4,000 Unbacked L-BTC, 3,400 BTC Back
A bug in Elements, the software Liquid runs, let one party create L-BTC with nothing behind it. An automatic peg-out turned that L-BTC into real bitcoin.
6 Sep 2026
At 13:53 UTC the party minted about 4,000 L-BTC and sent it to SideSwap's peg-out. Federation signers released 3,996.02 BTC at 14:28 UTC. Liquid's peg reserve fell from about 4,205 BTC to 197 BTC.
RETURNED, PARTLY
3,400 BTC came back to the Federation's peg wallet on 7 Sep at 16:09 UTC. About 600 BTC is still out. The party is holding it as a self-declared bounty, and Blockstream says it will not pay for the return of stolen property.
LIQUID SINCE
Bridge nodes were halted at 18:26 UTC on 6 Sep, and the incident was disclosed at 20:25 UTC. Blocks resumed on 9 Sep and user transactions on 10 Sep. Blockstream's 23 Sep report says peg-ins and peg-outs are still suspended.
How a Cache Skipped the Check
Liquid hides amounts. Every output carries a range proof that its hidden amount is in range, which is what stops anyone printing coins. Checking those proofs is slow, so nodes cache the ones they have already checked.
THE CACHE
Elements remembers range proofs it has verified, keyed by the data each proof covers. When a new output produces a key that is already in the cache, the node skips the check.
BUG A, 2018
The original key left out the asset commitment and the output script, so it did not cover everything the proof was about. A fix written on 3 Aug 2026 added both fields to the key.
BUG B, IN THE FIX
That fix joined the fields end to end, with no lengths between them. Two different outputs could then produce the same key bytes, with the field boundaries in different places. A valid proof from block 4,050,335 was already cached. The mint in block 4,050,336 matched its key, so its fake proof was never checked.
THE REPAIR
An interim patch reached the bridge nodes at 01:09 UTC on 7 Sep. Elements 23.3.4, released 9 Sep, writes each field with its length before hashing. Steven Roose's summary: joining variable-length fields without lengths is a canonicalisation bug.
SideSwap's Timeline
Times and transaction ids from SideSwap's 9 Sep statement. The mint time and block match Blockstream's report.
BEFORE
3 Aug: the Bug A fix, which is the code that carried Bug B. 12–13 Aug: SideSwap ran a private security build with that fix, and says the build accepted the mint. 1 Sep: the fix was merged publicly, under a title SideSwap says described the bug, before any release contained it.
THE SETUP
5 Sep, 20:55 UTC: a 0.001 BTC peg-in, traced through a bridge to Tornado Cash on Ethereum. Then 70 near-identical transactions, each putting a hidden value on an
OP_RETURN, about 8.8 kB, one input and three outputs. SideSwap calls them rehearsals. The last ran at 13:52 UTC.THE MINT
6 Sep, 13:53 UTC, Liquid block 4,050,336, transaction
f24a4b17…, about 13 kB. A 2.5 L-BTC test peg-out at 14:00, then the 4,000 L-BTC order at 14:05. The Federation paid out in Bitcoin block 965,783, and SideSwap forwarded 3,995.99999857 BTC in that same block.SideSwap's Operating Choices
SideSwap separates the Elements bug from its own choices, which turned a fault on Liquid into an irreversible Bitcoin payment. It says no SideSwap key, wallet, or system was compromised.
ONLINE KEY
The peg-out authorisation key sat online on SideSwap's server, and every Federation payout was forwarded automatically in the same Bitcoin block. Blockstream says the Federation Charter required that key to be offline. SideSwap says an offline key and a manual delay would have let it return the coins.
NO LIMITS
No size limit, velocity control, cap against L-BTC supply, or wallet-age check. An order for about 4,000 L-BTC from a wallet hours old went straight through. SideSwap says the Federation signed it, 11 of 15, without a size check of its own. SideSwap returned its 0.1% fee, about 4 BTC.
The Bounty and the Controls
About 600 BTC is still with the party that minted the L-BTC.
TWO POSITIONS
The party treats the rest as its bounty for finding the bug. Blockstream calls it theft and refuses to pay. Antoine Riard, on Delving on 23 Sep, argues that keeping exploited funds as a self-awarded bounty is theft, and that accepting one after the fact invites extortion.
QUESTION
The August patch closed one cache bug and created the one that was used. What review would catch a cache key built without lengths, and who in a federation is placed to do it?
QUESTION
SideSwap says it has handled 95% of Liquid peg-in transactions since 2021. With one dominant, automatic peg service, what was 11-of-15 Federation signing actually checking?