Security

Liquid Network Loses $320 Million in Bitcoin as Attacker Drains 95 Percent of Its Reserves

A suspected inflation bug in the sidechain's software let an attacker mint unbacked tokens and redeem them for real bitcoin, and the promise to return the funds has not yet been honored.

T
By TechQuire Daily Staff TechQuire Daily Staff
September 7, 2026 / 7 min read

Liquid Network, the Bitcoin sidechain operated by Blockstream, lost nearly 4,000 bitcoin, worth roughly 320 million dollars, over the weekend in an attack that drained about 95 percent of the sidechain's bitcoin reserves, according to reports on September 7. The attacker left an on-chain message claiming to be a white-hat hacker who intends to return the funds after the underlying software flaw is fixed, but the money had not been returned by the time the incident was publicly reported. The breach is among the largest ever suffered by a Bitcoin-related network and has raised urgent questions about the security of sidechains that rely on federated custody.

Key Facts

The scale of the loss is documented in multiple September 7 reports. The Hindu BusinessLine reported that approximately 3,996 to 3,998.5 bitcoin were transferred out of the network's reserves, worth an estimated 319.5 to 320 million dollars, while ForkLog, a cryptocurrency news outlet, reported the same figure. Bitcoin Magazine reported that the federation wallet held roughly 4,200 bitcoin before the attack and only about 197 to 207 bitcoin, or roughly 5 percent of the original holdings, remained afterward.

The attack path runs through a specific piece of infrastructure. Bitcoin Magazine and ForkLog both reported on September 7 that the funds were withdrawn using an authorization granted through SideSwap, a decentralized exchange protocol that operates on Liquid and provides one of the network's peg-out channels. The reports describe the exploit as an inflation bug in the Elements software that underpins Liquid, through which the attacker was able to create L-BTC, Liquid's wrapped bitcoin token, without a corresponding bitcoin reserve behind it, effectively minting value out of nothing and then redeeming it for real bitcoin.

The suspected root cause is a flaw in range-proof validation caching. Bitcoin Magazine reported on September 7 that researchers suspect the vulnerability lies in the way Elements caches range-proof validation, allowing the attacker to bypass a check that normally prevents the creation of unbacked tokens. Blockstream has not yet published a full technical post-mortem, and the reports note that the precise mechanism remains under investigation.

The attacker's message complicates the response. ForkLog and Yahoo Finance reported on September 7 that the address controlling the stolen funds posted a message on-chain identifying itself as a white-hat hacker, stating that the vulnerability had been exploited to force a fix and that most of the funds would be returned once the issue was resolved. As of the reporting time, no funds had been returned, and Bitcoin Magazine noted that the bitcoin price remained stable at around 80,000 dollars, suggesting markets had not yet priced in a major systemic event. Liquid suspended trading and notified partner exchanges to pause L-BTC deposits and withdrawals, while ForkLog reported that USDT, DePix and real-world-asset tokens on the network were not affected.

Analysis

What this really means is that the trust model at the heart of federated sidechains has been shown to have a hole that no amount of multisig custody can patch, because the vulnerability was not in the keys but in the software that issues and validates the sidechain's native token. Liquid's design rests on a federation of functionaries who collectively hold the peg-in bitcoin, and the conventional wisdom has been that the main risk is a conspiracy or compromise of those key holders. This attack bypassed that entire apparatus: whoever controlled the vulnerable code path could create L-BTC out of thin air and drain the reserve through a legitimate-looking peg-out, which means the security of the network depended on the correctness of code that had evidently never been tested against this class of bug.

The bigger picture here is that the inflation-vulnerability class is the most dangerous possible failure for a blockchain that claims to represent real assets. If an attacker can mint tokenized bitcoin without backing, the entire accounting premise of the sidechain collapses, because the supply of L-BTC no longer corresponds to the bitcoin held in reserve. The fact that the alleged attacker says they did it to force a fix, and has promised to return the funds, is cold comfort: the same technique could be used by someone with no intention of returning anything, and the network's 95 percent reserve depletion shows how quickly the damage can occur once the flaw is triggered.

The doubts raised by external observers are worth taking seriously. Bitcoin Magazine noted that some prominent voices in the Bitcoin community, including Ledger's chief technology officer Charles Guillemet and the longtime advocate Samson Mow, questioned whether the white-hat narrative is credible or whether it is a cover story for a theft, and the absence of returned funds at the time of reporting only deepened that skepticism. In any incident of this size, the burden of proof should be on the attacker to demonstrate good faith by actually returning the money, and until that happens the white-hat label should be treated as a claim, not a fact. There is also a practical lesson for users of the network: anyone holding L-BTC, USDT on Liquid, or tokens issued through SideSwap now faces real uncertainty about the solvency of the reserve backing those assets, and the range of possible outcomes includes a permanent loss that a multisig federation was never designed to prevent.

Why It Matters

For the Bitcoin ecosystem, the incident is a reminder that layer-two and sidechain solutions carry their own risk models, and that the security guarantees they offer are only as strong as the software they run. Liquid was designed for institutional use cases such as fast settlement and confidential transactions, and it has been marketed as a more secure alternative to centralized exchanges; an attack that drains 95 percent of its reserve undermines that positioning and will make institutions think twice before parking significant value on federated sidechains.

For the wider cryptocurrency industry, the event is a case study in how an inflation bug, the same class of vulnerability that has historically broken several altcoin networks, can strike a network whose assets are supposed to be fully backed. It also tests the credibility of the white-hat return narrative at scale, since the outcome, whether the funds are returned or not, will shape how the industry responds to future attacks in which the perpetrator claims benevolent intent. For regulators, a 320 million dollar loss on a network used by exchanges will add to the pressure for clearer rules on custody, reserves and incident disclosure across the sector.

Next Up

The single most important development to watch is whether the attacker makes good on the promise to return the funds, and on what timeline, since that will determine whether this becomes a recovered incident or one of the largest permanent losses in Bitcoin history. Equally important is Blockstream's technical post-mortem, which should explain the precise range-proof validation flaw and the fix, and whether the federation resumes peg-out services and reopens L-BTC deposits and withdrawals. Watch also for the reaction of exchanges that suspended Liquid activity, and for any evidence of broader exposure, since the same Elements code base may be used by other projects that now need to check whether they share the vulnerability. Any announcement of recovered funds, a forked recovery process, or a decision to socialize the loss across L-BTC holders will carry more weight for the network's future than the technical details of the exploit itself.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.