Blockstream exploit exposes core flaws in federated custody
- A software caching bug allowed an attacker to siphon 4,000 Bitcoin from Blockstream's Liquid network.
- Federated multi-signature signers failed to stop the exploit because all 15 nodes ran identical unpatched code.
- Blockstream backstopped a 600 Bitcoin deficit after the hacker returned most funds but kept a $48M ransom.
A single invalid proof wiped out $320 million in digital reserves.
An attacker exploited a caching flaw in the Elements consensus engine, generating 4,000 fake Bitcoin on Blockstream's Liquid network out of thin air. The vulnerability stemmed from code released on September 1, 2024, that attempted to patch an older 2018 range proof flaw. To save processing power, the validation code cached proof results without recording asset types or spending conditions. That missing context let forged proof data pass validation, creating phantom tokens that passed seamlessly into real circulation.
The breach exposed a structural weakness in federated security models. Liquid relies on an 11-of-15 multi-signature setup spread across independent institutions. However, because every federation node ran the same unpatched software update, all eleven signers reached the identical false conclusion. SideSwap accepted the forged assets, and the federation signers authorized a peg-out of nearly 4,000 real Bitcoin without a single node flagging the anomaly.
On Ungovernable Misfits on September 8, 2026, hosts q and a walked through how centralized software development effectively neutralizes multi-signature protections. Independent federation entities simply trusted Blockstream’s software update without performing independent code audits. Public code repositories revealed that a pull request fixing the caching logic had sat open since early September, but the exploit hit before nodes merged the fix.
"Centralized software consensus broke multi-sig security in seconds."
- q and a, Ungovernable Misfits
Following the exploit, the attacker used encrypted OP_RETURN payloads to negotiate directly with Blockstream over the Bitcoin blockchain. Pretending initially to act as a white hat, the thief returned 3,400 Bitcoin once nodes patched the underlying vulnerability. They retained nearly 600 Bitcoin - worth roughly $48 million - as an unnegotiated 15 percent ransom fee, ending on-chain dialogues with a single emoji before walking away.
On Bitcoin And on September 8, 2026, host David Bennett pointed out that automated AI tools have permanently altered protocol security. Continuous vulnerability scanners now parse open-source code repositories to generate functional exploits faster than human engineering teams can audit their own software. This asymmetry turns minor caching shortcuts into instant multi-million dollar liquidity events before human operators notice the flaw.
"Automated tools now scan code repositories continuously to construct exploits faster than human auditors can identify flaws."
- David Bennett, Bitcoin And
Three days later on Presidio Bitcoin Jam on September 11, 2026, discussion turned to the systemic aftermath and Blockstream CEO Adam Back's commitment to maintain the sidechain's one-to-one peg. Blockstream and its financial partners pledged to backstop the remaining 600 Bitcoin deficit out of pocket. Yet commentators noted that relying on corporate bailouts undermines the core premise of trust-minimized federated networks.
Federated custody promises security through distributed governance, but identical software dependencies reintroduce single points of failure. Until federations mandate diverse software implementations and independent code audits, multi-signature scripts offer little real defense against unified protocol bugs.
Shared code turns decentralized signers into a single compromised key.
Source Intelligence
- Deep dive into what was said in the episodes
Blockstream Liquid's $320M Hack, Open Source AI Summit Takeaways, Vora Reveal • Sep 11
- Blockstream Liquid was hacked for 4,000 BTC after an attacker exploited an inflation vulnerability. The exploit resulted from a flawed code patch released on September 1, 2024, which attempted to fix an older 2018 range proof vulnerability.
- Adam Back announced the Liquid network peg will remain one-for-one. Blockstream and its partners are plugging the remaining 600 BTC deficit after the hacker returned 3,400 BTC through encrypted OP_RETURN negotiations, keeping 15 percent as an unsolicited bounty.
Also discussed on this episode: (6)
Protocol (1)
- The Liquid exploit exposed structural risks in federated sidechains, where members blindly run software updates without auditing the code. The attacker bypassed security controls by exiting through Sideswap, a federation member that lacked KYC or transaction velocity controls.
Safety (1)
- An Anthropic employee's public exit over existential AI risk was an orchestrated media campaign designed to trigger regulatory capture. David Sachs argues that coordinated media coverage and political reactions aim to build regulatory barriers that protect closed labs while stifling open-source models.
Open Source (1)
- Attempts to restrict open-source AI development in the United States fail to account for China's pro-technology momentum. David Sachs points to data showing 83 percent of China's population holds a positive sentiment toward AI, viewing it as an economic tool rather than an existential threat.
Models (1)
- Ramez Naam demonstrated that OpenAI's technological lead has collapsed from 20 months in 2022 to just five months. This rapid convergence shows that AI development is heading toward a plurality of models rather than a single monopolistic winner.
Agents (1)
- Open protocols are essential to prevent vendor lock-in as autonomous AI agents proliferate. Builders at the summit highlighted open-source memory protocols as a critical mechanism to let users export their local context and memory across different models.
AI Infrastructure (1)
- Vora revealed its local AI hardware device featuring a mid-century wooden aesthetic and 64 gigabytes of RAM. The device serves as a local security membrane, allowing users to store memory and context locally while securely managing API calls to external cloud models.
4000 BITCOIN HACKED | THE BITCOIN BRIEF 89 • Sep 8
- An attacker drained nearly 4,000 Bitcoin from the Liquid Network after exploiting a software bug that accepted fake liquid Bitcoin as valid. Side swap accepted the coins, and the federation processed a peg-out of roughly 3,996 Bitcoin to the attacker.
- The Liquid federation's 11-of-15 multi-sig custody structure failed to stop the exploit because the underlying software validated the fake coins first. Since all signers ran the same faulty Elements code, they reached the same incorrect validation conclusion.
- The attacker communicated with Blockstream via on-chain OP_RETURN and PGP-encrypted messages, claiming they would return the funds once all nodes are patched. Max remains skeptical of a return, while q and a expects the attacker to comply.
Also discussed on this episode: (11)
Protocol (1)
- The Liquid exploit targeted a validation shortcut in the Elements software cache. The cache verified range proofs without validating asset types or spending conditions, allowing the attacker to bypass cryptographic checks with an invalid output that matched a cached description.
Coding (1)
- Orange Surf reports that the vulnerability was publicly exposed when a patch pull request sat open starting September 1. The attacker likely identified the unmerged bug fix and immediately exploited the live network.
Custody (4)
- Foundation released KeyOS 1.4 for Passport Prime, enabling app sideloading verified by developer certificates. The update allows custom security profiles, with plans for a whitelisted and vetted Foundation App Store to aid less technical users.
- Chilean exchange OrionX halted withdrawals after a forensic audit revealed $7 million in customer crypto was missing. Founding partners are accused of conducting unauthorized speculative trading with user funds without operating licenses between 2018 and 2021.
- The hacker responsible for the Wave 3 Coldcard exploit moved roughly 20.5 Bitcoin into Ethereum via Thorchain swaps. This constitutes slightly over 1 percent of the total 1,789 Bitcoin stolen during the exploit.
- Cake Wallet 6.4.4 added native Trezor support for cold storage, while Nunchuk added BitBox02 Bluetooth connectivity. Additionally, RoboSats Alpha 0.87 added three new coordinators and encrypted image uploads through Noster Blossom servers.
BTC Markets (1)
- CoinDesk reports that the Bitcoin-backed mortgage product offered by Better and Coinbase allows the lender to rehypothecate borrower collateral. This gives Better the right to reuse the pledged Bitcoin in secondary financial agreements, introducing additional counterparty risk.
Privacy (2)
- Trezor's shipping partner, ShipMonk, leaked customer records of approximately 67,000 US customers, bringing the total exposed to 80,000. The leak included names, physical addresses, phone numbers, and email addresses, highlighting shipping data risks.
- Pocket Bitcoin suffered a support system breach that exposed compliance records for 291 EU customers and bank transfer details for over 5,000 users. This breach directly links real-world identity data to public Bitcoin transaction histories.
Stablecoins (1)
- Two Thai businessmen are suing Tether for freezing $42.4 million in USDT across ten Ethereum addresses. The plaintiffs allege Tether executed the freeze based on an informal verbal request from Homeland Security, months before a warrant was issued.
Regulation (1)
- The US House canceled its late September voting sessions, narrowing the window to pass the Clarity Act before the midterm recess. A critical procedural vote requiring 60 votes to advance the regulatory bill is set for September 15.

