Overview
- A cache-key bug in Elements allowed attackers to mint unbacked L-BTC and withdraw about 4,000 BTC from Liquid’s federation reserve on Sept. 6 through a peg-out handled by SideSwap.
- After engineers deployed an emergency Elements v23.3.4 patch and updated bridge and functionary nodes, Liquid resumed block production but kept peg-outs suspended while it verifies ledger state.
- The actors returned roughly 3,400 BTC after nodes were patched but retained about 598.5 BTC in attacker-controlled addresses and used on-chain OP_RETURN messages to demand a 10% bounty.
- Blockstream publicly refused to pay the demanded bounty, called the withholding of funds theft, and said it will work with exchanges, blockchain forensics teams and law enforcement to trace and recover the remainder.
- The incident highlights a systemic risk in federated custody models and raises urgent questions about operational safeguards such as peg-out key handling, size and velocity checks, and norms for responsible disclosure.