructure firms, and asset managers signing an 11-of-15 multisig — that locks Bitcoin on the mainchain and issues a 1:1-pegged representation, L-BTC, on the sidechain. This federated custody model is a known structural trust assumption distinct from Bitcoin's base-layer proof-of-work security, and the September 2026 incident is described by multiple outlets as the largest security breach involving a Bitcoin sidechain to date, occurring at the software-validation layer rather than through compromise of the federation's signing keys.","heading":"Background on Liquid Network and Blockstream","severity":"medium","sources":[{"credibility":2,"name":"2026's Biggest Hack To Date - TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"credibility":2,"name":"$320 million bitcoin exploit hits Liquid Network - CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"}]}],"sources_used":[{"credibility":2,"name":"$320 million bitcoin exploit hits Liquid Network - CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"credibility":2,"name":"Liquid Network hack: Whitehats return 3,400 BTC - CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/08/white-hat-hackers-return-most-of-usd320m-bitcoin-taken-from-liquid-network"},{"credibility":2,"name":"2026's Biggest Hack To Date - TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"credibility":2,"name":"SlowMist details Liquid Network exploit, attacker mints 3,998 L-BTC in largest Bitcoin sidechain hack of 2026 - CryptoBriefing","type":"research","url":"https://cryptobriefing.com/liquid-network-exploit-slowmist-analysis/"},{"credibility":2,"name":"Analysis of the Liquid Network Cache Key Collision Vulnerability - SlowMist (Medium)","type":"research","url":"https://slowmist.medium.com/analysis-of-the-liquid-network-cache-key-collision-vulnerability-nearly-4-000-l-btc-minted-out-of-e2010c446971"},{"credibility":2,"name":"SlowMist Exposes Liquid Network Flaw: How a Cache Collision Minted 3,998 Unbacked L-BTC - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/11/slowmist-exposes-liquid-network-flaw-how-a-cache-collision-minted-3998-unbacked-l-btc/"},{"credibility":2,"name":"Liquid Network pauses after purported 'white-hat' hackers withdraw $320 million in bitcoin - The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-09-06-liquid-network-pauses-after-purported-white-hat-hackers-withdraw-320-million-in-bitcoin-413626"},{"credibility":2,"name":"'Return the bitcoin': Blockstream refuses ransom demand for remaining 600 BTC from Liquid exploit - The Block","type":"news_article","url":"https://www.theblock.co/news/ecosystems/2026-09-11-return-the-bitcoin-blockstream-refuses-ransom-demand-for-remaining-600-btc-from-liquid-exploit-414247"},{"credibility":2,"name":"L-BTC resumes trading with reserves covering just 85% of supply - CryptoSlate","type":"news_article","url":"https://cryptoslate.com/l-btc-resumes-trading-with-reserves-covering-just-85-of-supply/"},{"credibility":2,"name":"Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"credibility":1,"name":"A $320 Million Hack Exposes the Cracks in Crypto's Plumbing - Claims Journal","type":"news_article","url":"https://www.claimsjournal.com/news/national/2026/09/08/340016.htm"},{"credibility":2,"name":"Hackers Drain $320 Million From Bitcoin's Liquid Network, Keep $47 Million for Themselves in 'White Hat' Operation - Gizmodo","type":"news_article","url":"https://gizmodo.com/hackers-drain-320-million-from-bitcoins-liquid-network-keep-47-million-for-themselves-in-white-hat-operation-2000808262"},{"credibility":1,"name":"Bitcoin Hack Drains $320 Million From Crypto Network - Bloomberg","type":"news_article","url":"https://www.bloomberg.com/news/articles/2026-09-07/bitcoin-network-says-320-million-stolen-in-latest-crypto-hack"}],"summary":"Liquid Network is a Bitcoin sidechain developed and operated by Blockstream, secured by a federation of exchanges and institutions. On September 6, 2026, an attacker exploited a cache key collision bug in the Elements codebase to mint approximately 4,000 unbacked L-BTC and redeem them for real Bitcoin via the SideSwap peg-out platform, draining roughly 95% of the Liquid Federation's reserves (about $320 million) in under 40 minutes. The attacker, claiming to be a white-hat, returned about 3,400 BTC after Blockstream patched the bug but retained roughly 598.5 BTC (~$47 million) as a self-declared bounty that Blockstream has publicly refused to honor, leaving the network's reserves under-collateralized and exchanges facing an extended service disruption.","timeline":[{"date":"2018","event":"Blockstream launches the Liquid Network, a federated Bitcoin sidechain for exchanges and institutions.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"date":"2026-08","date_original":"2026-08-03","event":"An earlier, incomplete patch to the Elements cache-key hashing logic is applied, but reportedly does not fully close the boundary condition later exploited.","source":"CryptoBriefing (SlowMist analysis)","source_url":"https://cryptobriefing.com/liquid-network-exploit-slowmist-analysis/"},{"date":"2026-09","date_original":"2026-09-01","event":"The complete fix for the cache key collision bug is publicly committed to the Elements GitHub repository with a descriptive commit title, five days before it is exploited in production.","source":"Scout research summary citing Elements GitHub repository","source_url":"https://cryptobriefing.com/liquid-network-exploit-slowmist-analysis/"},{"date":"2026-09-06","date_evidence":"Liquid Network pauses after purported 'white-hat' hackers withdraw $320 million in bitcoin (article dated 2026-09-06)","event":"Attacker mints roughly 4,000 unbacked L-BTC (~13:53 UTC) and redeems them for real Bitcoin via SideSwap (payout ~14:28 UTC), draining about 95% of the Liquid Federation's reserves (~$320 million); Blockstream halts block production and instructs exchanges to suspend L-BTC deposits/withdrawals.","source":"The Block","source_url":"https://www.theblock.co/news/defi/2026-09-06-liquid-network-pauses-after-purported-white-hat-hackers-withdraw-320-million-in-bitcoin-413626"},{"date":"2026-09-07","date_evidence":"White-hat hackers return most of $320M bitcoin taken from Liquid Network (article dated 2026-09-08 reporting the return occurred September 7)","event":"Attacker returns approximately 3,400 BTC (~85% of stolen funds) to the Liquid federation wallet after Blockstream patches the vulnerability, retaining roughly 598.5 BTC (~$47 million).","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2026/09/08/white-hat-hackers-return-most-of-usd320m-bitcoin-taken-from-liquid-network"},{"date":"2026-09","date_original":"2026-09-10","event":"Liquid Network resumes block production and SideSwap reopens trading; federation peg-outs remain suspended, and on-chain reserves cover only about 85% of outstanding L-BTC supply.","source":"CryptoSlate","source_url":"https://cryptoslate.com/l-btc-resumes-trading-with-reserves-covering-just-85-of-supply/"},{"date":"2026-09-11","date_evidence":"'Return the bitcoin': Blockstream refuses ransom demand for remaining 600 BTC from Liquid exploit (article dated 2026-09-11, Friday)","event":"Blockstream publicly refuses the attacker's demand for a 10% bounty on recovered funds, calling it extortion and vowing to pursue the remaining ~598.5 BTC with law enforcement and forensic firms.","source":"The Block","source_url":"https://www.theblock.co/news/ecosystems/2026-09-11-return-the-bitcoin-blockstream-refuses-ransom-demand-for-remaining-600-btc-from-liquid-exploit-414247"}]},"v":1}