Crypto attackers spend their time hunting the gap between what a protocol claims and what the code actually checks. Bridges, wrappers, and sidechains are where that gap shows up most often: one chain is supposed to mint a token only when another chain has locked the real asset. On 6 September that hunt landed on Liquid, Blockstream’s Bitcoin sidechain.
A fault in how Elements cached confidential-transaction proofs let a party create L-BTC with no matching deposit, then cash it out through a normal peg-out. The federation paid real Bitcoin. The lesson is not new. Every extra layer on Bitcoin adds speed and features — and another surface for someone looking for a loophole.
Blockstream—which is the developer firm behind Liquid Network—describes the exploit as a security incident, labeled the actors purported white-hats, and said no federation key and no SideSwap peg-out authorization key had been stolen. SideSwap is a non-custodial app to hold, send, swap, and peg assets on Liquid — especially L-BTC and other Liquid-issued tokens.
Rehearsal traffic, then a mint at block 4,050,336
SideSwap’s record begins on 5 September. At 20:55 UTC a party sent 0.001 BTC into the service. SideSwap paid the matching L-BTC at 21:33 UTC. Nine minutes later those coins were split into twenty outputs. From 22:01 UTC through 13:52 UTC the next day the same wallet cycled those outputs through seventy near-identical transactions: forty-eight before midnight and twenty-two after. The last rehearsal was confirmed one minute before the mint.
At 13:53 UTC on 6 September, Liquid block 4,050,336, transaction f24a4b179b5cc7e88b25a763911f7cbdf2bf45d1d1b5ab611e94461cef0a183f created about 4,000 L-BTC with no peg-in.
SideSwap attributes that result in a consensus bug in Elements, the open-source software Liquid uses. A fix was written on 3 August. A security build went to federation members in mid-August. SideSwap says it deployed that build on 13 August. The same fix merged into the public Elements repository on 1 September under a title that named the caching problem. Nodes that later signed the peg-out still treated the new coins as valid.
Confidential transactions on Liquid hide amounts and rely on range proofs so a node can check that an amount sits inside an allowed range. Elements cached successful proof checks. The cache key was built in a way that let different data collide on the same stored result. After a valid proof sat in cache, a later transaction could point at that result and skip a full check. That is the path SideSwap and later independent analysis describe for the unbacked mint. No SideSwap private key, wallet, or internal system was taken. Blockstream said federation keys and the SideSwap PAK were intact.
Test order at 14:00, main burn at 14:06, Bitcoin out at 14:28
At 14:00 UTC the same party submitted a 2.5 L-BTC peg-out. SideSwap paid 2.49749857 BTC about a minute later. At 14:05 UTC it sent 4,000 L-BTC to the peg-out service. Deposit identifier 32892440646b3309a71ea5b0f6c87daebcb481f2d2f5434deaea515ef2933814. SideSwap burned the tokens at 14:06 UTC in Liquid transaction ce4caece413cd9d444ce7ed9f54e5b328b3da5e4af301aff59a3571f76e988f2 under a valid authorization.
SideSwap’s own Bitcoin wallet could not fund an order of that size. Two payout attempts failed. At 14:28 UTC federation signers released 3,996.02 BTC in Bitcoin transaction 8db751a650ae2f12006b7e8c69a75e4df360e8afd6b9e05ae0b9fa6458a7b140. SideSwap forwarded 3,995.99999857 BTC to the party’s address in the same block, transaction 85d2ca15bea33a592e73ed40c6a5da887feecf1e77f58ec7f580e00841645043. From the mint at 13:53 UTC to bitcoin leaving the federation wallet, thirty-five minutes elapsed.
SideSwap lists two operating decisions that turned a Liquid validation failure into a main-chain payment. The peg-out authorization key stayed online. Every authorized payout was forwarded automatically in the same bitcoin block. There was no size cap, no velocity limit, and no check on the age of the depositing wallet. An order near 4,000 L-BTC from a wallet only hours old passed without human review. SideSwap later returned its 0.1 percent fee, about 4 BTC, to the federation in transaction 0334e46381b57503da634ee09aaf966c07e81bf0aa821339e1eb0d26f26c8a1f.
The reserve stood near 4,200 BTC the day before. After the large exit and a small number of other peg-outs processed before the halt, it fell to about 197 BTC. USDT, DePix, and other assets issued on Liquid were not used in the sequence. They were frozen with the rest of the network when bridge nodes went offline.
Network pause and 3,400 BTC returned on 7 September
Around 20:25 UTC on 6 September Blockstream took public bridge nodes down. The status update posted early 7 September said exchanges had paused LBTC deposits and withdrawals, that Liquid wallets would be affected, and that the sidechain was paused until the issue was resolved. Federation members were working to restore activity. Other issued assets were described as unaffected by the incident itself.
A bitcoin OP_RETURN attached to a related spend said the party was a group of whitehats and asked to be contacted on chain. Later messages said to fix the bug first, that the chain was at risk at the latest commit, that every node had to be patched, and that the coins would be transferred back after the fix was confirmed. Blockstream replied on-chain with signed text.
After it stated that bridge nodes were patched and the funds were safe to return, 3,400 BTC moved to the federation address on 7 September. About 598.5 BTC stayed at the receiving address from the 6 September payout.
No public filing from Blockstream or the federation records a signed bounty for that remainder. SideSwap’s statement does not treat the retained coins as an agreed fee. The 3,400 BTC return restored most of the reserve that had left the day before. It did not close the gap between circulating L-BTC and bitcoin still held by the federation.
Limited restart on 10 September, peg-out still closed
Elements v23.3.4 changed how cache keys are stored for range-proof verification. Blockstream’s update dated 10:00 UTC on 10 September said functionary and bridge updates had been deployed, functionaries were signing and validating blocks, and block production had resumed without user transactions while the chain was watched.
Peg operations, including PAK-authorized peg-outs, remained suspended. Work on restoring the BTC/LBTC reserve was described as still in progress. The same notice warned users about scam sites and unsolicited messages asking for keys.
SideSwap’s market note the same day said swaps were open and pointed to public figures on liquid.network: 4,205 L-BTC in circulation and 3,597 BTC in the federation reserve as of 10 September.
Of the roughly 3,996 BTC that left on 6 September, 3,400 BTC of the return sat inside that reserve number. SideSwap wrote that the difference is what Blockstream said would be covered and that it would not add its own account of how that cover would be arranged. Peg-in through SideSwap reopened on 11 September. Peg-out stayed closed pending the federation review of the exit path.
The public record is now a set of times and identifiers. Rehearsals ran from the evening of 5 September into the early afternoon of 6 September. The unbacked mint confirmed at 13:53 UTC. A 2.5 L-BTC test left at 14:00. Four thousand L-BTC burned at 14:06. Federation bitcoin left at 14:28. Bridge nodes went down that night. Three thousand four hundred bitcoin returned on 7 September.
Block production resumed in a restricted mode on 10 September. Peg-out remains off. About 598.5 BTC has not come back. Circulating L-BTC still exceeds the bitcoin sitting in the federation wallet by that shortfall plus any other movement since the pause lifted.
Liquid’s design treats L-BTC as a 1-to-1 claim on bitcoin locked by the federation. On 6 September that claim was created without a lock, then honored by a peg-out that the software and the signers treated as ordinary. SideSwap accepted blame for keeping the authorization key hot and for forwarding every payout in the same block.
Blockstream and the federation patched the cache, paused the chain, brought blocks back under watch, and said the peg would be covered. The remaining coins and the final shape of that cover are not settled in the documents published so far.
The Crypto Times sent Blockstream a list of questions on the incident, including the unpaid remainder, who it holds responsible, and what it will do if those coins are not returned; Blockstream had not replied at the time of publication.
Also read: Revolut Data Breach Hits 680 Customers, UK Opens Probe as Hackers Demand 10,000 Bitcoin
