CYNTRI AIAutonomous DeFi
🔍SEARCH
THE BODY COUNT
HACK DATABASE·

Liquid Network Paid Out 4,000 Bitcoin That Never Existed

A caching flaw in Blockstream's validation software let an attacker mint 4,000 Bitcoin out of nothing on the Liquid Network. The federation's eleven-of-fifteen signers approved the withdrawal because the software told them the coins were real. Thirty-six minutes from mint to payout.

S
SYNTH·Hack Database
Liquid Network Paid Out 4,000 Bitcoin That Never Existed - CMZ investigation
Eleven of fifteen federation signers approved the withdrawal. The coins behind it never existed.

The largest crypto theft of 2026 did not break any cryptography, compromise any key, or forge any signature. It convinced a piece of software that money it had never seen was money it had already checked.

The Liquid Network is a Bitcoin sidechain built by Blockstream and run by a federation of exchanges and infrastructure firms. The mechanism is simple enough to describe in a sentence: lock real BTC in the federation's wallet and receive L-BTC on Liquid, or burn L-BTC and ask the federation to release your BTC back, which it approves through an eleven-of-fifteen multisig.

The complication is that Liquid hides transaction amounts. Confidential transactions mean the network cannot simply read a value and check it, so every confidential output carries a range proof, a cryptographic attestation that the hidden value falls inside a valid bound. Without that proof being verified, a transaction can create spendable value from nothing.

CyntriAI
PREDICTIVE DEFI
Stop chasing yields across five chains.
Cyntri AI agents predict, execute, and rebalance your DeFi positions using advanced predictive models.
ETHSOLARBBASEOP
Read the Whitepaper
cyntriai.org
A Cyntri AI Project

Verifying range proofs is computationally expensive. So Elements, the software that validates the Liquid Network, caches the results. Reconstructions from Bitquery and DeFiPrime, together with analysis from mempool.space developer mononaut, point to a flaw in that cache that allowed an invalid output to be treated as already verified.

In the hours before the attack, the attacker broadcast dozens of Liquid transactions carrying matching proof data, which is consistent with priming that cache. At 13:53 UTC on September 6, 2026, in block 4,050,336, they minted approximately 4,000 L-BTC with nothing behind it.

By 14:06 UTC they had requested a withdrawal through SideSwap, an approved federation operator. At 14:28 UTC the federation paid out about 4,000 BTC, and roughly 3,996 real Bitcoin reached the attacker. Thirty-six minutes from forging the asset to holding the proceeds.

The eleven-of-fifteen signature requirement functioned exactly as designed and approved the payout anyway, because Elements told every signer that the chain state holding the unbacked L-BTC was valid. SideSwap confirmed the fake L-BTC came from an Elements software bug rather than any compromise of its systems. Blockstream confirmed none of its signing keys were compromised. Both statements are true, and the money left regardless.

At roughly $319 million, this is the largest crypto theft of 2026, ahead of the April attacks on Kelp DAO at $292 million and Drift at $285 million, both attributed to North Korea. It is also by far the largest attack ever recorded against a Bitcoin sidechain. Ronin took $625 million, Poly Network $611 million, Wormhole $325 million. What separates Liquid from all three is the mechanism: those came from stolen validator keys, flawed bridge contracts and forged signatures. Liquid's attacker forged the asset itself.

Then, hours after the drain, a message appeared on Bitcoin.

The attacker had embedded eight words in the OP_RETURN field of a transaction: we are whitehats, contact us on chain. They then communicated with the Blockstream team through encrypted on-chain messaging and made an offer. Patch the bug, get every node updated, and the funds come back.

Blockstream patched. On September 7, the attacker returned about 3,400 BTC, roughly $272 million.

They kept 598.5 BTC, around $47 million, which they appear to be treating as a bounty. Nobody agreed to that figure. There was no bug bounty programme with a $47 million tier, no negotiation that settled on fifteen percent, no third party adjudicating what the disclosure was worth. The attacker took the money, named their own price for returning most of it, and the price was whatever they decided not to send back.

The Liquid Network remains paused. Exchanges have not resumed L-BTC trading. Using roughly 3,597 BTC in the identified reserve address against an estimated 4,200 L-BTC outstanding, the implied backing ratio is about 86 percent, though that is not a full reserve-and-liability reconciliation. The federation has not said how it will address the shortfall or when redemptions will resume. Until it does, L-BTC cannot be redeemed at all.

With Liquid included, 2026 has seen roughly $1.73 billion stolen across 333 incidents. The incident count is already a record. The dollar total, annualised at around $2.5 billion, runs below both 2025 and 2022. More attacks, smaller hauls, and occasionally one like this.

TRM labelled the attacker's addresses within a day and continues to track the $47 million that never came home.

The Aftermath

The attacker returned roughly $272 million and kept about $47 million, a figure nobody agreed to and no bounty programme covered. The Liquid Network remains paused with L-BTC redemptions halted and exchanges yet to resume trading. Public figures imply a backing shortfall of around 14%, and the federation has not announced how it will be addressed or when the peg will reopen. Blockstream has patched the Elements flaw. The attackers remain unidentified, their white-hat claim is unverified, and TRM continues tracking the retained funds. This is the largest crypto theft of 2026 and the largest attack ever recorded against a Bitcoin sidechain.

LESSONS LEARNED

!A cache of security checks is a security boundary. Elements cached expensive range-proof verifications, and a flaw in that cache let an attacker forge the asset itself.
!Multisig approves what the software tells it to approve. Eleven of fifteen signers behaved correctly and released 3,996 real Bitcoin against coins that never existed.
!Calling yourself a white hat after taking $319 million and keeping $47 million is not a bug bounty. It is a ransom with better branding.
!A sidechain reserve concentrates enormous value behind one codebase. One validation flaw exposed the entire pool.

COMMENTS

CMZ
END OF FILE
Filed under Hack Database