Blockstream's Liquid Network Hacked: $400M Bug Exploited Before Most Funds Recovered
Blockstream's Liquid Network, a bitcoin sidechain, suffered a major exploit on September 6, 2026, after attackers found a flaw in how the network's Elements software cached range proof verifications. This allowed roughly 4,000 unbacked LBTC tokens to be created with no real bitcoin behind them.
The attackers routed these fake tokens through SideSwap, a Liquid Federation member with authority to process peg-out requests. Because the validation failure occurred before the peg-out request was submitted, the system treated the transaction as legitimate and released real bitcoin, which was then forwarded to an address controlled by the attackers. Liquid's total bitcoin reserve fell from around 4,205 BTC to just 197 BTC as a result. Blockstream says no private keys were compromised and the network's functionary nodes operated normally throughout.
Blockstream has since recovered most of the stolen funds, though the Liquid Network remains offline while a patch is finalised. Other assets on the network, including USDT, were not directly affected by the vulnerability but remain temporarily unavailable due to the network-wide pause.