Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$84,063▼ 0.40%ETH$2,692▲ 0.06%SOL$122.04▲ 4.36%TOTAL CRYPTO$2.89T▼ 2.35%S&P 5007,743.41▲ 0.86%NASDAQ27,068.72▲ 3.51%DOW51,828.62▼ 3.26%GOLD4,320.50▼ 7.97%WTI92.44▲ 12.24%BRENT97.47▲ 10.04%EUR/USD1.1392▼ 2.37%USD/JPY157.19▼ 1.23%DXY101.04▲ 2.14%
Crypto

Liquid’s $320M Lesson: Two Bugs, One PAK Gap

Blockstream's postmortem shows a 2018 cache bug and a second flaw combined with a SideSwap key gap to drain $320 million from Liquid on September 6.

Pexels – DS stories

Blockstream published a detailed security assessment of the September 6 Liquid Network incident on Tuesday, confirming that two distinct consensus bugs in the Elements codebase, combined with a gap in one federation member’s peg-out key configuration, let an attacker mint roughly 4,000 unbacked LBTC and drain about $320 million in bitcoin from the sidechain. The report also discloses that a researcher had reported the first bug weeks before the attack, and that the fix for it, once merged publicly, exposed the second.

The attack unfolded at 13:53 UTC on September 6, at Liquid block 4,050,336. The attacker exploited a vulnerability in Elements’ rangeproof verification cache, the component that lets nodes skip re-verifying expensive zero-knowledge proofs they have already checked. A single transaction passed validation even though its output value was not backed by its inputs. Federation functionary nodes accepted it, inflating LBTC supply by roughly 4,000 coins with no bitcoin behind them.

The attacker then moved the fake LBTC through the network’s standard peg-out process via SideSwap, a federation member holding a Peg-out Authorization Key. That produced a withdrawal of approximately 4,000 BTC, confirmed in Bitcoin block 965,783. Smaller peg-outs confirmed before the network was halted brought the Liquid reserve down from about 4,205 BTC to just 197 BTC.

Two bugs, eight years apart

The postmortem identifies the root cause as a change merged into Elements in May 2018, version 0.14.1. The change simplified the cache key used to store rangeproof verification results so that it no longer included the asset commitment or the output’s scriptPubKey. A cached result was therefore not bound to all of the context used to verify the proof. Under the right conditions, a node could reuse a cached result and accept a proof in a context where it was not actually valid, while a node with a cold cache would reject the same transaction. That divergence could split consensus or stall block production.

The defect survived eight years of operation and multiple audits, something the report addresses directly. Security review, it notes, focuses most closely on new or changing code. Stable, long-running code that has passed prior review sits in a lower-risk tier in standard audit frameworks. Blockstream also says AI-assisted analysis tools are beginning to change how legacy codebases get reviewed, and that it is incorporating those capabilities into its ongoing review program.

The timeline around disclosure is the harder part of the story. An external researcher, credited in the report as stutxo, reported the first bug, labeled Bug A, through Blockstream’s security mailbox on August 2, with two proposed fixes. Blockstream opened an internal fix the next day, deployed it to bridge and testnet nodes, validated it on testnet against a cache-poisoning transaction by August 5, and merged the fix into the public Elements repository on September 1. The report is explicit about the consequence: from that point, the code containing the second bug, Bug B, was publicly visible.

Five days later, the attacker used it.

The key that let the coins out

Minting unbacked LBTC was not enough on its own. Converting it to real bitcoin required a valid peg-out, and peg-outs are controlled by PAK entries held by federation members. Each entry has two keys. An offline key, derived from a member’s cold wallet, controls where withdrawn bitcoin can go. An online key, living on a running node, signs peg-out requests. The design intends the offline key as a safety net: even if consensus validation accepts bad LBTC, the released bitcoin should sit in cold storage, giving the federation time to catch the problem.

That safety net failed for one member. The report describes a gap in how SideSwap’s PAK signing process was configured that allowed the attacker to route the withdrawal through SideSwap’s auto-forward service, which forwarded funds from SideSwap’s own whitelisted address to the attacker. Federation keys themselves were not compromised. SideSwap has published its own account of the operational issues it identified, which Blockstream credits with improving the accuracy of the report.

Recovery and what remains

The attacker identified themselves on-chain within hours, calling themselves white hats, and returned 3,400 BTC on September 7 after Blockstream patched the affected bridge nodes and confirmed the fix through signed on-chain messages. Approximately 602 BTC remain outstanding. Blockstream has rejected the group’s demand for a 10% bounty, worth roughly $32 million at the incident’s scale, and says it continues to pursue recovery of the remainder. Immunefi CEO Mitchell Amador said this week that retaining the funds crossed the line from responsible disclosure into theft.

Network operations recovered in stages. Blockstream halted the bridge nodes shortly after the attack, shipped an emergency interim patch within hours, and released a fully reviewed hardening version, Elements v23.3.4, within days. Block production resumed September 10, normal transactions followed the same day, and peg-ins reopened on September 11. Peg-outs remain paused. On-chain data shows 4,234.76 LBTC in circulation against 3,632.23 BTC in reserve, a shortfall that matches the unreturned coins. Blockstream co-founder Adam Back has said the peg will be covered 1:1 and has urged holders not to sell LBTC at a discount over the counter, but no date for restoring redemptions has been announced.

Date Event
Aug 2 Researcher reports Bug A with two proposed fixes
Sept 1 Bug A fix merged publicly, exposing Bug B
Sept 6 Attacker exploits Bug B, drains about 4,000 BTC
Sept 7 3,400 BTC returned after bridge nodes patched
Sept 10 Block production and transactions resume
Sept 23 Full incident assessment published

The report closes with a direct message to the attacker, urging the return of the outstanding BTC and promising recognition for good-faith discovery. It also commits the federation to a broader governance and security review, with updates to follow as corrective actions are formally adopted. All other Liquid-issued assets, including USDt and DePix, were unaffected, though they were unavailable while the network was paused.

SourcesBlockstream Liquid Network security incident assessment, September 23, 2026; crypto.news; The Bit Gazette; spendnode.io incident coverage.
Share: X