Glass Ledger

The Liquid Network Exploit: Every Signature Was Valid

Attackers drained about 4,000 BTC from Liquid Network without breaking a single key. Here is how an Elements bug turned a valid peg-out into a $320M hole.

Flow diagram: a dashed box of 4,000 unbacked L-BTC passes a green checkmark gate marked peg-out authorized, exiting as 3,996 real BTC released from the Liquid federation

At 14:05 UTC on Sunday, September 6, 2026, a customer handed 4,000 L-BTC to SideSwap, a member of the Liquid Federation that runs a peg-out service. A peg-out is the ordinary way out of Bitcoin's best-known sidechain: you burn the L-BTC you hold, and the federation releases the real Bitcoin that was backing it. SideSwap checked the request against its Peg-out Authorization Key, found it valid, and burned the tokens. Twenty-three minutes later the federation paid out 3,996 BTC, roughly 320 million dollars, to an address the sender controlled. Nothing was broken into. No key was stolen. Every signature on that withdrawal was genuine, and the wallet that had held about 4,200 BTC was left with roughly 200.

Twenty-Three Minutes on a Sunday Afternoon

By that evening Liquid had disabled its bridge nodes, SideSwap had suspended swaps, peg-ins and peg-outs, and exchanges were halting L-BTC deposits and withdrawals. Other assets issued on Liquid, including USDT, DePix and various tokenized real-world assets, were reported unaffected. Then the story turned strange. The party holding the Bitcoin wrote a message into a Bitcoin transaction: "we are whitehats. contact us on chain." Blockstream, Liquid's technology provider, answered about an hour later with a security contact address, and the two sides began trading PGP-signed messages embedded in Bitcoin blocks, in public, one confirmation at a time, while 3,998.5 BTC sat unmoved.

How the Liquid Network Exploit Produced Bitcoin Nobody Had Deposited

Liquid's design is meant to hold exactly one BTC in federation reserve for every L-BTC in circulation. Burn the token, release the coin, and the ratio holds. The Liquid Network exploit did not attack that accounting directly. According to SideSwap and Blockstream, a bug in Elements, the open-source software Liquid runs on, allowed L-BTC to be created that no Bitcoin had ever backed. Those tokens were not counterfeit in any way the system could see. They existed on the sidechain, they were spendable, and when they were presented for redemption they burned exactly like legitimate ones. The fraud happened before the Bitcoin transaction was ever signed, which is precisely why nothing downstream caught it. Every check that ran, ran correctly on inputs that were already wrong.

Eleven Valid Signatures on a Withdrawal That Should Not Have Existed

Blockchain security firm Bitslab reported that at least 11 of Liquid's 15 functionaries ultimately signed the payout. That number is the part worth sitting with. This was not one compromised operator or one careless signer. It was a supermajority of an intentionally distributed federation, each member independently doing its job, each one seeing a burn that looked real and an authorization that was real, and each one arriving at the same wrong answer. Distributing a decision across fifteen parties protects against a dishonest or compromised minority. It does nothing at all when every party is honest and every party is reading from the same corrupted premise. The signatures were not a failure of the signers. They were a faithful execution of a lie told upstream.

The Patch That Already Existed

There is one more detail, and it is the one most likely to sting for anyone who runs infrastructure. Blockstream has not published a technical explanation of the bug, but a fix for it had reportedly been added to Liquid's underlying software about five weeks before the withdrawal. The hole was known and closed in code while remaining open in production. The people holding the Bitcoin then made patching their condition for returning it: fix the bug, they said, and make sure every node is updated, because the chain is still at risk. Blockstream's public reply of "Yes, thank you" was confirmed in the same block as that condition and, as Jan3 chief executive and former Blockstream strategy chief Samson Mow pointed out, appeared to answer an earlier question about the return address rather than the demand itself. At the time of writing no funds had come back and no independent postmortem had been published.

What the Liquid Network Exploit Does and Does Not Say About Your Mining Pool

A sidechain federation and a mining pool are different systems solving different problems, so the honest lesson here is narrow rather than sweeping. It is not that federations are bad, that multisig is theater, or that Liquid users will lose money, since most of the Bitcoin may well be returned. It is simpler and more uncomfortable than that. When a system holds your Bitcoin on your behalf, the question that matters is not how many parties must agree before it moves. It is whether any of those parties can independently verify the thing they are agreeing about. Fifteen signers checking the same unverifiable claim are, for this purpose, one signer. The same question applies to a mining pool that holds a balance for you between blocks, regardless of how carefully it is run.

Where NexusPool's Non-Custodial Design Actually Differs

NexusPool answers that question by not holding the reward at all. A found block's coinbase transaction pays the miner's own address directly, with 0% pool fee, so there is no pooled reserve to reconcile, no balance to withdraw, and no moment where a signer has to decide whether your Bitcoin should move. The Payout Preflight tool exists for the verification half of the same idea: it reconstructs and checks the coinbase transaction byte for byte before a block is ever found, so you are reading the actual output rather than trusting a description of it, and the Glass Ledger receipts are signed and checkable offline for the same reason. None of that makes NexusPool immune to software bugs. Its own core code is not public, and this post is not a claim that it is, nor a claim that any pool, protocol or custody model changes your odds of finding a block, which are set by your hashrate against the network's difficulty and are identical everywhere. What a non-custodial design changes is the size of what can go wrong, not the probability that something will. You can read how the payout path is structured on NexusPool's technology page. For the fullest independent account of the incident as reported, see Decrypt's coverage of the Liquid withdrawal.

Which brings it back to those messages in the blockchain. Two parties, negotiating in public, inside the only ledger neither of them can quietly edit, over coins that left a vault because fifteen careful signers were all handed the same false receipt. The Bitcoin chain worked perfectly throughout. It recorded a valid transaction, then it recorded the argument about it. Everything that failed, failed one layer above it, in the part that asked people to take a number on faith.

Trust nothing. Verify that the system holding your coins can prove what backs them, not just that enough parties signed off.