SlowMist details Liquid Network exploit, attacker mints 3,998 L-BTC in largest Bitcoin sidechain hack of 2026

1 hour ago 19

A single software bug in Blockstream’s Elements codebase allowed an attacker to conjure nearly 4,000 unbacked L-BTC out of thin air, peg them out for real Bitcoin, and drain roughly 95% of the Liquid Federation’s reserves in a matter of hours. SlowMist published its full analysis of the September 6 exploit on September 11, confirming what is now the largest publicly disclosed security incident involving a Bitcoin sidechain this year.

The damage: approximately 3,998.5 L-BTC minted and redeemed, worth roughly $320 million. The Liquid Federation’s reserve wallet went from holding over 4,200 BTC to about 197 BTC.

How a caching shortcut became a $320 million problem

The root cause, according to SlowMist’s analysis, was a cache key collision vulnerability buried in the range-proof verification process. Range proofs are cryptographic checks that confirm transaction amounts fall within valid bounds without revealing exact values. They’re fundamental to Liquid’s confidential transaction model.

To speed up verification, Elements cached previously validated proofs so it wouldn’t have to recheck them. The problem was how those cache keys were constructed. Prior to version v23.3.4, the software generated cache keys without length prefixes. Two different inputs could produce identical cache keys, meaning the system would treat an invalid proof as already verified if its key happened to collide with a legitimate one.

The attacker exploited this collision to bypass verification, minting L-BTC that had no corresponding Bitcoin backing in the federation’s peg wallet. Those freshly minted tokens were then rapidly pegged out, converting them into real BTC on the Bitcoin mainnet before anyone could intervene.

The aftermath: partial recovery and an on-chain negotiation

Blockstream moved quickly after discovering the exploit. Peg operations were suspended, halting any further outflows. The network’s block production itself was paused and didn’t resume until September 10, after the team deployed Elements v23.3.4 with patched cache key management that includes proper length prefixes.

Blockstream confirmed that the incident was caused by a software bug, not a compromise of the federation’s signing keys.

The attacker communicated via Bitcoin OP_RETURN messages, a method of embedding short text strings directly into Bitcoin transactions. The messages identified the attacker as a white-hat researcher and included a demand for a 10% bounty.

Roughly 3,400 BTC were returned to the federation peg wallet following the patch. The attacker retained approximately 598.5 BTC, presumably their self-assessed finder’s fee. The math works out to about 15% of the total haul, not the 10% originally requested.

What this means for federated sidechains

The vulnerability wasn’t in the federation’s governance or key management. It was in a performance optimization. Caching verified proofs is a perfectly reasonable thing to do. The implementation just happened to contain a flaw that turned a speed improvement into a $320 million attack vector.

The network was offline for four days. Ninety-five percent of its reserves vanished before anyone noticed. And the recovery depended, in part, on the attacker’s willingness to return funds.

SlowMist’s analysis specifically flags the absence of length prefixes in cache key construction as the enabling factor, a detail that other projects using similar patterns should audit immediately.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article