logo

Liquid Network Incident Analysis

ID: 4ba416b2-871f-5ea5-9a90-953ff366dc8c

STIX ID: report--4ba416b2-871f-5ea5-9a90-953ff366dc8c

Feed Name: CertiK Blog

Threat Score
90/100

Date Published: 2026-09-08

Date Updated: 2026-09-09

...
...

On 6 September 2026 the Liquid sidechain was exploited via an ambiguous cache-key encoding in Elements' rangeproof verification cache, allowing an attacker to prime the cache, reuse a cached verification, and inflate L-BTC by ~3,998.5 L-BTC (~$318.7M), which was subsequently pegged out to Bitcoin; the report details the root cause, attack flow, key transactions and addresses (IOCs), and notes a partial return of funds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.