Subscribe Now
Trending News

Blog Post

Uncategorized

THE ‘SECURE’ LIQUID NETWORK JUST MINTED $320 MILLION FROM THIN AIR – YOUR ‘BITCOIN’ WAS NEVER YOURS 

You were told Liquid Network was how Bitcoin moved at institutional speed. Eleven of fifteen hand-picked corporate functionaries had to sign every peg-out. Extra authorization keys stacked on top. Audited code. Vetted members. The whole “don’t trust, verify” sales pitch, packaged and sold to exchanges.

On September 6, 2026, someone walked out with 4,000 BTC — roughly $320 million — in a single transaction. The federation wallet that backs every L-BTC token went from about 4,200 BTC to just over 200 BTC. That is 95% of the reserve. Gone in one block.

They did not steal keys. They did not phish a signer. The software itself let them print money from nothing.

Liquid runs on Elements, Blockstream’s own open-source codebase. Its confidential transactions hide payment amounts, so nodes rely on cryptographic range proofs to make sure nobody smuggles in a negative balance. Range proofs are expensive to verify, so nodes cache the result once one passes. The bug lived in how that cache key was generated.

The attackers submitted a legitimate transaction first — 1 L-BTC in, 1 L-BTC out — which validated and got cached under a key. Then they submitted a second transaction engineered to collide with the same cache key: 1 L-BTC in, 4,000 L-BTC out. The nodes recognised the cached key, skipped the expensive check, and waved $320 million through the door as “already verified.”

Minted from nothing. No keys compromised. No signer bribed. A caching bug nobody shipped a fix for, and the entire federation reserve evaporates in one block.

Then came the theater. The attackers left an on-chain message calling themselves white hats: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”

Ledger’s CTO is not buying it. “White hats don’t drain a bridge and then solicit an ‘on-chain’ contact,” he said, comparing the move to the $625 million Ronin hack. Former Blockstream CSO Samson Mow says the Signal request pretending to be the hackers did not even come from the address holding the 4,000 bitcoin.

This is the part that should make you furious: it was never your money to begin with. L-BTC is an IOU printed by a federation of corporations. When their software has a bug, your “bitcoin” can be inflated out of existence in a single block. Mainnet Bitcoin cannot be inflated like this. Liquid just proved it can.

The people who got drained trusted eleven companies more than they trusted themselves. Again. And 95% of the reserve now sits in an address controlled by someone calling himself a savior, while Blockstream’s network stays paused, asking nicely for its money back.

There is exactly one wallet on earth where your bitcoin is not a loan to someone else’s balance sheet: yours.

Get your coins off every federation, every sidechain, every exchange vault. Buy from people who actually fight for your sovereignty — get your stack at Bull Bitcoin and use coupon LOVEISBITCOIN at checkout: https://loveisbitcoin.com/bull

If a network with an 11-of-15 multisig, authorization keys, and audited code can lose 95% of its reserves to a cache collision, what exactly is your excuse for leaving your bitcoin anywhere but in your own wallet?

Previous

THE 'SECURE' LIQUID NETWORK JUST MINTED $320 MILLION FROM THIN AIR - YOUR 'BITCOIN' WAS NEVER YOURS

Related posts

Leave a Reply

Please authenticate to comment:

Required fields are marked *

⚡ Zap This!

Support this content with sats on Nostr

Zap QR

Lightning Address (tap to copy):

✅ Copied!

Or zap via Nostr client:

🟣 Open in Primal