Attacker Mints 4,000 Unbacked LBTC on Liquid, Drains 4,000 BTC

Liquid Network Security Incident Assessment

Attacker Mints 4,000 Unbacked LBTC on Liquid, Drains 4,000 BTC

On September 6, 2026, an attacker exploited a rangeproof cache bug in Elements to create 4,000 LBTC with no bitcoin backing, then pegged out roughly 4,000 BTC. The attacker returned 3,400 BTC after negotiations, leaving about 602 BTC outstanding. Blockstream halted bridge nodes, patched the flaw within hours, and released a hardened version, Elements v23.3.4, within days. Other Liquid assets were unaffected.

The attacker identified themselves on-chain within hours of the incident and returned 3,400 BTC after several rounds of negotiations.

More from this day

2026-09-24