AI Identifies $320M BTC Exploit, Raises Questions About Payout Limits
On September 6, 2026, an unknown attacker exploited Liquid's federation to withdraw $320 million in BTC. The withdrawal was facilitated by a bug in the Elements software underlying Liquid that allowed invalid L-BTC to be accepted as valid Bitcoin payments.
The Elements software caches successful checks of cryptographic proofs attached to confidential transactions. However, a September 1 code change concatenated asset generator and output script fields without encoding their boundaries. This created a situation where different verification requests could produce identical cache input.
Alpen Labs CEO Simanta Gautam claims that his AI agents were able to identify the flaw and reproduce it locally in about an hour after he heard of the September 6 attack. However, this speed does not necessarily mean that a standing AI monitor would have raised an actionable warning before the attack occurred.
A payout limit or other independent hold could have stopped the withdrawal even after Liquid admitted invalid state. SideSwap, which had its peg-out service used by the attacker, says it forwarded 3,995.99999857 BTC to the customer's address in the same Bitcoin block.