Price:

Blockstream pledges to backstop 600 BTC Liquid loss

Sep 11, 2026Summary from 2 podcasts.
  • Liquid sidechain lost 4,000 BTC after nodes validated a bad caching proof.
  • The attacker returned 3,400 Bitcoin but kept 600 BTC as an extortion fee.
  • Blockstream CEO Adam Back confirmed partners will cover the remaining deficit.

A single software flaw crushed the security promise of federated Bitcoin sidechains.

On Ungovernable Misfits, hosts q and a walked through how a caching shortcut inside the Elements software allowed an attacker to create 4,000 counterfeit tokenized Bitcoin. Liquid relies on range proofs to conceal transfer values without inflating supply. To save processing time, the consensus software cached successful proofs but omitted critical spending context. When an invalid proof hit the network, eleven federated signers authorized the withdrawal because every node ran the same compromised code.

The attacker routed the forged assets through SideSwap, a federated operator lacking withdrawal limits or identity verification. The federation then executed a standard peg-out, handing over nearly 4,000 real Bitcoin on the main chain. The 11-of-15 multisig arrangement proved useless because every signing node reached the exact same faulty software conclusion.

On Bitcoin And, host David Bennett explained that AI-driven scanning tools are accelerating exploit creation faster than human auditors can patch open-source repositories. The attacker used encrypted on-chain messages to negotiate with Blockstream, eventually returning 3,400 BTC while keeping 598.5 BTC - roughly $48 million - as a forced 15 percent bounty. Negotiations ended abruptly when the hacker sent a single sad-face emoji and walked away.

"Automated tools now scan code repositories continuously to construct exploits faster than human auditors can identify flaws."

- David Bennett, Bitcoin And

The Frontier previously reported on September 10 that negotiations had stalled with 598.5 BTC retained by the attacker. By September 11, the full extent of the code defect came to light on Presidio Bitcoin Jam. The vulnerability originated from a flaw in a September 1, 2024 software patch that attempted to fix an older 2018 range proof issue. A pull request resolving the caching logic had sat unmerged on GitHub since early September before the attacker struck.

Despite the breach, Blockstream CEO Adam Back announced that the Liquid network peg will remain strictly one-for-one. Blockstream and its federation partners are moving to cover the remaining 600 BTC deficit out of pocket. While the financial loss is contained, the incident exposes severe systemic risks in federated multisig architecture. All 15 federation signers implicitly trusted Blockstream’s software update without conducting independent code audits.

Federated custody was meant to eliminate single points of failure by distributing signing keys. Instead, running identical code across all signers created a uniform software single point of failure.

Multisig signers are only as independent as the code that runs them.

Source Intelligence

- Deep dive into what was said in the episodes

Blockstream Liquid's $320M Hack, Open Source AI Summit Takeaways, Vora RevealSep 11

  • Blockstream Liquid was hacked for 4,000 BTC after an attacker exploited an inflation vulnerability. The exploit resulted from a flawed code patch released on September 1, 2024, which attempted to fix an older 2018 range proof vulnerability.
  • Adam Back announced the Liquid network peg will remain one-for-one. Blockstream and its partners are plugging the remaining 600 BTC deficit after the hacker returned 3,400 BTC through encrypted OP_RETURN negotiations, keeping 15 percent as an unsolicited bounty.
Also discussed on this episode: (6)

Protocol (1)

  • The Liquid exploit exposed structural risks in federated sidechains, where members blindly run software updates without auditing the code. The attacker bypassed security controls by exiting through Sideswap, a federation member that lacked KYC or transaction velocity controls.

Safety (1)

  • An Anthropic employee's public exit over existential AI risk was an orchestrated media campaign designed to trigger regulatory capture. David Sachs argues that coordinated media coverage and political reactions aim to build regulatory barriers that protect closed labs while stifling open-source models.

Open Source (1)

  • Attempts to restrict open-source AI development in the United States fail to account for China's pro-technology momentum. David Sachs points to data showing 83 percent of China's population holds a positive sentiment toward AI, viewing it as an economic tool rather than an existential threat.

Models (1)

  • Ramez Naam demonstrated that OpenAI's technological lead has collapsed from 20 months in 2022 to just five months. This rapid convergence shows that AI development is heading toward a plurality of models rather than a single monopolistic winner.

Agents (1)

  • Open protocols are essential to prevent vendor lock-in as autonomous AI agents proliferate. Builders at the summit highlighted open-source memory protocols as a critical mechanism to let users export their local context and memory across different models.

AI Infrastructure (1)

  • Vora revealed its local AI hardware device featuring a mid-century wooden aesthetic and 64 gigabytes of RAM. The device serves as a local security membrane, allowing users to store memory and context locally while securely managing API calls to external cloud models.

4000 BITCOIN HACKED | THE BITCOIN BRIEF 89Sep 8

  • An attacker drained nearly 4,000 Bitcoin from the Liquid Network after exploiting a software bug that accepted fake liquid Bitcoin as valid. Side swap accepted the coins, and the federation processed a peg-out of roughly 3,996 Bitcoin to the attacker.
  • The Liquid federation's 11-of-15 multi-sig custody structure failed to stop the exploit because the underlying software validated the fake coins first. Since all signers ran the same faulty Elements code, they reached the same incorrect validation conclusion.
  • The attacker communicated with Blockstream via on-chain OP_RETURN and PGP-encrypted messages, claiming they would return the funds once all nodes are patched. Max remains skeptical of a return, while q and a expects the attacker to comply.
Also discussed on this episode: (11)

Protocol (1)

  • The Liquid exploit targeted a validation shortcut in the Elements software cache. The cache verified range proofs without validating asset types or spending conditions, allowing the attacker to bypass cryptographic checks with an invalid output that matched a cached description.

Coding (1)

  • Orange Surf reports that the vulnerability was publicly exposed when a patch pull request sat open starting September 1. The attacker likely identified the unmerged bug fix and immediately exploited the live network.

Custody (4)

  • Foundation released KeyOS 1.4 for Passport Prime, enabling app sideloading verified by developer certificates. The update allows custom security profiles, with plans for a whitelisted and vetted Foundation App Store to aid less technical users.
  • Chilean exchange OrionX halted withdrawals after a forensic audit revealed $7 million in customer crypto was missing. Founding partners are accused of conducting unauthorized speculative trading with user funds without operating licenses between 2018 and 2021.
  • The hacker responsible for the Wave 3 Coldcard exploit moved roughly 20.5 Bitcoin into Ethereum via Thorchain swaps. This constitutes slightly over 1 percent of the total 1,789 Bitcoin stolen during the exploit.
  • Cake Wallet 6.4.4 added native Trezor support for cold storage, while Nunchuk added BitBox02 Bluetooth connectivity. Additionally, RoboSats Alpha 0.87 added three new coordinators and encrypted image uploads through Noster Blossom servers.

BTC Markets (1)

  • CoinDesk reports that the Bitcoin-backed mortgage product offered by Better and Coinbase allows the lender to rehypothecate borrower collateral. This gives Better the right to reuse the pledged Bitcoin in secondary financial agreements, introducing additional counterparty risk.

Privacy (2)

  • Trezor's shipping partner, ShipMonk, leaked customer records of approximately 67,000 US customers, bringing the total exposed to 80,000. The leak included names, physical addresses, phone numbers, and email addresses, highlighting shipping data risks.
  • Pocket Bitcoin suffered a support system breach that exposed compliance records for 291 EU customers and bank transfer details for over 5,000 users. This breach directly links real-world identity data to public Bitcoin transaction histories.

Stablecoins (1)

  • Two Thai businessmen are suing Tether for freezing $42.4 million in USDT across ten Ethereum addresses. The plaintiffs allege Tether executed the freeze based on an informal verbal request from Homeland Security, months before a warrant was issued.

Regulation (1)

  • The US House canceled its late September voting sessions, narrowing the window to pass the Clarity Act before the midterm recess. A critical procedural vote requiring 60 votes to advance the regulatory bill is set for September 15.