// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
On September 6, 2026, unknown actors drained roughly 4,000 BTC — valued at approximately $320 million — from Liquid Network's federated wallet by exploiting a bug in Elements' range proof cache. The attackers, self-identified as "white hats," conditioned the funds' return on the deployment of a fix, retaining 598 BTC as a self-declared bounty according to a single source. Sources disagree on whether most funds have actually been returned.

On September 6, 2026, unknown operators withdrew roughly 4,000 BTC from Liquid Network's federated wallet. The haul, valued at approximately $320 million, represents nearly 95% of the sidechain's Bitcoin reserves. The attackers identified themselves as "white hats" and conditioned the return of funds on the publication of a corrective patch, retaining 598 BTC as a self-proclaimed bounty according to a single source.

Key Takeaways
  • Roughly 4,000 BTC (~$320 million) withdrawn on September 6, 2026 from Liquid Network's federated wallet, nearly 95% of Bitcoin reserves.
  • Bug in Elements' ComputeEntryRangeProof function: cache key omitted asset_commitment and scriptPubKey, allowing reuse of valid verification results for invalid transactions.
  • Attackers self-identified as "white hats" in on-chain messages and demanded a software fix before returning funds.
  • SiliconAngle reports "most of the loot has been returned"; The Register, Forklog, Yellow.com, The Cyber Express, and Shattered.io describe only a promise of return with funds still held.
  • Ledger CTO Charles Guillemet expresses skepticism: "Legitimate security researchers would not normally drain a bridge and then ask the affected project to make contact on-chain."

The Cache Bug: How a Skipped Check Minted Uncollateralized Tokens

The Liquid Network sidechain, operated by Blockstream, uses Confidential Transactions to obscure amounts and assets. The open-source Elements software maintains a cache of range proof verifications to avoid costly cryptographic recalculations.

According to OrangeSurf's analysis published on Forklog and verifiable in commit c26d719c29a40da280a825b25657e9c3d8bc7d99 of the ElementsProject/elements repository, the SignatureCache::ComputeEntryRangeProof function built its cache key using only the proof and commitment fields. It omitted asset_commitment and scriptPubKey.

This omission allowed an attacker to present a range proof for a different asset and receive a cached validation result from a previous legitimate transaction. According to Forklog, this made it possible to generate L-BTC tokens without the corresponding collateral on the Bitcoin main chain, with the network accepting them as valid.

The minted tokens were swapped via SideSwap's peg-out mechanism. Liquid Network stated the Peg Authorization Key (PAK) "was not compromised." SideSwap confirmed the attackers did not access its systems. The vulnerability resided exclusively in the Elements node validation logic.

On-Chain Negotiation: Patch Before Payment

The interaction between attackers and Liquid Network played out through OP_RETURN messages on the Bitcoin blockchain, supplemented by PGP-encrypted communications and, according to Yellow.com, contact via Signal. Alex Thorn of Galaxy Research reconstructed the conversation for The Cyber Express.

"Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix." — Attackers' on-chain message, cited by The Register

Yellow.com places the start of the conversation at 11:30 a.m. PDT on September 6, with messages at 7:20 p.m. and 8:30 p.m. The withdrawal transaction appears in Bitcoin block 965,783, timestamped 14:28:56 UTC — preceding the negotiation.

Liquid Network disabled bridge nodes and suspended operations; exchanges halted L-BTC deposits and withdrawals. Non-Bitcoin assets on the sidechain — USDT, DePix, RWA tokens — were untouched. The Bitcoin main chain was unaffected.

The Return Discrepancy: Promise Versus Execution

Sources diverge on the status of the funds. SiliconAngle, in a September 7 article, states "the hackers returned most of the loot in the early hours of today," specifying 598 BTC retained. The Register, Forklog, Yellow.com, The Cyber Express, and Shattered.io report only a promise of return, with funds still held at time of publication.

This discrepancy remains unresolved by available sources. The brief classifies SiliconAngle's report as potentially premature relative to the majority of sources.

The "white hat" label is contested. Ledger CTO Charles Guillemet told Yellow.com: "Legitimate security researchers would not normally drain a bridge and then ask the affected project to make contact on-chain." Liquid Network used the qualifier "purported white-hat."

The retention of 598 BTC (~$47 million) as a self-declared "bounty" — reported only by SiliconAngle — mirrors formal elements of an extortion demand: fund withdrawal, condition for return, unilateral compensation. The source does not specify whether Liquid Network or investigators share this interpretation.

Context: Sidechains and Bridges as 2026 Targets

According to data cited by SiliconAngle, 50 crypto breaches totaled $136.3 million in losses in August 2026. The Liquid Network incident, at ~$320 million in a single event, exceeds that aggregate figure. This data point does not establish a consolidated pattern for the full year 2026.

Liquid Network's federated structure — roughly 80 members with an 11-of-15 signing threshold for wallet movements — did not prevent the exfiltration. The patch was written on August 3, 2026 but merged on September 1, five days before the attack. The source does not specify the reasons for this release delay.

What to Do Now

For Elements node operators: The patch in commit c26d719c29a40da280a825b25657e9c3d8bc7d99 is available in the official repository. The source does not specify additional verification procedures beyond applying the patch to all nodes.

For L-BTC holders: Liquid Network has suspended operations; exchanges have halted deposits and withdrawals. The source does not specify restoration timelines or required user actions.

For security researchers: The case presents an unresolved discrepancy between sources on fund return and an unverified attacker identity. The source does not specify applicable responsible disclosure frameworks.

Frequently Asked Questions

Why did the attackers promise to return the funds?

According to on-chain messages cited by The Register and The Cyber Express, the attackers conditioned the return promise on verification that "every node is patched." The source does not specify the ultimate motive for this condition.

Was the PAK compromised?

No. Liquid Network explicitly stated "the PAK was not compromised." SideSwap confirmed its systems were not breached.

Is the Bitcoin blockchain at risk?

No. The attack targeted exclusively the Liquid Network sidechain. Bitcoin main chain was unaffected.

Who are the attackers?

Identity unverified. They self-identified as "white hats" but Liquid Network uses the qualifier "purported" and Ledger's CTO expresses skepticism.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. siliconangle.com
  2. theregister.com
  3. shattered.io
  4. yellow.com
  5. forklog.com
  6. thecyberexpress.com
  7. github.com