Liquid Lost 4,000 Bitcoin to a Cache, Not a Key
The biggest crypto hack of 2026 didn't steal a single signing key. It tricked Blockstream's Liquid federation into approving a withdrawal its own software said was valid, then held the last $47 million for ransom.
On September 6, at Liquid block 4,050,336, someone minted roughly 4,000 L-BTC that had no bitcoin behind it. Then they redeemed it for real bitcoin through the front door.
The Liquid Network, the Bitcoin sidechain run by Blockstream and a federation of exchanges and trading firms, lost about $319 million in BTC in the process, according to blockchain analytics firm TRM Labs. TRM ranks it as the largest theft of 2026, ahead of April's KelpDAO ($292 million) and Drift ($285 million) breaches.
Most of it came back. What matters is how it left.
No key was stolen
Liquid's security model rests on a federation. Bitcoin locked on the main chain sits in an 11-of-15 multisig controlled by functionaries run by federation members. To move BTC back out, a user burns L-BTC on the sidechain and the federation signs the payout.
Blockstream says no signing key was compromised. None needed to be.
The flaw lived in Elements, the open-source software Liquid runs on. Verifying range proofs, the cryptography that hides amounts in Liquid's confidential transactions, is computationally expensive, so Elements caches the results. According to Liquid's incident report, the attacker exploited how nodes cache those verifications, getting invalid outputs accepted as if they had already been checked. TRM notes the attacker broadcast dozens of Liquid transactions carrying matching proof data before the strike, setting up the pattern the cache would later trust.
The unbacked L-BTC then went through SideSwap, a federation member that holds a peg-out authorization key, via Liquid's standard peg-out process. SideSwap says the vulnerability was in Elements, not its own systems. TRM's timeline puts the whole sequence, from mint to the federation approving a payout of roughly 4,000 BTC, at about 36 minutes.
The federation did exactly what it was built to do. It checked the chain state its software reported, found it valid, and signed.
The "white hat" who kept 15%
The attacker's first message was embedded in a Bitcoin transaction's OP_RETURN field: "we are whitehats. contact us on chain."
What followed was an encrypted negotiation carried out on-chain. Blockstream disabled affected nodes, halted block production, and pushed a fix. On September 7, a PGP-encrypted message arrived attached to a 1,000-satoshi transaction; 38 minutes later, about 3,400 BTC came back, according to The Hacker News. The attacker kept 598.5 BTC, worth roughly $47 million.
Then came the invoice. A later OP_RETURN message demanded that Blockstream pay a 10% bounty out of its own funds, claimed the company had spent $1.5 million protecting $5 billion in assets, and warned that refusal would "cause all your holders a 15% loss."
Blockstream's answer on September 11 was blunt. "Return the bitcoin," the company said, calling the withholding "a crime, not responsible disclosure" and adding: "It is not white-hat activity. It is theft." It said it will not pay for the return of stolen property and is working with law enforcement, exchanges, and forensic firms to trace the rest.
That is the right call, and it is not a costless one. Blockstream CEO Adam Back has said in posts on X that "the 1:1 LBTC to BTC peg will be covered" and told holders "Do not panic sell OTC." Neither he nor the company has said how the shortfall will be funded or when redemptions reopen. TRM estimated L-BTC's backing at roughly 86% after the drain.
A patch, a restart, and a peg that isn't open
Blockstream deployed Elements v23.3.4 on September 9. Block production resumed on September 10. Peg operations, including PAK-authorized peg-outs, remain suspended.
That leaves Liquid in an awkward state: a live sidechain whose core promise, that one L-BTC is always redeemable for one BTC, is currently a pledge rather than a mechanism. The pledge is credible only as far as Blockstream's balance sheet is. Until the peg reopens, L-BTC is a claim on a company.
What this actually means
The industry spent years arguing about federations versus trust-minimized bridges almost entirely in terms of key custody: how many signers, how independent, how geographically distributed. Liquid's answer was a large federation of regulated businesses and a high signing threshold. Gizmodo reports the federation has more than 80 members, with 15 running functionaries.
This exploit walked past all of that. Fifteen independent signers running the same validation software are not fifteen independent checks. They are one check, replicated fifteen times. A multisig threshold protects against a signer going rogue. It does nothing when every signer is faithfully executing the same bug.
The lesson applies well beyond Liquid. Every bridge, rollup, and sidechain with a committee or federation should be asking the same question: what does our signer set actually verify, and does any of it depend on a single client implementation? Client diversity is standard doctrine for Ethereum's validators precisely because a consensus bug in a supermajority client is a network-wide failure. Federated bridges have mostly not held themselves to that standard.
The ransom dynamic is the second problem, and it is getting normalized. When protocols routinely pay attackers a percentage to return funds, "white hat" becomes a pricing tier for theft. Blockstream refusing to set that precedent matters more than the $47 million it costs.
The read
Liquid will likely survive this. Most of the funds are back, the bug is patched, and Blockstream's CEO has publicly pledged that the peg will be covered.
The things to watch are concrete. First, when peg-outs reopen and whether every L-BTC holder can actually redeem at par. Second, how the 598.5 BTC gap gets filled, and whether that comes from Blockstream or somewhere else. Third, whether the federation adds a second, independent validation path before signing peg-outs, because without one, the next caching bug gets the same 36 minutes.
