LIVE
Bitcoin $72-73K: ETF Realized Price and Coinbase PremiumConsensys Split: MetaMask Goes Its Own WayMexican Musician, Family Reportedly Killed Over Bitcoin WalletSecret Service Freezes $52.8M in Crypto Tied to XinbiClarity Act Lobbying: Crypto, Banks Target Senators' Home States1inch Routes Over $800B as Co-Founder Flags DeFi Profit HurdleMalone Lam Pleads Guilty in $245 Million Bitcoin TheftScam Center Strike Force Restrains $52M in Crypto in One DayDee Goens Replaces Jacob Horne as Zora CEORipple's Alderoty Urges Crypto Holders' Input on Clarity ActBitcoin $72-73K: ETF Realized Price and Coinbase PremiumConsensys Split: MetaMask Goes Its Own WayMexican Musician, Family Reportedly Killed Over Bitcoin WalletSecret Service Freezes $52.8M in Crypto Tied to XinbiClarity Act Lobbying: Crypto, Banks Target Senators' Home States1inch Routes Over $800B as Co-Founder Flags DeFi Profit HurdleMalone Lam Pleads Guilty in $245 Million Bitcoin TheftScam Center Strike Force Restrains $52M in Crypto in One DayDee Goens Replaces Jacob Horne as Zora CEORipple's Alderoty Urges Crypto Holders' Input on Clarity Act
Homepage/Bitcoin News/SlowMist: Liquid Network Exploit Minted 3,998 L-BTC
BITCOIN NEWS

SlowMist: Liquid Network Exploit Minted 3,998 L-BTC

·5 MIN READ·
MakeThe CC Presspreferred onGoogle

Blockchain security firm SlowMist has reported a Liquid Network exploit in which an attacker minted 3,998 L-BTC, a claim that lands as Blockstream confirms roughly 4,000 BTC left the Liquid Federation wallet in one of the year’s most serious Bitcoin sidechain incidents.

KEY FINDINGS - EVIDENCE LEVEL: MULTI-SOURCE
3Key sections mapped in this report
0Internal references connected to related coverage
5External source domains cited in the article
5 minEstimated time to read the full report

The report puts a hard number on an event that Blockstream, the company behind Liquid, has so far described in approximate terms. And it raises the stakes for a network built to move Bitcoin faster and more privately than the main chain. For related coverage, see CrediX Recovers $4.5M in Crypto After Exploit.

Here is what the evidence supports, and what still needs corroboration.

SlowMist reports a Liquid Network exploit

The exploit claim traces to SlowMist, a firm known for post-mortems on crypto hacks. According to unconfirmed reports carried by Crypto Briefing, SlowMist published its analysis on September 11 covering an incident dated September 6, 2026. For related coverage, see GMX Suffers $42M Exploit in Major Cyber Attack.

The affected network is Liquid, a Bitcoin sidechain operated by a federation of functionaries and secured through the Elements codebase. Its native pegged asset, L-BTC, is meant to be backed one-to-one by Bitcoin held in the federation’s reserve. For related coverage, see ChangeNOW API 2026: What It Offers, Who Uses It, and Whether It Delivers.

Blockstream has confirmed the broader incident. Its official notice reports that approximately 4,000 BTC, valued there at roughly $320 million, were withdrawn from the Liquid Federation wallet, according to the company’s incident permalink. Those are the issuer’s approximate figures, not independently reconciled explorer totals.

Liquid Federation wallet withdrawals

≈4,000 BTC

Blockstream’s initial incident notice reports approximately 4,000 BTC withdrawn from the Liquid Federation wallet. This is an official approximate withdrawal figure, not an independently reconciled loss total or the disputed L-BTC mint amount. Source: Blockstream official incident notice.

Blockstream says the withdrawals used the SideSwap Peg-out Authorization Key, or PAK, while stating that this key and the other authorization keys were not compromised. In other words, the drain was not a stolen-key smash-and-grab, at least by the operator’s account.

The company also said exchanges had been notified and had paused, or would pause, L-BTC deposits and withdrawals. No individual exchange notice was independently verified. Blockstream added that other Liquid assets, including USDT, DePix and tokenized real-world assets, were unaffected.

The reported mint of 3,998 L-BTC

The headline figure is the mint itself. According to unconfirmed reports attributed to Crypto Briefing’s readable extraction of the SlowMist analysis, the attacker minted and later redeemed L-BTC, with the report’s body citing approximately 3,998.5 units while its headline rounded to 3,998.

That discrepancy matters. The underlying SlowMist report and any on-chain mint transaction were not obtained, so the exact figure remains a reporting artifact rather than a verified chain fact.

Minting is not the same as confirmed theft. A mint of unbacked L-BTC represents tokens created without matching reserves, but converting that into realized proceeds or user losses requires transaction-level evidence that the available material does not provide.

The mechanism, too, is unverified. Crypto Briefing’s account describes a range-proof verification cache-key collision, caused by missing length prefixes in Elements versions before v23.3.4, that allegedly enabled unbacked minting; that description comes from a single secondary source. The same report claims roughly 95% of federation reserves were drained, and that the attacker used Bitcoin OP_RETURN messages to pose as a white-hat requesting a 10% bounty, with about 3,400 BTC later returned.

None of those figures were independently confirmed. They echo the pattern seen when Blockstream rejected a ransom demand after recovering the bulk of the drained Bitcoin, and they sit alongside other 2026 recovery stories such as CrediX clawing back $4.5 million after its own exploit. But recovery claims here remain attributed, not established.

What remains unverified about the reported exploit

The available material does not establish the exploit mechanism, its precise timing, or the true financial impact. The SlowMist report itself was not read, and no mint, peg-out, or return transaction was traced to a block explorer.

What Blockstream has confirmed is the recovery posture. As of September 10, 2026, 10:00 UTC, the company said block production had resumed without transactions and that required functionary and bridge node updates had been deployed, consistent with its broader post-incident guidance.

Resumed blocks did not mean full service. Peg operations, including PAK-authorized peg-outs, remained suspended, and restoration of the BTC/LBTC reserve was still in progress.

Blockstream also flagged a secondary threat. On September 9 it warned that impersonators were using emails, lookalike websites and direct messages, including fake refund and re-peg offers, and stressed that users need not move funds, enter recovery phrases, or install software sent by email.

Blockstream will never ask for your recovery phrase or PIN, or ask you to send funds anywhere.

This kind of federated-bridge failure is a distinct risk class from cross-chain router hacks like the reported $10 million THORChain exploit, but the containment playbook, pause, patch, warn, rebuilds trust in similar ways.

The wider market barely flinched. Bitcoin traded at $77,420 at research time, up a fractional 0.23% on the day, while the Fear & Greed Index sat at 56, firmly in Greed. Neither is a demonstrated response to the Liquid incident.

So the question that lingers: if SlowMist’s 3,998 L-BTC figure holds and Elements’ cache-key flaw is confirmed, how many other Bitcoin sidechains are running code with the same silent gap?

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

SOURCE TRANSPARENCY
  • External Source - Referenced domain: theccpress.com
  • External Source - Referenced domain: status.blockstream.com
  • External Source - Referenced domain: blog.blockstream.com
  • External Source - Referenced domain: coingecko.com
  • Byline - Reported by Felix van Dijk
  • Coverage Desk - Primary editorial category: Bitcoin News
SlowMist: Liquid Network Exploit Minted 3,998 L-BTC | TheCCPress