The Liquid Network recovered 3,400 Bitcoin—valued at approximately $268 million—following an exploit that drained roughly 4,000 BTC from the Liquid Federation wallet on Sept. 6. The actors retained 598.5 BTC, worth $47 million.

The incident gutted Liquid's reserves: the 3,996 BTC withdrawn represented 95 percent of the network's Bitcoin holdings, leaving only 197 BTC. Blockstream, Liquid's primary develo patched its bridge nodes and signaled to the actors that funds were "safe to return." The 3,400 BTC were subsequently broadcast to the federation address at 14:28 UTC.

No federation keys were compromised. Sideswap, the peg-out service involved in processing the withdrawal, confirmed its systems remained intact. The vulnerability originated from Elements, the Bitcoin Core fork powering Liquid nodes: a range-proof verification cache bug that allowed attackers to generate L-BTC without the underlying Bitcoin collateral normally required.

The mechanics reveal a critical structural weakness. Attackers conducted a 2.5 BTC test run, then broadcast approximately 4,000 unbacked L-BTC to Sideswap's peg-out service at 14:05 UTC on Sept. 6. Sideswap processed the withdrawal request as valid, burning the L-BTC and initiating the outflow. Liquid's federation signers executed the transaction as designed—the fundamental failure occurred at issuance, not custody. Unbacked tokens entered the system and were never rejected.

Communication between attackers and Blockstream diverged from standard responsible disclosure. The actors initially posted on-chain messages via Bitcoin OP_RETURN stating "we are whitehats. contact us on chain." Blockstream responded with PGP-signed messages, and the actors agreed to return funds once the network was secured.

The "white-hat" framing remains disputed. Ledger CTO Charles Guillemet questioned the tactic of draining funds first and negotiating later, though he later noted the actors could be inexperienced researchers. Liquid itself has referred cautiously to them as "purported white-hat hackers." The retention of 598.5 BTC without an explicit bounty agreement—a departure from standard white-hat protocols—compounds skepticism about their true motivations.

Liquid's operational status remains severely constrained. The network is paused, with bridge nodes disabled. L-BTC deposits and withdrawals at centralized exchanges are halted. Other Liquid-issued assets, including USDT, Depix, and real-world assets, were unaffected by the issuance bug.

The exploit exposes a structural vulnerability in sidechain architecture: multi-signature custody mechanisms cannot compensate for flaws in token generation logic. The range-proof verification cache bug allowed attackers to bypass the collateral requirement entirely—no custody theft occurred because the "stolen" Bitcoin never existed as a backed asset. This distinction is material. A federation can secure Bitcoin already in its possession; it cannot validate the integrity of tokens created before they reach custody.

Elements, despite being an established codebase, harbored a critical vulnerability that impacted the financial integrity of a derivative network holding hundreds of millions in assets. The incident underscores the necessity for continuous rigorous auditing of underlying codebases in sidechain implementations. The cost of a single overlooked cache bug in a Bitcoin Core fork manifested as a 95 percent reserve drain.