Industry News

Liquid Network Restores Operations After $320M Bitcoin Sidechain Exploit

Blockonomi · 11 Sept 2026
Key Takeaway Businesses relying on blockchain or fintech infrastructure should confirm vendors have patched known verification-logic flaws before resuming full operations.

The Liquid Network, a Bitcoin sidechain operated by Blockstream, has resumed block production after a security incident in which attackers extracted around 4,000 Bitcoin, nearly 95% of the funds held in its custodial wallet. The individuals involved identified themselves as ethical security researchers.

The root cause was a flaw in Elements, the open-source software underlying Liquid, specifically in a caching component meant to speed up verification of confidential transactions. This flaw let previously validated results be reused incorrectly, allowing the attacker to mint Liquid's Bitcoin-pegged token (L-BTC) without actually depositing real Bitcoin. They then redeemed these fake tokens through a legitimate withdrawal service, tricking the network into releasing genuine Bitcoin. No cryptographic signing keys were stolen; the issue was purely in the software logic validating token redemptions.

The attackers communicated with Blockstream via messages embedded in Bitcoin transactions and indicated they would return the funds once the vulnerability was patched. According to reports, around $270 million has since been returned, with $46 million reportedly retained. Transaction processing and withdrawal features remain disabled while recovery continues.

Summarised by CISO AI from Blockonomi. We link back to every original so you can read it yourself.