toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trade
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
Be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android version app
More download options

Attacker exploits Liquid bug to withdraw Bitcoin

2026-09-09 02:57

SpotFuturesExploitBTC

An attacker exploited a software flaw in the Elements codebase used by the Liquid Network on Sept. 6, minting roughly 4,000 unbacked Liquid Bitcoin (LBTC) and converting nearly all of it into real BTC through Liquid’s normal withdrawal mechanism. The attacker later returned 3,400 BTC, but about 598.5 BTC—valued at approximately $47 million at the figures provided—remains under addresses they control, with no public agreement confirming it as a bug bounty.

The exploit drained about 3,998.5 BTC from Liquid’s multisignature reserve wallet, or roughly 95% of the wallet’s bitcoin balance at the time. The withdrawals left about 197 BTC in the reserve wallet before the partial return. Blockstream, the company behind the Liquid Network and Elements software, has said it is continuing discussions with the attacker and is seeking recovery of the remaining BTC.

The incident places the focus on the software checks that connect issued LBTC with the BTC held in Liquid’s reserve. Liquid’s 11-of-15 multisig custody arrangement was not breached, according to the account of the incident. Instead, the system authorized withdrawals after fraudulent LBTC entered the peg-out process and was treated as valid.

Fake LBTC passed through a normal peg-out route

The attacker first minted LBTC without the corresponding BTC being deposited into Liquid’s reserve. That counterfeit balance was then submitted to the network’s standard peg-out process, which ordinarily burns LBTC and releases an equivalent amount of BTC from the federation-controlled reserve wallet.

The withdrawals occurred in two transactions. The first moved roughly 2.5 BTC, apparently serving as a test of the exploit. A second transfer then withdrew around 3,996 BTC. Combined, the transactions removed nearly the entire reserve balance available to the peg-out system.

Liquid’s peg-out mechanism is designed to allow LBTC holders to redeem their sidechain assets for native Bitcoin. The process requires approvals from a federation of operators using an 11-of-15 multisig arrangement. At least 11 authorized signers must approve a withdrawal before BTC can leave the reserve.

In this case, the signers appear to have approved transactions that met the formal withdrawal requirements, while the underlying system failed to reject invalid LBTC. The episode shows that a multisig threshold can secure access to a reserve wallet without independently proving that every asset presented for redemption was validly created.

Blockstream said the exploit did not involve leaked multisig private keys. It also said the peg-out authorization key used by SideSwap, a Liquid-related service, was not stolen. The attacker instead exploited the Elements vulnerability to create invalid LBTC, then used the intended burn-and-withdraw workflow to obtain real BTC.

On-chain contact led to a partial return

After moving the funds, the attacker placed a message in a Bitcoin transaction using OP_RETURN, a field that can store a small amount of arbitrary data on the blockchain. The message said: “we are whitehats. contact us on chain.”

Blockstream responded by sending 1,000 satoshis to an address associated with the attacker and requesting contact. Communications subsequently continued through Bitcoin OP_RETURN messages, PGP signatures and encrypted notes.

The attacker said that most of the funds would be returned once a fix had been deployed, and requested that bridge nodes be upgraded before a repayment. Following a signed message stating that bridge nodes had been fixed, the attacker returned 3,400 BTC to the Liquid multisig wallet on Sept. 7.

The remaining approximately 598.5 BTC was moved to another address controlled by the attacker. Public messages visible on-chain did not include a settlement granting the attacker permission to keep those funds or defining them as a security reward. Blockstream’s latest incident update treats the balance as recoverable assets and says discussions remain ongoing.

That distinction leaves the episode in a different category from a conventional disclosed vulnerability and paid bug bounty. Security researchers commonly demonstrate exploits with limited funds or coordinate disclosure before taking user-backed assets. Here, the attacker obtained control of almost 4,000 BTC before opening communications and has retained a substantial portion following the partial repayment.

Urgent patch targets invalid peg-outs

Blockstream has planned an urgent Elements v23.3.4 release to address the vulnerability. Functionary operators, which help run Liquid’s federation infrastructure, are expected to modify network behavior so invalid peg-outs are rejected before ordinary service resumes.

Liquid had not fully returned to normal operations in the latest update, and Blockstream had not set a confirmed timetable for complete restoration or recovery of the outstanding BTC. The response will likely be closely watched by institutions and services using the sidechain for settlement and asset issuance.

Launched in 2018, Liquid is a Bitcoin sidechain designed for faster and more confidential settlement between participating entities. It also supports issued assets, including stablecoins and tokenized securities. The number of entities involved in Liquid’s governance and operations has risen from 23 to 87, while the value of real-world assets issued on the network has surpassed $5 billion, according to the supplied figures.

The exploit does not indicate that Bitcoin itself was compromised. The BTC withdrawn came from Liquid’s own federation reserve, where bitcoins are held to back LBTC circulating on the sidechain. Yet the loss demonstrates how a flaw in the asset-validation path can undermine a bridge’s backing even when the reserve wallet’s signing keys remain secure.

The next operational test for Liquid is whether its patched software and federation procedures can restore confidence that every redeemed LBTC corresponds to BTC actually held in reserve. Recovery of the remaining 598.5 BTC would reduce the direct reserve shortfall, while the handling of the attacker’s claimed white-hat status will shape how the incident is viewed across the security community.


Concerned about bridge hacks and sidechain risks? Deepen your security knowledge with this crypto security breaches guide now.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trade
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.