Liquid Network Breach Exposes 4,000 Unbacked Tokens
The Liquid Network suffered a significant security breach on September 6, 2026, after attackers exploited a flaw in its Elements software. The exploit allowed roughly 4,000 unbacked LBTC tokens to be minted and converted into real BTC through the network's peg-out system.
The vulnerability was related to how Liquid nodes cache range proof verifications, and it let attackers create LBTC with no bitcoin reserves backing it. The unbacked tokens were then routed through SideSwap, a Liquid Federation member holding peg-out authorization.
Blockstream confirmed the Liquid Federation has since recovered most of the stolen funds, though 598.5 BTC remains outstanding. Discussions are continuing with the individuals involved in an effort to recover the remaining bitcoin.