
Blockstream demands return of 602 BTC after Liquid network exploit
- —The Liquid exploit occurred on September 6, 2026, via a 2018 code flaw in Elements
- —The attacker minted about 4,000 fake LBTC and redeemed them for real BTC via SideSwap
- —Some 3,400 BTC were returned; 602 BTC remain with the hacker
- —Blockstream will require external audits of consensus changes and launch a bug bounty
Why it matters: The incident highlights bridge and reserve vulnerabilities and sets a new audit standard for L2 network upgrades.
Source: Livecoins