In September 2026, Liquid Network, a Bitcoin sidechain created by Blockstream, was the victim of an estimated $320 million hack. The attacker took advantage of a flaw in the proof validation code in Elements, an open-source fork of the Bitcoin Core source code that Liquid Network uses.
Inside the Attack
The Liquid Network hack involved the unauthorized minting of approximately 4,000 L-BTC worth about $320 million. These L-BTC were unbacked, meaning that the Liquid Network sidechain accepted them as valid despite the fact that no BTC was locked to back them. Once the fake L-BTC were created, the attacker was able to use the legitimate peg-out process to swap them for BTC on Bitcoin. This accounted for about 95% of the protocol’s total reserve.
The root cause of the incident is believed to be a flaw in the proof verification code that Liquid Network used for Confidential Transactions. The range-proof verification code contained a cache-key collision vulnerability that failed to ensure that range-proofs were unique.
The cache key in question didn’t incorporate the asset ID and script context properly. As a result, the attacker was able to use a legitimate, previously-verified proof to validate another transaction that it wasn’t created for. This enabled the attacker to perform the malicious mint and cash out the stolen BTC.
The vulnerability in the Elements codebase has been detected and patched earlier; however, the patch wasn’t rolled into an official tagged release yet. As a result, nodes running the previous official release of the codebase rather than the very latest version of the code were exposed to exploitation.
Once the attack was detected, Blockstream disabled the affected nodes and halted block production until all the patch had been applied to the entire network. Additionally, exchanges paused L-BTC deposits and withdrawals to help limit the damage. Later, the purported whitehat hacker returned 3,400 of the 4,000 stolen Bitcoin.
Lessons Learned from the Attack
This incident demonstrates the potential risk and implications of supply chain attacks, especially for open-source codebases. In this case, a key vulnerability had been identified and patched within the Elements codebase, making it publicly visible. However, the fact that the patch hadn’t been incorporated into an official release meant that some nodes were running a stale, vulnerable version of the code.
Web3 projects need visibility into their full attack surface and risk exposure, including third-party and supply chain risks. Halborn’s Risk Assessment advisory services provide insight into an organization’s holistic risk exposure. Get in touch to learn more.
