Liquid Network Lost 4,000 Bitcoin in September Attack
A vulnerability in the rangeproof verification cache allowed an attacker to bypass validation and drain reserves.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Do you trust the security of decentralized digital asset networks for your personal holdings?
On September 6, 2026, the Liquid Network suffered a security breach that resulted in the unauthorized withdrawal of 4,000 Bitcoin from its reserves. The network was temporarily halted while developers addressed the exploit.
Why it matters
This incident highlights the operational risks inherent in sidechain bridges, which rely on secure validation logic to maintain parity between locked assets and issued tokens. The event underscores the critical nature of maintaining resilient cryptographic verification caches in decentralized infrastructure.
The attacker exploited a vulnerability in the Elements rangeproof verification cache to create 4,000 unbacked LBTC. These tokens were then moved through the standard peg-out process, reducing the reserve from 4,205 BTC to 197 BTC.
The players
Blockstream
A developer of Bitcoin infrastructure, including the Liquid Network sidechain and mining technology.
Adam Back
The co-founder of Blockstream and a long-time researcher in the field of cryptographic protocols.
The details
The Liquid Network uses 15 geographically distributed functionary nodes, requiring 11 nodes to sign off on a block. By bypassing validation, the attacker moved unbacked LBTC—Liquid Bitcoin, an asset pegged 1:1 to Bitcoin—through the system's peg-out mechanism, which allows users to redeem LBTC for underlying Bitcoin held in the reserve. Blockstream, the entity managing the network, deployed an emergency patch on September 7, 2026, to fix the specific cache vulnerability.
Timeline
September 6, 2026: Liquid Network nodes were halted following an attack.
September 7, 2026: Blockstream deployed an emergency patch.
September 9, 2026: Liquid Network resumed block production.
September 25, 2026: Blockstream assessed 602 Bitcoin remained outstanding.
The Tech Race
The incident follows a recurring pattern of security failures in cross-chain bridges where validation mechanisms are exploited to drain reserve assets. This event serves as a critical stress test for the security of federated sidechain architectures compared to centralized custodial solutions.
Users of the Liquid Network were forced to pause all transaction activity during the three-day maintenance window. While 3,400 Bitcoin have been returned, those holding assets relying on the network's reserve liquidity may face ongoing volatility until full reserve balances are confirmed.
The takeaway
The event serves as a reminder that sidechain bridges remain high-value targets for exploits due to the complexity of maintaining peg parity. Stakeholders should monitor Blockstream for updates regarding the recovery of the remaining 602 Bitcoin.
Further reading
For broader context on protocol vulnerabilities, visit the Cybersecurity section.
Source note: This article includes information reported by Business Standard.
Live Poll
Do you trust the security of decentralized digital asset networks for your personal holdings?






