Liquid Network Drained of $320 Million in Bizarre Exploit
A $320 million exploit occurred on the Liquid Network on September 6, 2026, when an attacker used a range-proof cache bug to mint unbacked L-BTC and drain 95% of the federation reserve through SideSwap.
The attacker communicated via Bitcoin OP_RETURN messages, declaring 'we are whitehats,' and returned 3,400 BTC after Blockstream patched its bridge nodes, while keeping 598.5 BTC (about $47 million) as a self-declared bounty.
Blockstream confirmed no federation keys were compromised, attributing the exploit to a cache-key collision in the confidential transactions verification logic that had entered the Elements master branch but never appeared in a tagged release.