Sunday, September 6, 14:27 UTC. The Liquid reserve shows 4,205.29 bitcoins. Sixty seconds later, 202.63. Between the two, a single transaction and 3,996.0183 bitcoins heading out. At the price of the moment, around $79,000 per coin, so a little over $320 million.
Nobody stole a single private key. No safe was picked, nobody bribed an employee. That's the detail that matters most in this story, and it's also the one that should concern all of us. The network did exactly what it was asked to do.
What follows is quick. Liquid cuts its bridges, exchanges suspend L-BTC deposits and withdrawals, customers discover that they can no longer get back what they had put there. Two days later, block production starts again. The money going out does not. As I write these lines, it is still impossible to turn L-BTC into bitcoin.
So I'm starting again from the beginning, because this business explains better than ten articles why the word bitcoin means nothing on its own.
Liquid is Bitcoin's cloakroom
You enter a theater, you hand over your coat, they give you a numbered token. The token is not the coat. It tells you that when you leave, if everything goes well and if the cloakroom is still open, someone will give you back your coat. That's the whole article.
Liquid is a network running alongside Bitcoin, launched by Blockstream in 2018. The idea: move bitcoin faster and more discreetly than on the original chain, with ridiculous fees and transactions that nobody can read from the outside. Exchanges and payment companies use it every day, and you do too without knowing it as soon as you withdraw crypto in a country where the main chain is expensive.
The mechanism is the cloakroom, literally. You put your bitcoins in a shared address. This address is not held by one person, but by fifteen companies that have to sign together: eleven signatures out of fifteen to open it. In exchange, you receive L-BTC, a token with exactly the same value, which lives on the parallel network. When you want to go home, you destroy your tokens and the cloakroom gives you back real bitcoins. That's what is called a withdrawal, or a peg-out if you read the trade press.
The model has held up for eight years. It has one flaw that is never written in big enough letters: between the moment you hand over your coat and the moment you get it back, you no longer have your coat.
Your token is worth only as much as the promise of the person holding it, and the cloakroom can close during the night
The bug was not in the keys, it was at the entrance checkpoint
Fifteen companies, eleven signatures out of fifteen, hardware keys, procedures: all these people did their job properly. The key authorizing withdrawals was not compromised, the cloakroom signed every withdrawal as it was supposed to sign it. The problem was one level higher, in the free software that runs Liquid, a derivative of Bitcoin Core called Elements.
To avoid recalculating the same checks endlessly, this software keeps in memory the proofs it has already validated. A sort of checkpoint notebook at the entrance, with the tokens already stamped. Except that this notebook filed its notes under an incomplete key: it remembered that a proof had been validated, without remembering which asset on the network it belonged to. A token stamped for one currency could therefore be reused for another.
You can see the picture. Someone shows up at the counter with a ticket that has already been validated, but for the wrong coin, and the door opens.
And this was not a last-minute stroke of luck. The preparation took fourteen hours. The attacker seeded 68 identical proofs in blocks 4,049,384 to 4,050,246, at 41 satoshis per transaction, which costs almost nothing. He was preparing his notebook. Then came the strike, in block 4,050,336: 83 inputs, each carrying exactly eleven signatures. Then he left through the front door, converting his perfectly compliant fake tokens into real bitcoins, and the federation paid.
Sunday, September 6, 2026, the cloakroom reserve between 14:27 and 14:28. Source: Blockstream, public record of the chain
The fix existed, it was not in any published version
Here is the part I can't let go of. The hole was known, fixed and put away in a drawer.
The patch that ties the software's memory to the relevant asset was written on August 3. It was merged on September 1. It was picked up in the developers' branches on September 2 and 3. And no released version of the software contains it. The federation's participants, for their part, were running a version released on April 13. A technical note highlighted by Jameson Lopp, a well-known observer in the field, goes further: the software being run by the members of the locker room is more than two years behind the code.
Four days. The patch enters the code on the evening of September 1, the hole is exploited on the 6th. I don't know, and nobody knows, whether the guy was reading the public repository. What I do know is that he didn't need to put much effort into it, and that the hole was open for anyone who wanted to see it.
Want a simple image? A building where the front door has been repaired on the plans, approved in a meeting, sent on to the locksmith, and where nobody has put in the new lock yet.
Repaired on paper, never taken out of its box, and in the meantime the hole remained open
The nice hackers kept 46 million
The next day, Blockstream signs a message on the chain to say that the nodes are fixed and that the money can come back safely. And the money comes back: 3,400 bitcoins, around $270 million, in block 965 950. Eighty-five percent.
There are 598.5 bitcoins left in an address the guy still controls, around 46 million. He presents himself as a benevolent hacker, he negotiates through signed messages slipped into transactions, and his explanations are public. His last message is two characters long, and it's an upside-down sad smiley.
Blockstream has never announced an agreement, a bounty, or the terms of anything. Ledger's chief technology officer, Charles Guillemet, asked the uncomfortable question: if these 600 bitcoins are a negotiated payment, we're no longer talking about a good deed, we're talking about extortion. I don't have a better way of putting it, and I think he's right to say it out loud.
Concretely, what does this change for you
Three things, and the first one is reassuring.
Bitcoin has not been hacked. The main chain is intact, its twenty-one million coins are where they were, its keys haven't moved. What failed is the plumbing we install on the side to go faster, and that plumbing is everywhere: on the other chains, with intermediaries, in contracts that promise returns.
Second thing, and this is the lesson that applies to everyone. A bitcoin that isn't on the Bitcoin chain isn't a bitcoin. It's an IOU. You have a claim on someone. On an exchange, your balance is a claim. On a parallel network, your token is a claim. In a contract that promises you a return, another claim. The question is never "is it bitcoin", it's "who owes it to me, and how long has it been since they stopped updating their software".
At home, my family photos sleep on a Synology in a closet, nobody else can open them, and it cost me the price of the box. I'm not telling you to go buy a safe and put everything in it, that would be selling you something. I'm telling you that the only difference between the two ways of storing things is the name of the person who can say no on the day you want to get them back.
Third thing, the timeline, honestly. Liquid withdrawals are still frozen, and nobody knows when they'll reopen. Eighty-five percent of the bitcoins have come back, which means the locker room will have enough to return the coats. It also means that fifteen percent are missing, and that the reopening date depends on people who are repairing software that everyone thought was solid. And in the meantime, if you have crypto on an exchange, you're in the same position as those customers, without knowing it. I wrote the other day that Belgium has two licensed exchanges out of 338: that's not a reason to panic, it's a reason to look at where your coins are.
What you hold in your hand, or what someone else holds for you. There is no third option
What occupies me is not the 598 bitcoins
The theft figure will pass, the investigation will take its course, and in three weeks nobody will be talking about it anymore. What remains is the software version.
A counterpart the size of Liquid, which alone holds more than four thousand bitcoins, was running code that was two years old, with a patch available and not installed. This isn't individual negligence, it's how things work: nobody updates what works, and nobody wants to be the one who causes an outage on deployment day. In the meantime, whoever is looking for a hole has all the time in the world.
So the question I'm asking myself, and I'm asking you too: these services you use every day, would you be able to say when they were last updated? No? Me neither, for most of them.
Good luck to the fifteen companies in the locker room for the reopening. And to those who pulled it off, a piece of advice: a sad smiley can't be erased from a public chain.




Join the conversation
You need an account to comment on this article. Creating one is free and takes under a minute.
No comments yet.