Liquid Network, the Bitcoin sidechain run by Blockstream, lost 3,996 BTC on September 6, worth about 320 million dollars. Nobody stole a private key. The 11-of-15 federation that guards the peg signed the payout the way it signs any other, because the coins leaving looked legitimate to the software checking them.
That is the part worth sitting with. No phishing, no leaked seed, and both Blockstream and the trading venue SideSwap confirmed that no signing key gave way. It inverts the pattern for 2026, a year in which stolen keys drove most of the losses. Here the keys held. The money still walked out.
A cached proof got reused
The flaw lived in Elements, the node software behind Liquid Network. Confidential transactions on the sidechain hide amounts behind a rangeproof, math that proves a hidden number sits in a valid range without showing it. Elements cached proofs it had already verified, and the cache key left out the asset and script context. So one verified proof could be replayed against a different output, and some nodes accepted L-BTC that nothing backed.
At 14:05 UTC a customer sent 4,000 L-BTC to SideSwap for a peg-out. SideSwap burned the tokens, and 23 minutes later the federation released 3,996.01 BTC on the Bitcoin mainchain. On paper the burn and the release cancel out. Underneath, the bug had conjured those L-BTC, not any buyer. Developers had merged a fix days earlier, but nobody cut it into a tagged release, so Liquid Network still ran the vulnerable build. The Cosmos stack had its own version, where a bug reported in April was still live when six chains fell months later.
What 197 BTC leaves behind
The federation held roughly 4,200 BTC before the peg-out. After it, 197. About 95 percent of the reserve gone in one afternoon. Liquid Network halted new transactions on September 7, and exchanges froze L-BTC while the federation built a patch. The drain was large enough to swallow the week's other incidents, including a dormant Notional Finance contract that lost 1.7 million dollars.
The L-BTC still circulating is the open question. The burn removed 4,000 tokens, so the token-to-reserve ratio holds in theory. In practice a peg standing on 197 BTC has almost no room to meet redemptions once peg-outs reopen, and analysts warned L-BTC could slip below parity with Bitcoin.
The white hat did it backwards
Whoever moved the funds left on-chain messages calling themselves a white hat, offering to return most of the coins if Liquid Network patched every node first. The federation answered in an OP_RETURN in block 965,875:
Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.
Ledger chief technology officer Charles Guillemet pointed out that the order was backwards. Convention says you report a flaw quietly and let someone patch it before anyone touches a large reserve. None of the 3,996 BTC had returned as of the latest reports. Code flaws like this make up around 60 percent of crypto hacks but a far smaller share of the money lost, because the biggest thefts still trace back to broken key custody, not broken logic. Liquid Network is the costly exception: a federated chain sold as more controlled than an open one, drained almost dry while every signer acted correctly.