Liquid Network is temporarily down after encountering an Elements Rangeproblem

The Liquid network temporarily ceased operations after an Elements Rangeproof vulnerability allowed an attacker to create unsecured L-BTC and peg 4,000 Bitcoin worth $320 million.

9/7/20264 min read

Create unsecured L-BTC instead of stealing keys.

The architecture of this vulnerability reverses the pattern that has characterized the vast majority of failed bridging and custodial attacks. In a typical bridging attack, the attacker obtains the private key or forges the signatures necessary to authorize withdrawals, then moves the actual assets out of the reserve fund that legitimately backs the circulating tokens. Here, the reserve fund's authorization mechanism works exactly as designed, the signatures are valid, and the federation authorized the withdrawal because, from a system perspective, the withdrawal request is valid.

The problem lies upstream. Liquid's price pegging mechanism issues L-BTC on the sidechain against Bitcoin locked in the federation's reserve fund, maintaining a one-to-one relationship where each circulating L-BTC must correspond to one BTC held in the reserve fund. Peg-out is the reverse operation: holders burn L-BTC on the sidechain and receive the corresponding BTC from the federation's wallet.

The Elements rangeproofing vulnerability allowed an attacker to create L-BTC without corresponding Bitcoin backing. Elements uses secret transactions with rangeproofing, cryptographic structures that prove the transaction amount falls within a valid range without revealing the amount itself—a security feature Liquid provides to institutional users who don't want the size of their transactions publicly visible. A flaw in the implementation of that rangeproofing allowed an attacker to create L-BTC out of thin air while the network's validation logic accepted the acquired tokens as valid.

Once the attacker held what appeared to be valid L-BTC, the pegging process proceeded normally. The Federation saw a valid L-BTC pegging request that the self-validating system confirmed as genuine, and released the corresponding Bitcoin from its reserves. The system did exactly what it was built to do. What failed was the accounting layer supposed to ensure that L-BTC could only exist as long as Bitcoin was locked.

Operational flow

Blockstream disabled Liquid's bridge nodes within hours, blocking new transactions from being sent to the network and halting sidechain operations until the vulnerability was patched. Exchanges were instructed to temporarily suspend L-BTC deposits and withdrawals. Blockstream's status page identified public bridge nodes as the affected component.

The underlying Bitcoin structure remained unaffected throughout the event. The vulnerability targeted Liquid's alliance-controlled price anchoring mechanism, a separate system built on top of the Bitcoin platform, and never touched Bitcoin's consensus, mining, or payment rules. Bitcoin traded at approximately $79,470 to $79,762 during the incident, down about 0.3% in 24 hours, with a total market capitalization of nearly $1.6 trillion. The price stability throughout the $320 million mining operation on Bitcoin's oldest sidechain reflects the market's accurate assessment that the incident was limited to Liquid's specific implementation and not any inherent weakness in Bitcoin itself.

Other assets issued on Liquid are also described as unaffected, including USDT, DePix, and the physical, tokenized assets circulating on the sidechain. These tokens are issued by their respective issuers based on their own collateral agreements, not on the federation's Bitcoin reserves, meaning that the depletion of reserves does not affect their collateral.

The partnership model is under intense scrutiny.

As of September 6th, Liquid's bridging architecture was considered a secure alternative to algorithm- and smart contract-based bridges, which had caused numerous catastrophic incidents across Ethereum-side ecosystems in the early 2020s. The bridging model requires a known and defined threshold of participants to authorize withdrawals, a design that eliminates the smart contract logic flaws that plagued Ronin, Wormhole, and Nomad. That track record built trust and allowed Liquid to scale to over 4,000 BTC in reserves.

The September 6 attack demonstrated that the security of the affiliate model depends on the accuracy of the code defining what the affiliate is authorizing, not just on the integrity of the signing process. A legitimate affiliate authorizing withdrawals for tokens that should never have existed offers no more protection than a legitimate smart contract executing a erroneous order.

Blockstream's May 2026 roadmap emphasized reducing reliance on trust-based models across the industry, and the company has been developing a 1-in-n BitVM bridge model, replacing the assumption of a loyal majority of the link with a design that requires only one loyal participant to prevent theft. If link designs continue to produce problems on this scale, the priority of that work will increase significantly.

Assessment and Conclusion

The sidechain remains temporarily suspended, and there is no announcement regarding when it will return to normal operation. Deploying the patch across all linked nodes is a prerequisite for restarting the network and for the attacker to commit to refunding funds, creating a sequential dependency where Blockstream must fix the vulnerability before knowing whether Bitcoin will be restored.

The full restoration depends on the participating parties respecting the stated "white hat" intent, which remains unverified. The withdrawal of 95% of the reserves means that even if Liquid resumes operations, the current circulating L-BTC supply will only be backed by approximately 200 BTC compared to the fully collateralized token supply prior to September 6th. Without the return of the withdrawn funds or capital investment from Blockstream to restore the reserves, L-BTC holders will face requirements from the affiliate that the affiliate is currently unable to fully meet.

Disclaimer: The content in this article is for informational, research, data analysis, and reference purposes only regarding the cryptocurrency market. All opinions, assessments, forecasts, or opinions reflect the author's perspective at the time of publication and do not constitute investment advice, solicitations for buying or selling, trading recommendations, advertising, marketing, or promotion of any financial products, services, or cryptocurrencies. Mentions of projects, tokens, protocols, exchanges, wallets, or cryptocurrency service providers (CASPs) are for research, analysis, or informational purposes only and should not be construed as endorsements, recommendations, or guarantees in any way. HCCVenture does not broker, advertise, market, promote, or connect users in Vietnam with any cryptocurrency services from CASPs. HCCVenture does not accept asset custody, investment mandates, manage assets, or execute transactions on behalf of clients. All investment decisions are made entirely through the reader's own research (DYOR), evaluation, and responsibility; HCCVenture is not liable for any losses or damages arising from the use of or reliance on the information presented in this article.

Compiled and analyzed by HCCVenture

Join our information channels: https://link3.to/holdcoincventure

Explore HCCVenture group

HCCVENTURE QUANT JSCO

© 2026 HCCVENTURE. ALL COPYRIGHTS RESERVED.

Connect with us

Popular content

Contact to us

Address: 8th Floor, Bach Dang Complex Building, 50 Bach Dang Street, Hai Chau Ward, Da Nang City, Vietnam.

Phone: 1900 1509

Gmail : sp_contact@hccventure.com

Disclaimer: The information on this website is for informational purposes only and should not be considered investment advice. We are not responsible for any risks or losses arising from investment decisions based on the content here.

TERMS AND CONDITIONS • CUSTOMER PROTECTION POLICY

ANALYTICAL AND NEWS CONTENT IS COMPILED AND PROVIDED BY EXPERTS IN THE FIELD OF DIGITAL FINANCE AND BLOCKCHAIN ​​BELONGING TO HCCVENTURE ORGANIZATION, INCLUDING OWNERSHIP OF THE CONTENT.

RESPONSIBLE FOR MANAGING ALL CONTENT AND ANALYSIS: HCCVENTURE FOUNDER - TRUONG MINH HUY

Read warnings about scams and phishing emails — REPORT A PROBLEM WITH OUR SITE.

HCCVENTURE Quantitative Data Joint Stock Company operates in the field of on-chain data analysis of crypto assets on the blockchain and provides market research reports on crypto assets. Check the company profile information (Business Registration Number: 0402354866) at www.masothue.com