The Liquid Network experienced a major security incident on September 6, 2026, after attackers exploited a vulnerability in the open-source Elements software. The flaw permitted the unauthorized minting of approximately 4,000 unbacked Liquid Bitcoin (LBTC) tokens, which were then converted into real bitcoin via the network's peg-out system.
According to incident details, the exploit occurred at Liquid block 4,050,336 due to a vulnerability in range proof verification caching. Attackers utilized SideSwap’s peg-out authorization to process the unbacked tokens. Because the validation failure occurred prior to the peg-out request, SideSwap’s node and network functionaries treated the transactions as legitimate, releasing bitcoin to a whitelisted address tied to SideSwap before the funds were moved to addresses controlled by the exploiters.
Blockstream confirmed that no private keys were compromised during the attack, and the Liquid Federation’s functionary nodes operated normally. Prior to the breach, the Liquid reserve held roughly 4,205 BTC, which dropped to 197 BTC following the unauthorized peg-outs. Other issued assets, such as USDT, were not directly impacted, though they remain temporarily unavailable while the network is paused.
Following the exploit, individuals identifying themselves as white-hat security researchers left a message on the bitcoin mainchain requesting coordination with Blockstream. Blockstream deployed a bridge node patch on September 7 to close the vulnerability. Subsequently, 3,400 BTC was returned to the Liquid Federation’s peg wallet, leaving approximately 598.5 BTC outstanding as discussions for full recovery continue.
Blockstream announced that an emergency release of Elements, version 23.3.4, is undergoing review and is expected within 48 hours to help restore full network operations. Functionary operators will apply necessary adjustments once the update is deployed, and users have been advised that no proactive action is required to protect existing funds.


