The report puts a hard number on an event that Blockstream, the company behind Liquid, has so far described in approximate terms. And it raises the stakes for a network built to move Bitcoin faster and more privately than the main chain. For related coverage, see CrediX Recovers $4.5M in Crypto After Exploit.
Here is what the evidence supports, and what still needs corroboration.
SlowMist reports a Liquid Network exploit
The exploit claim traces to SlowMist, a firm known for post-mortems on crypto hacks. According to unconfirmed reports carried by Crypto Briefing, SlowMist published its analysis on September 11 covering an incident dated September 6, 2026. For related coverage, see GMX Suffers $42M Exploit in Major Cyber Attack.
The affected network is Liquid, a Bitcoin sidechain operated by a federation of functionaries and secured through the Elements codebase. Its native pegged asset, L-BTC, is meant to be backed one-to-one by Bitcoin held in the federation’s reserve. For related coverage, see ChangeNOW API 2026: What It Offers, Who Uses It, and Whether It Delivers.
Blockstream has confirmed the broader incident. Its official notice reports that approximately 4,000 BTC, valued there at roughly $320 million, were withdrawn from the Liquid Federation wallet, according to the company’s incident permalink. Those are the issuer’s approximate figures, not independently reconciled explorer totals.
Liquid Federation wallet withdrawals
≈4,000 BTC
Blockstream says the withdrawals used the SideSwap Peg-out Authorization Key, or PAK, while stating that this key and the other authorization keys were not compromised. In other words, the drain was not a stolen-key smash-and-grab, at least by the operator’s account.
The company also said exchanges had been notified and had paused, or would pause, L-BTC deposits and withdrawals. No individual exchange notice was independently verified. Blockstream added that other Liquid assets, including USDT, DePix and tokenized real-world assets, were unaffected.
The reported mint of 3,998 L-BTC
The headline figure is the mint itself. According to unconfirmed reports attributed to Crypto Briefing’s readable extraction of the SlowMist analysis, the attacker minted and later redeemed L-BTC, with the report’s body citing approximately 3,998.5 units while its headline rounded to 3,998.
That discrepancy matters. The underlying SlowMist report and any on-chain mint transaction were not obtained, so the exact figure remains a reporting artifact rather than a verified chain fact.
Minting is not the same as confirmed theft. A mint of unbacked L-BTC represents tokens created without matching reserves, but converting that into realized proceeds or user losses requires transaction-level evidence that the available material does not provide.
The mechanism, too, is unverified. Crypto Briefing’s account describes a range-proof verification cache-key collision, caused by missing length prefixes in Elements versions before v23.3.4, that allegedly enabled unbacked minting; that description comes from a single secondary source. The same report claims roughly 95% of federation reserves were drained, and that the attacker used Bitcoin OP_RETURN messages to pose as a white-hat requesting a 10% bounty, with about 3,400 BTC later returned.
None of those figures were independently confirmed. They echo the pattern seen when Blockstream rejected a ransom demand after recovering the bulk of the drained Bitcoin, and they sit alongside other 2026 recovery stories such as CrediX clawing back $4.5 million after its own exploit. But recovery claims here remain attributed, not established.
What remains unverified about the reported exploit
The available material does not establish the exploit mechanism, its precise timing, or the true financial impact. The SlowMist report itself was not read, and no mint, peg-out, or return transaction was traced to a block explorer.
What Blockstream has confirmed is the recovery posture. As of September 10, 2026, 10:00 UTC, the company said block production had resumed without transactions and that required functionary and bridge node updates had been deployed, consistent with its broader post-incident guidance.
Resumed blocks did not mean full service. Peg operations, including PAK-authorized peg-outs, remained suspended, and restoration of the BTC/LBTC reserve was still in progress.
Blockstream also flagged a secondary threat. On September 9 it warned that impersonators were using emails, lookalike websites and direct messages, including fake refund and re-peg offers, and stressed that users need not move funds, enter recovery phrases, or install software sent by email.
Blockstream will never ask for your recovery phrase or PIN, or ask you to send funds anywhere.
This kind of federated-bridge failure is a distinct risk class from cross-chain router hacks like the reported $10 million THORChain exploit, but the containment playbook, pause, patch, warn, rebuilds trust in similar ways.
The wider market barely flinched. Bitcoin traded at $77,420 at research time, up a fractional 0.23% on the day, while the Fear & Greed Index sat at 56, firmly in Greed. Neither is a demonstrated response to the Liquid incident.
So the question that lingers: if SlowMist’s 3,998 L-BTC figure holds and Elements’ cache-key flaw is confirmed, how many other Bitcoin sidechains are running code with the same silent gap?
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.