Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
publish · Blockstream Liquid Network
- Sequence
- #1
- Score
- →
- Cluster
- mainnet-beta
- Slot
- 446154672
- Off-chain at
- 2026-09-11T12:14:54.990Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 8wX1s29NSXoR5ZGF35DTUWTp6F4LbCR2QHc6MtxRzU65
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (23333 chars)
{"actor":"system:backfill","investigation_id":"e243a495-2650-427a-956f-83a77b98fccd","kind":"publish","page_slug":"blockstream-liquid-network","published_at":"2026-09-11T12:14:54.678Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Blockstream Liquid Network","sections":[{"content":"The Liquid Network is a Bitcoin sidechain launched by Blockstream that enables faster, lower-fee, and confidential Bitcoin transfers between member exchanges, brokers, and financial institutions. The network uses a federated custody model in which a set of functionary nodes — operated by Liquid member organizations — collectively manage the reserve of Bitcoin backing the L-BTC token on a 1:1 basis. Confidential Transactions, a cryptographic feature inherited from the Elements codebase, allow transaction amounts to be hidden while still being verifiable via range proofs. As of September 2026, the federation held approximately 4,205 BTC in reserve. The network had operated since 2018 without a prior reserve-level security incident.","heading":"Overview and Background","severity":"low","sources":[{"credibility":2,"name":"Liquid Network Incident Report — @Liquid_BTC on X (September 8, 2026)","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"}]},{"content":"On September 6, 2026 at approximately 13:52 UTC, attackers began executing a sequence of transactions against the Liquid Network. At 13:53:10 UTC (Liquid block 4,050,336), they triggered the core inflation transaction, minting approximately 3,998.5 unbacked L-BTC using a cache-key collision vulnerability in the rangeproof verification logic of the Elements software. The attack exploited the fact that the cache key for rangeproof verification concatenated variable-length fields (P, C, X, S) without length encoding, allowing two distinct validation inputs to produce the same cached entry. An attacker who first primed the cache with a valid transaction could subsequently submit a malformed transaction that reused the cached verification result, effectively bypassing the cryptographic check and creating L-BTC without a corresponding Bitcoin deposit. At 14:06 UTC, the attacker submitted a peg-out request through SideSwap, a Liquid federation member holding a Peg-out Authorization Key (PAK). Because the validation failure occurred at the transaction level before the peg-out was initiated, both SideSwap's node and the globally distributed functionary nodes accepted the unbacked L-BTC as valid. At 14:28:56 UTC, the attacker received approximately 3,996 BTC sent to the address bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte. The total attack duration from mint to completion was approximately 36 minutes. The federation reserve fell from approximately 4,205 BTC to roughly 197–202 BTC — a depletion of approximately 95%. Blockstream confirmed that no federation signing keys were compromised; the exploit operated entirely through a software validation error.","heading":"The September 6–7, 2026 Exploit","severity":"critical","sources":[{"credibility":2,"name":"Liquid Network Incident Report — @Liquid_BTC on X (September 8, 2026)","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":2,"name":"CertiK: Liquid Network Incident Analysis","type":"research","url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"credibility":2,"name":"TRM Labs: 2026's Biggest Hack to Date — Liquid Network","type":"research","url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"credibility":2,"name":"crypto.news: Liquid Network drained of $320M in cache bug exploit","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"}]},{"content":"The vulnerability was located in the open-source Elements codebase, which underlies both the Liquid Network and several other Bitcoin sidechains. Specifically, the flaw was in the rangeproof verification cache used by Confidential Transactions. The cache key was constructed by concatenating multiple variable-length byte fields without delimiter or length encoding, which meant that distinct inputs could hash to the same cache entry — a classic cache-collision or type-confusion vulnerability. An attacker who crafted setup transactions to prime the cache could subsequently submit a malicious inflation transaction that reused a valid cached verification result for an invalid output, bypassing the cryptographic range proof check entirely. Security researchers noted that the fix for this bug had been committed to the Elements repository on or around August 3, 2026, and was merged to the main branch on September 2, 2026 — four days before the exploit. However, federation nodes were running Elements v23.3.3, released on April 13, 2026, which predated the fix. Blockstream released Elements v23.3.4 as an emergency patch on September 9, 2026, addressing the cache-key encoding flaw.","heading":"Root Cause: Elements Software Cache Vulnerability","severity":"critical","sources":[{"credibility":2,"name":"CertiK: Liquid Network Incident Analysis","type":"research","url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"credibility":2,"name":"Liquid Network Incident Report — @Liquid_BTC on X (September 8, 2026)","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":2,"name":"crypto.news: Liquid Network drained of $320M in cache bug exploit","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"}]},{"content":"After draining the reserve, the attackers embedded messages in Bitcoin transactions via OP_RETURN outputs, stating 'we are whitehats. contact us on chain.' They negotiated publicly over the blockchain, initially offering to return funds. On September 7, 2026 at approximately 16:09:25 UTC, the attackers returned 3,400 BTC to the Liquid Federation peg wallet, retaining approximately 598.5 BTC — roughly 15% of the total — which they characterized as a self-declared security bounty. The attackers subsequently demanded that Blockstream pay a 10% bounty from corporate reserves, threatening that refusal would result in Liquid users absorbing a permanent 15% loss. Security researchers and commentators debated whether draining $320 million before making contact qualifies as responsible disclosure or constitutes extortion; Gizmodo and Blockonomi reported that experts broadly viewed the unilateral asset seizure as inconsistent with recognized white-hat practices. Blockstream publicly rejected the bounty demand, stating: 'We will not pay a ransom for the return of stolen funds. Taking assets without authorization and withholding their return is a crime, not responsible disclosure.' The company stated it had engaged in good faith with the actors but that those communications did not constitute acceptance of the withdrawal or the terms demanded. As of September 10, 2026, approximately 598.5 BTC (~$47M) remained outstanding. TRM Labs confirmed it had labeled the attacker addresses and was continuing to track the retained funds. Blockstream stated it was cooperating with law enforcement, exchanges, and forensic specialists to recover the remaining Bitcoin through legal channels.","heading":"Attacker Communications and Partial Fund Return","severity":"high","sources":[{"credibility":2,"name":"TRM Labs: 2026's Biggest Hack to Date — Liquid Network","type":"research","url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"credibility":2,"name":"crypto.news: Blockstream says it will not pay ransom for stolen Liquid Bitcoin","type":"news_article","url":"https://crypto.news/blockstream-says-it-will-not-pay-ransom-for-stolen-liquid-bitcoin/"},{"credibility":2,"name":"Gizmodo: White Hat Liquid Network Crypto Hackers Are Now Grandstanding and Demanding a 10% Bounty","type":"news_article","url":"https://gizmodo.com/white-hat-liquid-network-crypto-hackers-are-now-grandstanding-and-demanding-a-10-bounty-2000809413"},{"credibility":2,"name":"CryptoPotato: Blockstream Rejects 10% Bounty Demand From Liquid Hackers","type":"news_article","url":"https://cryptopotato.com/we-will-not-pay-blockstream-rejects-10-bounty-demand-from-liquid-hackers/"}]},{"content":"Blockstream disabled bridge nodes on September 6, 2026 at approximately 20:25 UTC, halting new peg-in and peg-out operations once the exploit was detected. Block production was halted on September 7 at approximately 04:49 UTC. A patch was deployed to bridge nodes on September 7 at 01:09 UTC. The coordinated patch rollout required all federation member nodes to update and resolve a resulting chain split before the network could safely resume. Blockstream released Elements v23.3.4 publicly on September 9, 2026 as an emergency update, hardening the cache keys used for range proof verification. Block production resumed on September 10, 2026 at approximately 12:26 UTC, four days after the exploit, initially without user transactions as a safety measure. Peg-in and peg-out operations remained suspended pending full reserve recovery and safety validation. Blockstream described a three-stage restart plan: resume block production, validate transactions, and restore peg operations only after the reserve deficit is addressed. Blockstream co-founder Adam Back stated on September 9, 2026 that 'the LBTC to BTC 1:1 peg will be covered,' urging holders not to panic-sell.","heading":"Network Response, Patch Deployment, and Restart","severity":"high","sources":[{"credibility":2,"name":"CryptoTimes: Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"credibility":2,"name":"Liquid Network Incident Report — @Liquid_BTC on X (September 8, 2026)","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":2,"name":"CryptoBriefing: Liquid Network resumes block production after $320M Bitcoin drain","type":"news_article","url":"https://cryptobriefing.com/liquid-network-resumes-after-320m-exploit/"},{"credibility":2,"name":"Unchained Crypto: Liquid Attackers Return 3,400 BTC and Keep Nearly 600 as Blockstream Prepares a Restart","type":"news_article","url":"https://unchainedcrypto.com/liquid-attackers-return-3400-btc-and-keep-nearly-600-as-blockstream-prepares-a-restart/"}]},{"content":"Prior to the exploit, the Liquid Network federation held approximately 4,205 BTC in reserve. After the exploit and the partial return of 3,400 BTC, the implied reserve backing ratio stood at approximately 86%, meaning that not all circulating L-BTC could be redeemed 1:1 for BTC without additional capital. Peg-in and peg-out operations were suspended as of September 10, 2026. L-BTC trading was suspended across exchanges that had listed the token. Blockstream's public pledge that the 1:1 peg 'will be covered' indicated an intent to make holders whole, but no binding commitment or timeline had been announced as of September 10, 2026. The approximately 598.5 BTC (~$47M) retained by the attackers represents the outstanding reserve gap if not recovered. Holders of L-BTC and counterparties relying on the peg faced uncertain redemption conditions pending resolution.","heading":"Reserve Deficit and L-BTC Holder Risk","severity":"high","sources":[{"credibility":2,"name":"TRM Labs: 2026's Biggest Hack to Date — Liquid Network","type":"research","url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"credibility":2,"name":"CryptoTimes: Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"credibility":2,"name":"KuCoin News: Blockstream's Liquid Network Loses $320M in BTC Hack","type":"news_article","url":"https://www.kucoin.com/news/flash/blockstream-s-liquid-network-loses-320m-in-btc-hack"}]},{"content":"Several structural observations emerged from security analysts and commentators following the incident. First, the vulnerability was in the open-source Elements software rather than in the federation's key management or multi-signature custody logic — meaning the attack surface lay in software shared across multiple deployments rather than in Blockstream-specific code. Second, the patch for the specific cache-key encoding bug had been committed to Elements before the exploit occurred, but federation nodes had not been updated to a version containing the fix; this raised questions about the federation's software update and patch management processes. Third, SideSwap's PAK role — which enables users to initiate peg-outs without requiring federation involvement for each transaction — provided the mechanism through which the unbacked L-BTC was converted to real BTC, though SideSwap's systems were not themselves compromised; the federation's own functionary nodes accepted the transaction as valid. Fourth, the incident demonstrated that Confidential Transaction range-proof verification can be a critical security boundary: a single cache-level flaw bypassed the cryptographic guarantee that output amounts are valid. The scale of the incident — approximately $320M drained in 36 minutes — highlighted the concentration risk inherent in federations that hold large reserves.","heading":"Systemic and Structural Observations","severity":"medium","sources":[{"credibility":2,"name":"CertiK: Liquid Network Incident Analysis","type":"research","url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"credibility":2,"name":"TRM Labs: 2026's Biggest Hack to Date — Liquid Network","type":"research","url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"credibility":3,"name":"James Tsetsekas: The Liquid Incident — When Bitcoin Security Meets Federated Bridges","type":"other","url":"https://blog.jamestsetsekas.com/posts/the-liquid-incident-when-bitcoin-security-meets-federated-bridges/"}]}],"sources_used":[{"credibility":2,"name":"Liquid Network Incident Report — @Liquid_BTC on X (September 8, 2026)","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":2,"name":"TRM Labs: 2026's Biggest Hack to Date — Liquid Network","type":"research","url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"credibility":2,"name":"CertiK: Liquid Network Incident Analysis","type":"research","url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"credibility":2,"name":"crypto.news: Liquid Network drained of $320M in cache bug exploit","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"},{"credibility":2,"name":"crypto.news: Blockstream says it will not pay ransom for stolen Liquid Bitcoin","type":"news_article","url":"https://crypto.news/blockstream-says-it-will-not-pay-ransom-for-stolen-liquid-bitcoin/"},{"credibility":2,"name":"CryptoTimes: Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"credibility":2,"name":"CryptoBriefing: Liquid Network resumes block production after $320M Bitcoin drain","type":"news_article","url":"https://cryptobriefing.com/liquid-network-resumes-after-320m-exploit/"},{"credibility":2,"name":"CryptoBriefing: Blockstream confirms bridge nodes patched, funds safe to return","type":"news_article","url":"https://cryptobriefing.com/blockstream-liquid-network-exploit-funds-return/"},{"credibility":2,"name":"Unchained Crypto: Liquid Attackers Return 3,400 BTC and Keep Nearly 600 as Blockstream Prepares a Restart","type":"news_article","url":"https://unchainedcrypto.com/liquid-attackers-return-3400-btc-and-keep-nearly-600-as-blockstream-prepares-a-restart/"},{"credibility":2,"name":"Gizmodo: White Hat Liquid Network Crypto Hackers Are Now Grandstanding and Demanding a 10% Bounty","type":"news_article","url":"https://gizmodo.com/white-hat-liquid-network-crypto-hackers-are-now-grandstanding-and-demanding-a-10-bounty-2000809413"},{"credibility":2,"name":"CryptoPotato: Blockstream Rejects 10% Bounty Demand From Liquid Hackers","type":"news_article","url":"https://cryptopotato.com/we-will-not-pay-blockstream-rejects-10-bounty-demand-from-liquid-hackers/"},{"credibility":1,"name":"CoinDesk: Bitcoin Network Used by Exchanges Hit by $320 Million Exploit (September 7, 2026)","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"credibility":1,"name":"CoinDesk: White-Hat Hackers Return Most of $320M Bitcoin Taken from Liquid Network (September 8, 2026)","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/08/white-hat-hackers-return-most-of-usd320m-bitcoin-taken-from-liquid-network"},{"credibility":1,"name":"Bloomberg: Bitcoin's Latest Hack Puts Key Crypto Vulnerability in Spotlight (September 8, 2026)","type":"news_article","url":"https://www.bloomberg.com/news/articles/2026-09-08/bitcoin-s-latest-hack-puts-key-crypto-vulnerability-in-spotlight"},{"credibility":2,"name":"KuCoin News: Blockstream's Liquid Network Loses $320M in BTC Hack","type":"news_article","url":"https://www.kucoin.com/news/flash/blockstream-s-liquid-network-loses-320m-in-btc-hack"},{"credibility":3,"name":"James Tsetsekas: The Liquid Incident — When Bitcoin Security Meets Federated Bridges","type":"other","url":"https://blog.jamestsetsekas.com/posts/the-liquid-incident-when-bitcoin-security-meets-federated-bridges/"}],"summary":"The Liquid Network is a Bitcoin sidechain operated by Blockstream via a federated multi-signature custody model, designed for fast, confidential BTC transfers between exchanges and financial institutions. On September 6, 2026, attackers exploited a cache-key collision vulnerability in the open-source Elements software to mint approximately 4,000 unbacked L-BTC and drain roughly $320 million from the federation reserve — one of the largest Bitcoin-adjacent security incidents on record. Attackers claiming to be white-hat researchers subsequently returned approximately 3,400 BTC while retaining ~598.5 BTC (~$47M) as a self-declared bounty; Blockstream publicly rejected the bounty demand and characterized the retention as theft.","timeline":[{"date":"2026-04-13","event":"Elements v23.3.3 released — the version running on federation nodes at the time of the exploit, predating the fix for the rangeproof cache vulnerability.","source":"Liquid Network Incident Report / CertiK analysis","source_url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"date":"2026-08-03","event":"Fix for the rangeproof verification cache-key collision vulnerability committed to the Elements open-source repository.","source":"CertiK: Liquid Network Incident Analysis","source_url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"date":"2026-09-02","event":"Vulnerability fix merged into the Elements main branch — four days before the exploit.","source":"CertiK: Liquid Network Incident Analysis","source_url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"date":"2026-09-06","event":"At approximately 13:52 UTC, attacker begins setup transactions against the Liquid Network.","source":"CertiK: Liquid Network Incident Analysis","source_url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"date":"2026-09-06","event":"At 13:53:10 UTC (block 4,050,336), attacker mints approximately 3,998.5 unbacked L-BTC via the rangeproof cache collision exploit.","source":"Liquid Network Incident Report (@Liquid_BTC on X)","source_url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"date":"2026-09-06","event":"At 14:06 UTC, attacker submits peg-out request through SideSwap. At 14:28:56 UTC, approximately 3,996 BTC sent to attacker address — total attack duration roughly 36 minutes. Reserve falls from ~4,205 BTC to ~197–202 BTC.","source":"TRM Labs; CertiK","source_url":"https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds"},{"date":"2026-09-06","event":"At approximately 20:25 UTC, Blockstream disables bridge nodes and halts new peg operations after detecting the exploit.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"date":"2026-09-07","event":"At 01:09 UTC, Blockstream deploys patch to bridge nodes. At approximately 04:49 UTC, block production halted. Attackers communicate via OP_RETURN, claiming to be white-hat researchers.","source":"CryptoTimes; TRM Labs","source_url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"date":"2026-09-07","event":"At approximately 16:09:25 UTC, attackers return 3,400 BTC to the Liquid Federation peg wallet, retaining approximately 598.5 BTC as a self-declared bounty.","source":"CertiK; TRM Labs","source_url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"date":"2026-09-08","event":"Liquid Network publishes official incident report via @Liquid_BTC on X detailing the vulnerability, timeline, and response.","source":"Liquid Network (@Liquid_BTC on X)","source_url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"date":"2026-09-08","event":"Attackers escalate demands, requesting a 10% bounty paid from Blockstream's corporate reserves, threatening permanent 15% loss for L-BTC holders if refused.","source":"Gizmodo; Blockonomi","source_url":"https://gizmodo.com/white-hat-liquid-network-crypto-hackers-are-now-grandstanding-and-demanding-a-10-bounty-2000809413"},{"date":"2026-09-09","event":"Blockstream releases Elements v23.3.4 emergency patch. Adam Back states the LBTC 1:1 peg 'will be covered.' Blockstream publicly rejects the bounty demand, stating it will not pay a ransom.","source":"crypto.news; CryptoTimes","source_url":"https://crypto.news/blockstream-says-it-will-not-pay-ransom-for-stolen-liquid-bitcoin/"},{"date":"2026-09-10","event":"Liquid Network resumes block production at approximately 12:26 UTC, initially without user transactions. Peg-in and peg-out operations remain suspended pending full reserve recovery.","source":"CryptoTimes; CryptoBriefing","source_url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"}]},"v":1}