Founder Office Hours with Gene Deyev: live on Zoom, Mondays 1 PM ET and Thursdays 2 PM ET. Ask him anything.Ask the founder, live.

Save a seat
Score your asset Talk to us

$320M walked out of Liquid, and most of it walked back

The Elements bug let attackers mint L-BTC that was never backed and redeem it for real bitcoin. Then they wrote to Blockstream in an OP_RETURN field and returned 3,400 BTC.

$320M walked out of Liquid, and most of it walked back

At 13:53 UTC on 6 September, someone minted about 4,000 L-BTC on the Liquid Network with nothing behind it. At 14:06 they asked to withdraw it. At 14:28 the federation paid out real bitcoin. Thirty-six minutes, roughly $320 million, and the largest crypto theft of 2026 so far.

Liquid is the bitcoin sidechain built by Blockstream. Each L-BTC is meant to be a claim on one bitcoin held by the federation, a group of functionaries who approve withdrawals eleven of fifteen.

The bug

The flaw was in Elements, the software Liquid runs on. According to TRM Labs, Elements caches its checks of the range proofs on confidential outputs, and a flaw in that cache let an invalid output carrying unbacked L-BTC pass validation. Before the attack, the attackers broadcast dozens of transactions carrying matching proof data to prepare it. The withdrawal went through SideSwap, and the federation signed because, as far as Elements could tell, the chain was valid.

No signing keys were compromised, Blockstream says, and SideSwap says the same of its own. No CVE has been assigned and the full technical details are not public.

Read that twice: the exploit was a method for creating an unbacked token and cashing it out at par.

Then the strange part

<picture> <source media="(max-width: 640px)" srcSet="/blog/images/liquid-opreturn-2026-09-10-m.png" /> <img src="/blog/images/liquid-opreturn-2026-09-10.png" alt="An OP_RETURN message written into a bitcoin transaction: we are whitehats. contact us on chain" /> </picture>

The attackers wrote that line into the OP_RETURN field of a bitcoin transaction and then negotiated with Blockstream over encrypted on-chain messages. Their condition: patch the bug on every node first. Blockstream confirmed in a signed message that the bridge nodes were patched and "the funds were safe to return."

At 15:31 UTC on 7 September, a transaction arrived carrying 1,000 satoshis and a PGP-encrypted message. Thirty-eight minutes later, 3,400 BTC came back, roughly $270 million. They kept 598.5 BTC, about $47 million, apparently as a bounty. They are still unidentified.

Not everyone accepts the label they gave themselves. Charles Guillemet, CTO of Ledger, rejected the white-hat framing and suggested the coins they kept look more like extortion than a reward.

Where it stands

Liquid is still paused and redemptions are halted. TRM puts the implied backing at about 86%: 3,597 BTC of reserves against roughly 4,200 L-BTC outstanding. USDT and the other assets issued on Liquid were not affected.

What it shows

Two things are true at once. The failure was a backing failure, the same class of problem as a token with nothing behind it, only wearing an engineer's clothes. And the recovery happened at all because bitcoin is a register: the coins were identifiable, the movement was traceable, and there was a counterparty who worked out that giving it back beat holding it.

That is not a happy ending. It is a working ledger.

Sources

  • TRM Labs, timeline, the Elements cache flaw, the OPRETURN message, backing
  • The Hacker News, the negotiation, the return transaction, Blockstream's and Ledger's statements
  • CoinDesk, the return of most of the funds

Two ways in

A post is an argument. A score is an answer.

Twenty-five questions across seven dimensions tell you where your own asset stands.

Prefer email? info@stobox.io.

Score your asset

Free, about eight minutes, and nobody calls you unless you ask.

Score your asset

Or read the rest

348 more posts, newest first.

All posts

Or bring the asset itself – thirty minutes, and we will say if the answer is no.

Stobox Technologies Inc. These are the author’s posts, not legal, tax or investment advice, and not an offer to sell or a solicitation to buy any security. See the privacy summary.