Alpen Labs used AI to quickly reproduce the $320 million Liquid Bitcoin sidechain exploit. The attack exposed a cache flaw that let unbacked L-BTC drain reserves. No working payout limit rule exists to stop similar attacks, raising new concerns for bridge security.
Nearly 4,000 bitcoin vanished from the Liquid sidechain's reserve in one unauthorized move. The breach shocked the market. It wasn't just the size-about $320 million-but the way it happened. A cache bug in the Elements software let an attacker turn fake L-BTC into real bitcoin, slipping past the cryptographic checks meant to stop this.
Blockstream said the attack happened on September 6, 2026, at 13:53 UTC in Liquid block 4,050,336. Both Liquid nodes and federation functionary nodes accepted the bad transaction. The network was paused right after. Operations only resumed on September 10, after a full security review and a patch.
The exploit inflated the LBTC supply by about 4,000 LBTC without bitcoin backing, resulting in a withdrawal of roughly 4,000 BTC confirmed on-chain in Bitcoin block 965,783.
AI pinpoints the flaw
Simanta Gautam, CEO of Alpen Labs, said his team's AI agents traced and reproduced the exploit locally in about an hour after news broke. The AI quickly found that the Elements code cached proof checks in a way that didn't tell valid and invalid transactions apart. A code change on September 1 had joined key fields as raw bytes, without marking where one ended and another began. This let a valid proof "seed" the cache, so a later, invalid transaction could slip through. The attacker got past the proof check and triggered a real bitcoin withdrawal from the federation's reserve.
Bridge design and missing safeguards
The breach showed a bigger problem: there were no strong payout limits or outside checks before federation signers sent out funds. SideSwap, which handled the peg-out, said its authorization key was online, payouts were automatic, and there were no controls for size, speed, or human review. The attacker's order was bigger than SideSwap's wallet, so two payout attempts failed before the federation finally sent 3,996 BTC. A payout limit or outside hold-set before authorization or signing-could have stopped the exit, even after the sidechain accepted the bad state. But no such rule was in place.
Blockstream's review found that smaller peg-outs before the halt had already cut the Liquid reserve from about 4,205 BTC to just 197 BTC. Other Liquid-issued assets, like USDt and DePix, were not hit by the bug, but they were frozen while the network was paused. Reuters confirmed that Blockstream called the breach an exploit of Elements software used by Liquid, and that about 4,000 BTC worth $320 million was involved. More details are in the Blockstream incident assessment.
Liquid is a federated Bitcoin sidechain designed to enable fast, confidential transfers and issuance of digital assets. Its security model relies on a group of functionary nodes that collectively manage the peg-in and peg-out process, with cryptographic proofs and operational controls intended to ensure one-to-one BTC backing.
Patch and aftermath
Elements developers moved fast. By September 8, they had changed the cache key logic to encode field lengths, added tests for collisions, and gave an option to skip the range-proof cache. Version 23.3.4 came out the next day to close the gap that let the exploit happen. Liquid's federation stopped peg-outs, only letting normal transactions go through. Withdrawals would need full BTC backing and outside reviews before restarting. The big question now is whether future peg-outs will have an independent way to stop large, authorized requests before bitcoin leaves custody.
Evidence and unanswered questions
Alpen Labs' AI demo was a look back, not a live defense. The team didn't have the exact production validator binaries or the real cache contents, so they worked from source code and on-chain data. SideSwap's own security build accepted the attack transaction, showing the bug was real on at least one node. But it's still not clear if all federation functionaries were affected. Like the $1.1 million EvilTokens phishing case reported earlier, the Liquid exploit shows how missing one key check can put even big, multi-party bridges at risk of huge losses.
On September 6, 2026, the attacker sent 4,000 L-BTC to SideSwap's peg-out service at 14:05 UTC. SideSwap burned the tokens with valid authorization at 14:06, but the order was too big for its wallet, so two payout attempts failed before federation signers sent 3,996 BTC at 14:28. The payout went to the customer's address in the same Bitcoin block, draining the reserve. Liquid's federation paused peg-outs and said on September 17 that withdrawals would only restart after checking full BTC backing, finishing software updates, testing, and outside reviews.
Bridge security is about more than cryptographic proofs. The Liquid exploit shows that operational controls-like payout limits, offline authorization keys, and outside review-are needed to stop losses when software bugs or consensus failures hit. Without these, even one cache bug can turn a sidechain's promise of one-to-one bitcoin backing into a multi-million dollar loss. For U.S. users and exchanges using cross-chain bridges, the lesson is clear: technical fixes must go hand in hand with operational safeguards, or the next exploit could be just as fast and costly.
Bridges like Liquid depend on federated signers to approve withdrawals. But without payout limits or outside holds, one compromised or misconfigured node can cause massive losses. Cryptographic proofs are meant to stop unauthorized exits, but operational controls are needed to catch failures that get past the code. As bridge systems grow more complex and valuable, the mix of software security and human or automated oversight will decide if these networks can survive the next attack.