A flaw in Liquid’s transaction-validation cache allowed a September 6 transaction to create approximately 4,000 LBTC without corresponding bitcoin, after which the network’s normal peg-out machinery released roughly 4,000 BTC from its reserve. Blockstream’s September 23 technical assessment establishes that sequence; it was not fully known when the September 7 open edition was originally due.
This retrospective separates the event-day record from later findings. Contemporaneous reporting on September 6 established that Liquid had paused activity after a large withdrawal and that the operator was trying to contact parties calling themselves white hats. The root cause, exact transaction path and recovery accounting came later and should not be read as knowledge available at the start of September 7.
A valid cache entry masked an invalid output
Liquid is a federated Bitcoin sidechain built on Elements. Users lock BTC and receive LBTC intended to remain backed one-for-one. Its 15 functionary nodes require signatures from at least 11 operators to accept blocks, according to Blockstream’s assessment.
The failure occurred before those signatures became useful as a safeguard. At 13:53 UTC on September 6, Blockstream says a transaction in the original Liquid block 4,050,336 reused the byte pattern of a previously accepted rangeproof-cache entry. Nodes holding that cached result treated a different, invalid proof as already verified. The transaction’s output therefore entered accepted chain state even though its value was not backed by its inputs.
Once accepted, the unbacked LBTC looked valid to downstream systems. SideSwap’s later incident statement says the party submitted about 4,000 LBTC to its peg-out service at 14:05 UTC. Federation signers released 3,996.02 BTC at 14:28 UTC, and SideSwap forwarded 3,995.99999857 BTC in the same Bitcoin block. Those figures describe the principal peg-out, not a live reserve balance or a dollar valuation.
Consensus validation and operational controls both failed
Blockstream says the SideSwap authorization key was not stolen. Instead, SideSwap and the functionaries authenticated a peg-out request against chain state that consensus had already accepted incorrectly.
SideSwap separately acknowledged that its signing key was online, that payouts were automatically forwarded, and that it applied no size limit, velocity check or wallet-history review. It also noted that the federation supplied the required signatures for an order representing a large share of LBTC supply. The two primary accounts therefore identify different control layers: flawed consensus admitted unbacked value, while peg-out procedures did not stop an extraordinary withdrawal.
Blockstream coordinated a bridge-node halt at 18:26 UTC on September 6. The Block’s event-day report, published at 5:14 p.m. EDT and updated at 6:32 p.m., described the network as effectively paused and said the root vulnerability had not yet been disclosed. That is the appropriate information boundary for the original recovery date.
Later records narrow the remaining uncertainty
Blockstream reports that 3,400 BTC was returned at 16:09 UTC on September 7—after the open-edition context—and that approximately 602 BTC remained under recovery efforts as of its latest cited public update at 21:05 UTC on September 17. The quantities are operator accounting, not an independent audit, and the assessment says its investigation may be updated.
Elements version 23.3.4, released September 9, changed the rangeproof-cache construction to add explicit length framing and offered an option to disable the cache. Blockstream also says the invalid outputs and four descendants were removed during a chain reorganization, and that no related inflation remained in the current Liquid chain as of its September 23 report.
Those measures address the identified software path and chain state. They do not erase the reserve loss, independently verify the outstanding recovery amount or prove that every operational weakness has been corrected. The lasting market-structure lesson is narrower: a federated signing threshold cannot protect a reserve when the shared consensus state and the withdrawal controls both accept the same invalid premise.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

