Security Incident · Live Updates

Liquid Network $320M Security Incident: Full Investigation

Approximately $319 million in was abnormally withdrawn from the Liquid Network Federation reserve. The attacker exploited an Elements software vulnerability to create L- without real backing, then redeemed it for real through the normal exit process. The attacker自称 "white hat" and returned about 85% of funds after the vulnerability was patched, but approximately 598.5 remains unreturned.
Event date: September 6, 2026 Latest update: September 15, 2026 Blockchain Infrastructure / Sidechain / Software Vulnerability
Initial Outflow
$319M
≈ 4,000
Withdrawn
4,000
~95% of reserves
Returned
85%
≈ 3,400
Outstanding
$47M
≈ 598.5

Fund Recovery Progress

85% Returned
85%
15%
3,400 Returned 598.5 Outstanding
Attack Flow
Software vulnerability (Elements transaction validation)
Create L- with no real backing
L- enters normal transaction / exit flow
System accepts transaction as valid → Peg-out
Real flows out of Federation reserve wallet (≈4,000 )

Chainalysis notes that the attacker exploited a Liquid transaction validation software vulnerability, not a private key leak. The system validated an asset that was cryptographically valid but economically shouldn't exist.

Timeline
Sep 6, 2026
Security incident occurs

Attacker exploits vulnerability to create unbacked L-, withdrawing approximately 4,000 via normal Peg-out, valued at approximately $319 million.

Sep 7, 2026
Vulnerability patched & partial return

Liquid completes software patch; attacker self-identifies as "white hat" via on-chain message, returns approximately 3,400 (85%).

Now · Sep 15
Network remains paused

Peg-in/Peg-out suspended, approximately 598.5 not yet returned, L- redemption mechanism not restored.

Why This Attack Is Particularly Dangerous

  • No private key theft or multisig compromise detected
  • Attacker exploited asset issuance/validation logic flaw
  • Trust chain: reserve → L- → Elements validation → Peg-out
  • "Code security" ≠ "asset security"

Current Fund Status

  • Initial reserves: ≈ 4,200
  • Abnormal withdrawal: ≈ 4,000 (95% of reserves)
  • Returned: ≈ 3,400 (~$272M)
  • Outstanding: ≈ 598.5 (~$47M)
Expert Perspective & Industry Reflection

This incident does not mean the network itself was compromised. What is truly challenged is the trust model between sidechain asset issuance, validation, and redemption.

The Liquid incident reminds the market that when enters other systems through sidechains, wrapped assets, or bridges, the risk investors bear is no longer entirely equivalent to directly holding . The industry needs to re-examine the gap between "code security" and "economic security."

#LiquidNetwork #SidechainSecurity #Wrapped
⚠️ L- Holder Risk Alert

Peg-out remains suspended, and L- cannot currently be redeemed for . The implied backing ratio is approximately 86%, but Liquid has not yet announced a final plan for handling the shortfall. Do not send to the paused Liquid Network, and beware of secondary scams such as "official refunds" or "seed phrase verification."

Recommended balance check: Blockstream Green, Aqua, SideSwap, exchange accounts.

Primary sources: Reuters, Chainalysis, TRM Labs, The Block Page updated: 2026-09-15 14:30 UTC