The Liquid Network posted an incident report on social media platform X on Wednesday, September 9, 2026 and talked about what happened, clarified certain points, elaborated the steps that have been taken as of now and what comes next for the restoration of the network.
On September 6, 2026, at 15:53:10 UTC at Liquid Block 4,050,336, a security breach, where 4,000 LBTC were created without the necessary Bitcoin to back them, was identified. This incident forced the network to go offline. The vulnerability was found in the open source Elements software, specifically in how Liquid nodes handled range proof verifications. Attackers took advantage of this vulnerability and produced unbacked LBTC which seemed legitimate on the network.
The attackers did not get access to the Liquid Federation keys and there was no breach of the functionary operators. The failure happened during transaction validation, before any normal peg-out routine began. The fake LBTC eventually got turned into real BTC using SideSwap, one of the Liquid Federation members holding a peg-out authorization key (PAK).
The Liquid functionaries saw these transactions as valid and processed the peg-outs, releasing roughly 4,000 BTC. Before this happened, the Liquid reserve held about 4,205 BTC. After the exploit and a few more peg-outs went through before everything was stopped, only 197 BTC were left in the reserve.
How the Exploit Affected Liquid’s Bitcoin Reserve
The incident shows how even when private keys stay safe, a software validation error can still do a lot of damage. The report makes clear no keys were lost and no hacks happened to the Liquid Federation functionaries. The peg-out system did exactly what it was designed for. The core issue was that the fake LBTC had already passed transaction validation, letting the later peg-out seem fully authorized.
The group behind the exploit used SideSwap’s services to swap the unbacked LBTC for BTC through the regular peg-out process. Since SIdeSwap’s node and all the distributed Liquid functionary nodes accepted the LBTC as valid, the withdrawal went through a whitelisted Bitcoin address. SideSwap then sent the BTC to an address provided by the attackers.
There was more fallout than just the initial withdrawal. After the major peg-out, some more peg-outs were processed before Liquid Network was paused, reducing the reserve down to 197 BTC from about 4,205 BTC pre incident.
Other assets on Liquid like USDT or other tokens were not affected by this flaw. Still, these assets cannot be accessed because the network has been halted while the investigation, software review and repair work continue. Right now, users can’t transact on Liquid until things are fixed.
The investigation is still going. Blockstream said the incident happened because several unlikely events lined up and managed to get past the system’s usual safeties. More updates are expected soon.
Patch, Fund Recovery and Network Restoration
Blockstream found the vulnerability and patched Liquid’s bridge nodes, completing the work on September 7 at 01:09 UTC. Meanwhile, work on a broader fix for the Elements software has already begun.
Later, the exploiters identified themselves on the Bitcoin mainchain as white hat security researchers and asked for contact about the vulnerability. On September 7 at 16:09:25 UTC, at Liquid block 965,950, they sent 3,400 BTC back to the Liquid Federation peg wallet. About 598.5 BTC, 15% of the lost funds, still had not been recovered when the report was published. Blockstream and the white hat group kept negotiating on returning the rest.
The next step is the emergency release of Elements v23.3.4. Blockstream said the fix is ready and going through a lot of internal and external testing. They expect to release it within about 48 hours.
Once the software update is set, Liquid functionary operators will adjust things further to bring the network back online and return the right network state. Part of this means rejecting the invalid peg-out. The main goal is to get normal operations running again safely, with full 1:1 BTC backing.
For Liquid node operators, the report says to look out for the emergency Elements update and follow the upgrade steps when ready. Regular users do not need to do anything right now to protect their funds. The Liquid Federation, Blockstream, and the white hat hackers are staying in close contact as work continues on getting the network running again.


