
An attacker exploited a caching flaw in Liquid Network to create 4,000 ghost BTCs, returned 3,400 after implicit trading, but kept 598, or nearly $47 million, while the network remained shut down and the price of Bitcoin barely moved.
AI-generated summary
Liquid Network est une sidechain de Bitcoin permettant des transactions plus rapides et confidentielles. Elle repose sur une fédération de nœuds qui gère la réserve de BTC garantissant les L-BTC en circulation. Une faille dans la vérification des preuves de plage (range-proof) a permis la création de L-BTC sans couverture réelle.
Render to Caesar the things that are Caesar's. The Liquid Network robber has rewritten the formula in his own way: he restores the essentials and keeps the tithe. Two days after emptying 95% of the federated reserve of this Bitcoin sidechain, the attacker returned 3,400 of the approximately 4,000 BTC stolen from Blockstream. Of the 320 million dollars stolen on Sunday, around 268 million therefore found their way back to the federation. The rest, 598 bitcoins, or nearly $47 million, is still in the wallet of the person who presents himself as a “whitehat”.
Return to the starting point. Sunday, September 6, a caching bug in the range-proof verification of Elements, the software that runs Liquid Network, made it possible to create L-BTC without the slightest bitcoin as collateral behind it. The hacker first tests the flaw with around 2 BTC. It's happening. He followed that up with nearly 4,000 phantom L-BTC, converted into real bitcoins via SideSwap's exit service. The federation's reserve, which was close to 4,200 BTC, fell to 197 BTC. No private keys were stolen. It was the token issuance logic that failed, not the safe.
The attacker left an on-chain message translated from English: “We are whitehats. Contact us on-chain. » A facade of good citizenship that Charles Guillemet, technical director of Ledger, did not really buy, “an ethical hacker does not clear a bridge before proposing a discussion” he even specified. Blockstream cut the bridge nodes immediately. L-BTC was under-collateralized, but the other assets, issued natively on the sidechain (USDT, DePix, tokenized assets), did not leave the chain. Frozen too, it was not siphoned off. Trust suspended, sidechain stopped.
Bitcoin (BTC): remote trading and partial restitution
What could have turned into a standoff was resolved behind the scenes. Blockstream fixes the bug, patches its nodes, then signals to the attacker that the ground is “safe” to return the funds. Something promised, thing half-delivered: Monday, 3,400 BTC left for the federation’s address. The attacker, who had set a condition before returning anything, pocketed a little more than 15% of the loot in the process. A ransom-style tithe, negotiated without a single word having been exchanged off-chain.
Bitcoin did not flinch. The price remained around $79,500 at the time, barely 0.5% down. The market read the story for what it is, a sidechain accident, not a breach in the Bitcoin protocol itself.
The transaction circulating on mempool.space and which we take as proof of reimbursement shows nothing of the sort. Two inputs, four outputs, 598.49954242 BTC which goes almost entirely back to the original address. A simple movement of funds to one's own wallet, coupled with an encrypted PGP message hidden in an OP_RETURN output. The figure actually fits right with the 598.5 BTC that the attacker kept, not with the 3,400 returned to the federation.
Enough to temper the idea of a repentant Christmas story version. The network, for its part, remains at a standstill: deposits and withdrawals suspended from exchanges, bridge nodes deactivated, no recovery schedule announced.
AI outlook — possibilities, not facts
Blockstream publiera un rapport détaillé sur la faille et les correctifs appliqués dans les jours à venir.
Likely · Within days
Les exchanges maintiendront la suspension des dépôts et retraits de L-BTC jusqu'à ce qu'un audit de sécurité indépendant soit effectué.
Likely · Within weeks

The G7 published a report on September 3, 2026 calling for immediate preparation for post-quantum cryptography, due to the “harvest now, decrypt later” threat. Bitcoin, Ethereum and Solana are directly affected, their infrastructures being in the crosshairs despite the absence of frontal targeting of cryptocurrencies. Developers are working on solutions like BIP-360 for Bitcoin, while Ethereum and Solana are testing post-quantum fixes, although the computing power required remains speculative at this time.

Vitalik Buterin considers the thesis that AI could break the security of Bitcoin unfounded. It distinguishes easily correctable software vulnerabilities from the cryptographic robustness of SHA-256, while emphasizing the difficulty of social consensus.

Jensen Huang, boss of Nvidia, proclaimed the arrival of artificial general intelligence on X following the launch of GPT-6 Astra by OpenAI, trained on more than 100,000 Nvidia GPUs.

Nearly 4,000 bitcoins (around $320 million) were removed from Liquid Network's bridge via a potential vulnerability in Elements software. The attacker presents himself as an ethical hacker, a version disputed by Ledger.

The SEAL organization publishes a repository on cyberattacks targeting crypto developers. Faced with the compromise of workstations, as during the hacks of Bybit and Radiant Capital, the guide recommends strict compartmentalization of environments.

The threshold of logical qubits needed to break Bitcoin's cryptography has fallen to 813, according to the ecdsa.fail ranking. Faced with this threat, Circle has released a new monitoring tool to assess quantum risk.