Crypto news report · source clearly identified

Liquid Network drained of $320 million after range‑proof cache bug

A cache‑key collision in the Elements codebase let an unknown actor mint unbacked L‑BTC, drain 95% of the Liquid federation reserve and return most of the funds after on‑chain negotiation.

A range‑proof verification cache bug in the Elements codebase allowed an attacker to create roughly 4,000 unbacked L‑BTC and peg them out for real Bitcoin, draining about $320 million from the Liquid Network in less than half an hour.

How the exploit worked

Liquid uses confidential transactions that hide output amounts behind Pedersen commitments. To verify that hidden amounts are within a valid range, the Elements software caches successful verification results. The cache key was derived only from the proof bytes and hidden amount, omitting asset type and scriptPubKey. This omission let a previously verified proof be replayed in a different context.

The attacker planted identical range proofs over several hours, causing the cache to store a valid result. Later, they constructed an output that matched the cached key but was otherwise invalid. Federation nodes retrieved the cached result and skipped the necessary verification, allowing the creation of approximately 3,996 L‑BTC out of thin air.

Drain of the federation reserve

At block 4,050,336 the attacker sent the newly minted L‑BTC to SideSwap’s peg‑out service. SideSwap burned the L‑BTC and requested the corresponding Bitcoin from the Liquid federation. The federation released 3,996.0183 BTC to the attacker’s Bitcoin address, reducing the federation wallet from 4,205.29 BTC to 202.63 BTC in about 23 minutes – the largest single‑transaction reserve drain in a Bitcoin sidechain.

On‑chain negotiation and partial return

After the drain, the attacker posted an OP_RETURN message stating “we are whitehats” and opened a public negotiation with Blockstream. Nine OP_RETURN messages were exchanged, a PGP key was verified, and Blockstream patched its bridge nodes. Following the patch, the attacker returned 3,400 BTC to the federation, keeping 598.5 BTC (≈ $47 million) in their wallet.

Impact and open questions

The incident halted block production on September 7, 2026, and exchanges suspended L‑BTC deposits and withdrawals. Blockstream confirmed that no federation keys were compromised; the exploit stemmed from a cache‑key collision that had been merged into the Elements master branch but not included in any released version. The event has revived debate over the trust model of federated sidechains and raised legal questions about whether retaining the remaining funds without a formal bounty agreement constitutes theft or legitimate security research.

Source & attribution

News Source

Publisher
crypto.news
Original date
September 8, 2026, 5:58 PM
Original headline
Liquid Network drained of $320 million as cache bug lets attacker mint unbacked Bitcoin
View original report ↗