Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#1
Score
Cluster
mainnet-beta
Slot
446216376
Off-chain at
2026-09-11T17:42:00.857Z
Anchored at
Block time

Independent verification

1. Database (off-chain)
3WxgEuF5WmzZqEw79Y5ty3hxeRnMBTrQ9cB465ZeAife
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (23786 chars)
{"actor":"system:backfill","investigation_id":"196749fe-765a-46f0-ae2c-ff225f75a1c9","kind":"publish","page_slug":"liquid-network-elements-cache-bug-exploit-september-2026","published_at":"2026-09-11T17:42:00.709Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Liquid Network / Elements Cache-Bug Exploit (September 2026)","sections":[{"content":"On September 6, 2026 at approximately 15:53:10 UTC, beginning at Liquid block 4,050,336, an attacker exploited a vulnerability in the open-source Elements software used by the Liquid Network to validate Confidential Transactions. The vulnerability allowed the attacker to create approximately 3,998.5 L-BTC tokens that were not backed by any Bitcoin held in the federation's reserve. The attacker then used SideSwap's peg-out authorization to convert the fraudulent L-BTC into native Bitcoin. The main peg-out of 3,996.02 L-BTC completed at 14:28:56 UTC, and reserve holdings fell from approximately 4,205 BTC to 197 BTC — a reduction of roughly 95%. Blockstream confirmed that no federation private keys were compromised; the exploit was a software-level validation bypass, not a cryptographic key theft. The Liquid Network halted block production and exchanges suspended L-BTC deposits and withdrawals. Other assets on the network, including USDT and tokenized real-world assets, were reportedly unaffected.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"Liquid Network official incident report (X/@Liquid_BTC, September 8, 2026)","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":2,"name":"Liquid Network drained of $320M in cache bug exploit — crypto.news","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"},{"credibility":2,"name":"Liquid Network suffers $320M hack as 4,000 BTC drained from federation wallet — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/liquid-network-320m-hack-bitcoin-sidechain/"},{"credibility":2,"name":"Liquid Network Exploit Drained $316M Via Software Bug, Not Stolen Keys — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/326941/20260908/liquid-network-exploit-drained-316m-via-software-bug-not-stolen-keys.htm"}]},{"content":"Security researchers at CertiK and independent analysts identified the root cause as an ambiguous cache-key encoding in Elements' rangeproof verification logic. Liquid's Confidential Transactions use zero-knowledge range proofs to verify that hidden transaction amounts are valid without revealing the values. The caching layer constructed cache keys by concatenating four fields — rangeproof (P), value commitment (C), asset generator (X), and script (S) — into a single SHA-256 stream without length-encoding the variable-length fields. Because no delimiters separated the fields, distinct input tuples could produce identical byte streams, yielding matching cache keys despite representing different cryptographic inputs. An attacker who primed the cache with a legitimately valid transaction could then submit a second, invalid transaction whose cache key collided with the first; the cache returned a 'verified' result for the second transaction without performing any cryptographic check. CertiK described the attack as a four-stage sequence: cache priming via setup transactions; submission of a malicious inflation transaction that reused the cached validation result; creation of unauthorized L-BTC; and peg-out via SideSwap to convert fraudulent L-BTC to native Bitcoin. On-chain analysis reported by CryptoSlate noted that a fix for the bug had been merged to the Elements development branch on approximately September 1–3, 2026, but had not been included in any tagged release, meaning every production federation node was still running vulnerable code at the time of the exploit.","heading":"Technical Root Cause: Elements Rangeproof Cache-Key Collision","severity":"critical","sources":[{"credibility":2,"name":"Liquid Network Incident Analysis — CertiK","type":"research","url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"credibility":2,"name":"Tokens created out of thin air may explain how $320 million in Bitcoin left the Liquid sidechain — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/tokens-created-out-of-thin-air-may-explain-how-320-million-in-bitcoin-left-a-sidechain/"},{"credibility":3,"name":"Liquid Network Hack Explained: Inside the $320M Attack Path No Scan Would Have Caught — CodeAnt","type":"research","url":"https://codeant.ai/blogs/liquid-network-hack-attack-path-validation"}]},{"content":"Following the exploit, the attacker embedded messages in Bitcoin OP_RETURN fields identifying themselves as 'whitehats' and inviting Blockstream to contact them on-chain. Messages included 'we are whitehats. contact us on chain' and 'Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched.' On September 7, 2026, the attacker returned 3,400 BTC (approximately $265–268 million at prevailing prices) to the Liquid Federation wallet at approximately 16:09–18:09 UTC. The attacker retained 598.5 BTC — approximately 15% of the total withdrawn — and according to reporting by Blockonomi and Recorded Future News, demanded a 10% bounty from Blockstream's corporate treasury, threatening to impose a permanent 15% loss on Liquid users if demands were refused. No formal bug bounty agreement existed between the attacker and Blockstream before the exploit. Charles Guillemet, CTO of Ledger, was quoted as disputing the white-hat characterization and suggesting the conduct resembled extortion. The Recorded Future/The Record article noted blockchain-embedded PGP-encrypted content requiring Blockstream to respond before full fund return.","heading":"Attacker Communications and Alleged White-Hat Claims","severity":"high","sources":[{"credibility":2,"name":"'White hat' hackers take $47 million bounty after $320 million crypto theft — The Record (Recorded Future News)","type":"news_article","url":"https://therecord.media/liquid-network-blockstream-crypto-theft-hackers-keep-reward"},{"credibility":2,"name":"Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html"},{"credibility":2,"name":"Blockstream Takes Hard Stance Against Liquid Network Hackers Demanding Ransom for 598 BTC — Blockonomi","type":"news_article","url":"https://blockonomi.com/blockstream-takes-hard-stance-against-liquid-network-hackers-demanding-ransom-for-598-btc"},{"credibility":1,"name":"$320 million bitcoin exploit hits Liquid Network — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"}]},{"content":"On September 11, 2026, Blockstream issued a public statement explicitly rejecting the attacker's white-hat characterization. The company stated: 'Unauthorized asset seizure and conditional withholding constitutes criminal activity, not responsible disclosure.' Blockstream declared it would 'not pay a ransom for the return of stolen funds' and characterized the 598.5 BTC still held by the attacker as theft. The company announced it would engage law enforcement, cryptocurrency exchanges, financial service providers, and blockchain forensic specialists to trace and recover the outstanding assets. As of September 11, 2026, the 598.5 BTC remains in an address controlled by the attacker and no court proceedings or law enforcement charges had been publicly announced. This page will be updated as the legal and recovery status develops.","heading":"Blockstream's September 11 Response and Legal Posture","severity":"high","sources":[{"credibility":2,"name":"Blockstream Takes Hard Stance Against Liquid Network Hackers Demanding Ransom for 598 BTC — Blockonomi","type":"news_article","url":"https://blockonomi.com/blockstream-takes-hard-stance-against-liquid-network-hackers-demanding-ransom-for-598-btc"},{"credibility":2,"name":"'White hat' hackers take $47 million bounty after $320 million crypto theft — The Record (Recorded Future News)","type":"news_article","url":"https://therecord.media/liquid-network-blockstream-crypto-theft-hackers-keep-reward"}]},{"content":"Blockstream deployed a security patch on September 7, 2026 at approximately 01:09 UTC, updating all functionary and bridge nodes to a hardened version of Elements. An emergency release, Elements v23.3.4, was committed within 48 hours of the incident. The patch addressed the cache-key construction flaw by adding proper length delimiters to the field concatenation used to build rangeproof verification cache keys. Block production resumed on September 10, 2026, initially producing blocks without transactions as a precautionary measure while the network was monitored. Peg operations and full transaction functionality remained paused at the time of the Liquid Network's September 8 incident report. Both Halborn and CertiK confirmed that the patched version closes the specific cache-collision vector exploited in this incident. The Liquid Network official report characterized the exploit as resulting from 'several individually low-probability factors' interacting together and stated the goal of resumption was '1:1 backing for BTC.'","heading":"Patch Deployment and Network Restart","severity":"medium","sources":[{"credibility":2,"name":"Liquid Network official incident report (X/@Liquid_BTC, September 8, 2026)","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":2,"name":"Liquid Network resumes block production after $320M Bitcoin drain — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/liquid-network-resumes-after-320m-exploit/"},{"credibility":2,"name":"Explained: The Liquid Network Hack (September 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-liquid-network-hack-september-2026"}]},{"content":"The Liquid Network is a Bitcoin sidechain operated by a federation of financial institutions and exchanges. As of Q1 2026, the federation comprised 87 member organizations with 15 active signers required to achieve an 11-of-15 multisig threshold for block validation. In this incident, no federation member's private keys were stolen or compromised. The attack operated at the transaction validation layer — the cache-key collision caused Liquid nodes to treat an invalid transaction as already-verified, bypassing the rangeproof check before the transaction ever reached the multisig signing layer. SideSwap, a Liquid Federation member holding a peg-out authorization (PAK) key, processed the peg-out because the malicious L-BTC appeared valid to all nodes running the vulnerable Elements build. Bitcoin's base layer was not affected; the exploit was confined entirely to the Elements sidechain layer. L-BTC deposits and withdrawals were suspended by major exchanges upon detection of the anomaly.","heading":"Federation Architecture and Scope of Compromise","severity":"high","sources":[{"credibility":3,"name":"Liquid Network Hack: $320M Bitcoin Sidechain Exploit [2026] — Shattered.io","type":"research","url":"https://shattered.io/liquid-network-320-million-hack-2026/"},{"credibility":2,"name":"Liquid Network Exploit Drained $316M Via Software Bug, Not Stolen Keys — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/326941/20260908/liquid-network-exploit-drained-316m-via-software-bug-not-stolen-keys.htm"},{"credibility":2,"name":"Tokens created out of thin air may explain how $320 million in Bitcoin left the Liquid sidechain — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/tokens-created-out-of-thin-air-may-explain-how-320-million-in-bitcoin-left-a-sidechain/"}]},{"content":"As of September 11, 2026 — the date of Blockstream's public rejection of the attacker's demands — 598.5 BTC (approximately $47 million at $78,000–$80,000 per BTC) remains in an address controlled by the attacker. No court has adjudicated ownership of these funds. Blockstream has characterized the retained amount as stolen property and announced a law-enforcement-led recovery effort. The attacker has not returned the 598.5 BTC as of the publication of this investigation. Samson Mow, CEO of JAN3 and a former Blockstream executive, was quoted estimating the unreturned amount in media coverage. The status of Blockstream's engagement with law enforcement or blockchain forensic firms has not been publicly detailed as of September 11, 2026.","heading":"Outstanding Funds and Recovery Status","severity":"high","sources":[{"credibility":2,"name":"Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html"},{"credibility":2,"name":"Blockstream Takes Hard Stance Against Liquid Network Hackers Demanding Ransom for 598 BTC — Blockonomi","type":"news_article","url":"https://blockonomi.com/blockstream-takes-hard-stance-against-liquid-network-hackers-demanding-ransom-for-598-btc"},{"credibility":2,"name":"'White hat' hackers take $47 million bounty after $320 million crypto theft — The Record (Recorded Future News)","type":"news_article","url":"https://therecord.media/liquid-network-blockstream-crypto-theft-hackers-keep-reward"}]},{"content":"Multiple security researchers characterized the cache-key collision as a long-standing architectural flaw in the Elements codebase, described in some analyses as originating in the 0.x era of the software. The vulnerability existed in the production codebase for an extended period before the fix was authored. Notably, the fix was reportedly merged to the Elements development branch on approximately September 1–3, 2026 — several days before the exploit — but was not included in any tagged release and was therefore not deployed by federation nodes. This gap between fix authorship and production deployment is a distinct contributing factor to the severity of the incident. CertiK's analysis noted that the class of bug — insufficient input delimitation in cache-key construction for cryptographic verification — is a category that standard automated security scanners would not reliably detect, because it requires understanding the semantic relationship between the caching layer and the underlying cryptographic primitive. The Bitcoin base layer itself has no architectural relationship to the flaw; the vulnerability was specific to the Elements sidechain implementation.","heading":"Broader Context: Elements Software Architecture Risk","severity":"high","sources":[{"credibility":2,"name":"Liquid Network Incident Analysis — CertiK","type":"research","url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"credibility":3,"name":"Liquid Network Hack Explained: Inside the $320M Attack Path No Scan Would Have Caught — CodeAnt","type":"research","url":"https://codeant.ai/blogs/liquid-network-hack-attack-path-validation"},{"credibility":2,"name":"Tokens created out of thin air may explain how $320 million in Bitcoin left the Liquid sidechain — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/tokens-created-out-of-thin-air-may-explain-how-320-million-in-bitcoin-left-a-sidechain/"}]}],"sources_used":[{"credibility":2,"name":"Liquid Network official incident report (X/@Liquid_BTC, September 8, 2026)","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":2,"name":"Liquid Network drained of $320M in cache bug exploit — crypto.news","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"},{"credibility":1,"name":"$320 million bitcoin exploit hits Liquid Network. Hacker makes conditional offer — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"credibility":2,"name":"Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html"},{"credibility":2,"name":"Explained: The Liquid Network Hack (September 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-liquid-network-hack-september-2026"},{"credibility":2,"name":"Liquid Network Incident Analysis — CertiK","type":"research","url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"credibility":1,"name":"Hackers Drain $320 Million From Bitcoin's Liquid Network — Bloomberg","type":"news_article","url":"https://www.bloomberg.com/news/articles/2026-09-07/bitcoin-network-says-320-million-stolen-in-latest-crypto-hack"},{"credibility":2,"name":"'White hat' hackers take $47 million bounty after $320 million crypto theft — The Record (Recorded Future News)","type":"news_article","url":"https://therecord.media/liquid-network-blockstream-crypto-theft-hackers-keep-reward"},{"credibility":2,"name":"Blockstream Takes Hard Stance Against Liquid Network Hackers Demanding Ransom for 598 BTC — Blockonomi","type":"news_article","url":"https://blockonomi.com/blockstream-takes-hard-stance-against-liquid-network-hackers-demanding-ransom-for-598-btc"},{"credibility":2,"name":"Tokens created out of thin air may explain how $320 million in Bitcoin left the Liquid sidechain — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/tokens-created-out-of-thin-air-may-explain-how-320-million-in-bitcoin-left-a-sidechain/"},{"credibility":2,"name":"Liquid Network suffers $320M hack as 4,000 BTC drained from federation wallet — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/liquid-network-320m-hack-bitcoin-sidechain/"},{"credibility":2,"name":"Liquid Network resumes block production after $320M Bitcoin drain — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/liquid-network-resumes-after-320m-exploit/"},{"credibility":2,"name":"Liquid Network Exploit Drained $316M Via Software Bug, Not Stolen Keys — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/326941/20260908/liquid-network-exploit-drained-316m-via-software-bug-not-stolen-keys.htm"},{"credibility":2,"name":"Attackers Drained 4,000 Bitcoin From Blockstream's Liquid Network — 247 Wall St.","type":"news_article","url":"https://247wallst.com/investing/cryptocurrency/2026/09/08/attackers-drained-4000-bitcoin-from-blockstreams-liquid-network-they-say-they-are-white-hats-and-want-to-give-it-back/"},{"credibility":3,"name":"Liquid Network Hack: $320M Bitcoin Sidechain Exploit [2026] — Shattered.io","type":"research","url":"https://shattered.io/liquid-network-320-million-hack-2026/"},{"credibility":2,"name":"Hackers Drain $320 Million From Bitcoin's Liquid Network — Gizmodo","type":"news_article","url":"https://gizmodo.com/hackers-drain-320-million-from-bitcoins-liquid-network-keep-47-million-for-themselves-in-white-hat-operation-2000808262"},{"credibility":3,"name":"Liquid Network Hack Explained: Inside the $320M Attack Path No Scan Would Have Caught — CodeAnt","type":"research","url":"https://codeant.ai/blogs/liquid-network-hack-attack-path-validation"}],"summary":"On September 6, 2026, an unidentified attacker exploited an ambiguous cache-key encoding flaw in the open-source Elements software underpinning Blockstream's Liquid Network sidechain. Approximately 3,998.5 unbacked L-BTC (valued at roughly $320 million) were minted and pegged out for native Bitcoin, draining an estimated 95% of the federation's reserves. The attacker returned 3,400 BTC on September 7 and retained 598.5 BTC (~$47 million), characterizing the retention as a 15% bounty; Blockstream's September 11 public statement rejects this characterization and refuses to treat the incident as a white-hat disclosure, stating the retained funds constitute theft.","timeline":[{"date":"2026-09-01","event":"A fix for the rangeproof cache-key collision bug was reportedly merged to the Elements development branch. No tagged release contained it; production nodes remained on the vulnerable build.","source":"CryptoSlate / on-chain researcher Mononaut","source_url":"https://cryptoslate.com/tokens-created-out-of-thin-air-may-explain-how-320-million-in-bitcoin-left-a-sidechain/"},{"date":"2026-09-06","event":"Between approximately 11:30 and 13:16 UTC, the attacker executed a series of dry-run peg-out transactions on the Liquid Network, testing the exploit mechanism.","source":"CryptoSlate / CertiK","source_url":"https://cryptoslate.com/tokens-created-out-of-thin-air-may-explain-how-320-million-in-bitcoin-left-a-sidechain/"},{"date":"2026-09-06","event":"At 13:52:10 UTC, the attacker broadcast setup (cache-priming) transactions. At 13:53:10 UTC, the malicious inflation transaction was submitted at Liquid block 4,050,336, exploiting the cache-key collision to create approximately 3,998.5 unbacked L-BTC.","source":"CertiK Liquid Network Incident Analysis","source_url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"date":"2026-09-06","event":"At 14:06:10 UTC, the second (main) peg-out of 3,996.02 L-BTC was submitted via SideSwap. At 14:28:56 UTC, the attacker received 3,996.02 BTC on Bitcoin mainnet. Federation reserves fell from approximately 4,205 BTC to 197 BTC — a 95% drain.","source":"CertiK / crypto.news","source_url":"https://www.certik.com/blog/liquid-network-incident-analysis"},{"date":"2026-09-07","event":"Blockstream deployed emergency security patch at approximately 01:09 UTC, updating functionary and bridge nodes to a hardened Elements build (emergency release Elements v23.3.4 announced).","source":"Liquid Network official incident report (X/@Liquid_BTC)","source_url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"date":"2026-09-07","event":"The attacker returned 3,400 BTC to the Liquid Federation wallet at approximately 16:09–18:09 UTC, retaining 598.5 BTC. On-chain messages identified the actors as 'whitehats' and demanded a 10% bounty from Blockstream's corporate treasury.","source":"The Hacker News / Blockonomi","source_url":"https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html"},{"date":"2026-09-08","event":"Liquid Network published its official incident report at 19:10 UTC. Report confirms no private keys compromised, describes the exploit as a rangeproof verification cache flaw, announces Elements v23.3.4 emergency release, and states restoration goal of 1:1 BTC backing.","source":"Liquid Network official incident report (X/@Liquid_BTC)","source_url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"date":"2026-09-10","event":"Liquid Network resumed block production, initially without transactions, following patching of all functionary and bridge nodes.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/liquid-network-resumes-after-320m-exploit/"},{"date":"2026-09-11","event":"Blockstream issued a public statement rejecting the white-hat characterization, refusing to pay the attacker's demanded bounty, characterizing the retained 598.5 BTC as theft, and announcing engagement of law enforcement and blockchain forensic specialists.","source":"Blockonomi / The Record (Recorded Future News)","source_url":"https://blockonomi.com/blockstream-takes-hard-stance-against-liquid-network-hackers-demanding-ransom-for-598-btc"}]},"v":1}