EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

SlowMist: Liquid network vulnerability caused 3,998 L-BTC to be cast

2026-09-12 15:24:54
Bookmark

Blockchain security company SlowMist discloses Liquid network vulnerability: Attackers minted nearly 4000 L-BTC

Blockchain security company SlowMest reported an exploitation of the Liquid network, claiming that the attacker minted 3,998 L-BTC. This statement is consistent with Blockstream's confirmation that in one of the most serious Bitcoin sidechain incidents in 2026, approximately 4,000 BTC were transferred out of the Liquid Alliance Wallet.

The report provides precise numbers for incidents that Blockstream, the operating company behind Liquid, had previously described in only approximate terms. This has also raised concerns about the security of a network that is designed to transfer bitcoins faster and more privately than the main chain.



Details of the Liquid network vulnerability reported by SlowMest

The vulnerability allegation originated from SlowMist, an organization known for conducting post-mortem analysis of cryptocurrency hacking incidents. According to unconfirmed reports, SlowMist released its analysis report on September 11, covering events that occurred on September 6, 2026.

Liquid is a Bitcoin sidechain operated by federal members and built based on the Elements codebase. Its native anchor asset, L-BTC, is designed to be backed by one-to-one bitcoin held in alliance reserves.

Blockstream has confirmed broader incident circumstances. According to its official announcement, approximately 4,000 BTC (valued at approximately US$320 million at the time) were withdrawn from the Liquid Alliance Wallet. It should be noted that these are issuers 'approximate data and not the total number of block browsers independently checked.

Blockstream pointed out that the withdrawal operation used the SideSwap Peg-out Authorization Key (PAK), but stated that the key and other authorization keys had not been compromised. In other words, according to the operator, this outflow of funds was not a simple robbery by stealing the key.

The company also stated that the exchange has been notified and has suspended or is about to suspend the deposit and withdrawal of L-BTC. Notifications from any individual exchange have not yet been independently verified. Blockstream added that other Liquid assets, including USDT, DePix and tokenized real-world assets, were unaffected.



The core focus of the report on the casting of 3,998 L-BTC pieces

is on the "casting" behavior itself. Based on unconfirmed reports attributed to readable extracts of Crypto Briefing's analysis of SlowMist, the attacker forged and subsequently redeemed L-BTC. Approximately 3,998.5 units are cited in the main body of the report, while the title is rounded to 3,998 units.

This difference is important. Since the original SlowMist report or any on-chain casting transaction records could not be obtained, the exact numbers are still reports rather than verified on-chain facts.

Forging is not the same as confirmed theft. Unsupported L-BTC minting represents tokens created without corresponding reserves, but to convert them into actual gains or user losses, transaction-level evidence is required, and existing materials do not provide such evidence.

The mechanism has also not been proven. Crypto Briefing's description states that this is due to the lack of length prefixes in versions prior to Elements v23.3.4, which led to proof-of-range verification cache key collisions, thereby allowing unsupported casting to be implemented; the description comes from only a single secondary source. The same report claimed that about 95% of the alliance's reserves were emptied, and that the attackers used a Bitcoin OP_RETURN message to disguise themselves as a white-hat man and demand a 10% reward, and approximately 3,400 BTC were subsequently returned.

None of the above figures have been independently confirmed. They echo Blockstream's pattern of rejecting extortion demands after recovering most of its stolen bitcoins and are tied with other 2026 recovery stories such as CrediX. However, the claim of recovery here is still attributive rather than a fait accompli.



Vulnerability content to be verified

Existing material fails to establish a vulnerability mechanism, precise timing, or true financial impact. SlowMist's report itself has not been read, and no cast, exit or return transactions have been traced to the blockchain browser.

Blockstream confirms the recovery trend. As of 10:00 UTC on September 10, 2026, the company stated that block production has resumed without transactions and that required federation member and bridge node updates have been deployed, consistent with broader ex post facto guidance.

Restoration of block production does not mean restoration of full service. Peg operations (including PAK-authorized exits) remain suspended and the restoration of BTC/LBTC reserves is still in progress.

Blockstream also flags a secondary threat. On September 9, it warned that impostors were using emails, phishing websites and direct messages, including false refunds and re-Peg quotes, and emphasized that users did not need to move funds, enter mnemonics or install emailed software.

Blockstream will never ask for your mnemonic or PIN code, nor will it ask you to send funds anywhere.

This federal bridging failure is a unique risk category that is different from cross-chain router hacking attacks such as the reported $10 million THORChain vulnerability, but its response strategies-pause, patch, warn, re-establish trust-are similar in way.



Market reaction

There was little volatility in the broader market. During the study period, Bitcoin traded at US$77,420, up slightly 0.23% on the day, while the Fear and Greed Index was 56, firmly in the "greedy" range. Neither of these were obvious reactions to the Liquid incident.

So, the question left is: If SlowMist's 3,998 L-BTC data holds true and Elements 'cache key flaw is confirmed, how many other Bitcoin sidechains are running code with the same hidden flaw?

Disclaimer : This article is for reference only and does not constitute financial or investment advice. There are significant risks in the cryptocurrency and digital asset markets. Before making a decision, be sure to study it yourself.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP