Hacker News
Liquid Network Security Incident Assessment
On September 6, 2026 an attacker exploited a flaw in Elements’ rangeproof verification cache, creating a single transaction that inflated the Liquid supply by ~4,000 LBTC without corresponding BTC. The attacker moved the unbacked LBTC through a SideSwap peg-out, withdrawing ~4,000 BTC, then returned 3,400 BTC after negotiations, leaving ~602 BTC outstanding. Blockstream halted Liquid bridge nodes, applied an emergency patch, and released Elements v23.3.4 to harden the network.