Liquid Network is working to recover roughly 598.5 BTC after an exploit in its underlying open-source Elements software created about 4,000 unbacked LBTC and enabled the funds to be withdrawn as bitcoin, according to the network’s incident report. The attacker has returned 3,400 BTC to the Liquid Federation peg wallet, leaving about 15% of the affected funds outstanding.
The incident, disclosed after the exploit on Sept. 6, struck Liquid’s peg mechanism rather than the Functionary federation’s signing infrastructure. Liquid said the vulnerability involved the way nodes verify cache-range proofs, allowing invalid issuance activity to pass verification. The newly created LBTC was exchanged through SideSwap and redeemed through Liquid’s regular peg-out process.
Liquid is a Bitcoin sidechain designed to move bitcoin and other assets more quickly between participating entities. LBTC is its bitcoin-backed asset, intended to be redeemable one-for-one for BTC held in federation-controlled reserves. Once the fraudulent LBTC entered the peg-out route, the issue shifted from an invalid token issuance to a reserve shortfall affecting users seeking to withdraw bitcoin.
Reserves fell from 4,205 BTC to 197 BTC
Before the exploit, Liquid held about 4,205 BTC in reserves, the network said. That balance fell to about 197 BTC after the attacker’s peg-outs and additional withdrawals were completed before operations were halted.
The size of the reserve decline demonstrates the pressure a software-level validation failure can place on a federated bridge. Liquid’s reserve pool was sufficient to honor the fraudulent redemption requests until withdrawals were stopped, even though the corresponding LBTC had no bitcoin backing.
Liquid said the attacker identified themselves as a white-hat researcher and returned 3,400 BTC on Sept. 7. Blockstream, the company closely associated with Liquid’s development, said it was discussing recovery of the remaining funds while preparing work to restore the network.
The network said Functionary nodes and their private keys were not compromised. It also said other Liquid-issued assets, including USDT, were unaffected. Those distinctions narrow the immediate technical scope, though users of LBTC remain exposed to the unresolved reserve gap until the missing bitcoin is recovered or otherwise covered.
The episode tests confidence in federated bitcoin bridges
The exploit places fresh attention on the operational assumptions behind wrapped bitcoin systems. A one-to-one peg depends on more than visible reserve addresses; it also depends on the software that validates issuance, the redemption process, and the parties that control the underlying bitcoin.
Federated systems can offer faster settlement and functions that are difficult to implement directly on Bitcoin’s base layer. Their trade-off is that users rely on a defined group of operators and the code governing the federation’s asset rules. Liquid’s disclosure indicates that the federation itself was not breached, but the exploit still allowed bitcoin reserves to leave because the protocol accepted invalid LBTC.
That distinction will likely shape the recovery effort. If the remaining 598.5 BTC is returned, the immediate reserve imbalance could be resolved. If it is not, Liquid will need to determine how redemptions and outstanding LBTC are handled while the network’s software and operating procedures are repaired.
The incident also provides a practical warning for traders using bridged assets in strategies that do not require immediate use of a sidechain. A wrapped token’s market label may imply a fixed relationship with the underlying asset, but redemption reliability ultimately rests on the bridge’s reserves, validation logic and withdrawal controls.
Market activity remained uneven across major tokens
The broader crypto market showed mixed movement during the reported 24-hour period. Bitcoin fell 0.68%, while Ether was nearly unchanged, gaining 0.02%. XRP rose 1.40% and BNB added 1.72%, while Solana and Sui declined modestly.
Zcash led gains among the most actively traded tokens cited in the market snapshot, rising 4.76%, while SOPH fell 17.42%. Smaller-cap tokens posted sharper moves, including gains for OL, ICX, AEON, Polkadot, Cosmos, Cronos and MultiversX.
Meme-token activity also focused on 4Stock, BNC4 and BUILD, according to GMGN tracking cited in the supplied material. A deposit address connected with Four.meme’s 4Stock was estimated to have received 8,965,865 USDC, or about $8.9 million. Since 4Stock had issued BNC4 as its stated one-to-one stock-pegged token, the deposits were attributed to BNC4 minting flows.
Token incentives and fee burns add to a fragmented market
LAPTOP said it would open an airdrop claim window at 8 p.m. Beijing time for 30 days, allocating 20% of total supply to community distributions. Its plan includes 2% for users who incurred losses trading the TRUMP meme token and related assets, 8% for Hunter Biden Substack subscribers as of Sept. 6, and 10% for future distributions determined by Phoenix Veritas Foundation.
Such targeted allocations can rapidly concentrate attention around eligibility criteria rather than a token’s immediate utility. They can also create substantial selling pressure when claims become transferable, particularly where recipients received tokens without a purchase cost.
Elsewhere, Uniswap founder Hayden Adams said UNI’s annualized burn rate, calculated from the preceding seven days, had reached roughly $263 million. The figure suggests elevated protocol fee generation under Uniswap’s burn framework, though a seven-day annualization can change quickly with on-chain trading conditions.
Celero Communications separately announced a $275 million funding round at a valuation above $3 billion, led by Atreides Management, Valor Equity Partners and Alphabet’s CapitalG. The chip startup said it plans to develop technology for demanding data-processing workloads, adding another large private financing to infrastructure supporting AI computing.
For crypto markets, the Liquid incident remains the most immediate test: it shows how rapidly a technical weakness in a pegged-asset system can turn into a shortage of underlying reserves, even without stolen federation keys or a direct compromise of the custody operators.
Concerned about exploits like Liquid’s? Learn how crypto infrastructure and security breaches shape network risk.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
