Attackers drained nearly 4,000 BTC from Liquid's reserves by exploiting a software bug, proving that even strong private key controls can't shield users from technical failures or insurance gaps.
Nearly 4,000 Bitcoin disappeared from Liquid's reserves in a single, authorized withdrawal-not because private keys were stolen, but because a software bug let attackers create fake tokens and cash them out for real Bitcoin. The incident left the network's security model in pieces and raised new doubts about what protection users actually have.
How the attack bypassed key security
Liquid is a Bitcoin sidechain built for faster, more private transactions. It holds a shared reserve of Bitcoin to back its L-BTC tokens. Users deposit Bitcoin, get L-BTC, and can later swap those tokens back for Bitcoin. On September 6, attackers found a vulnerability in the Elements codebase that let them mint about 4,000 L-BTC without depositing any Bitcoin. They then exchanged these unbacked tokens for real Bitcoin through the normal peg-out process, draining the reserve and exposing a major flaw in the network's validation logic.
A flaw in Liquid's range-proof validation allowed attackers to create and redeem nearly 4,000 L-BTC without any real Bitcoin backing, resulting in a $320 million loss.
This incident challenges the idea that private key security is the ultimate defense against crypto theft. Here, the private keys were never touched, but the software used them to sign off on fraudulent withdrawals. It's as if a group of signers all approved a payment based on a balance sheet that had already been tampered with. The result: a legitimate-looking transaction that emptied the vault.
Insurance and its limits
Many users and companies see insurance as a safety net, but the reality is more complicated. Crypto insurance usually covers specific types of losses or claims against the company, not blanket reimbursement for every customer. Even when there's a payout, it may not be enough to cover all missing assets. The terms of coverage, the cause of the loss, and the total amount at stake all affect what gets paid out-and to whom.
Blockstream, which runs Liquid, said that neither the federation keys nor the peg-out authorization keys were compromised. They called it a security incident, not a private key breach. The root cause was a bug in the range-proof validation logic of Elements, where a validation cache could return a previously stored "valid" result for a different output, letting unverified values slip through. After the attack, Blockstream halted the network, released an emergency patch for Elements v23.3.4 on September 9, and had the fix reviewed by outside security teams including Bitcoin Red Team and Alpen Labs before restarting block production. Still, withdrawals of L-BTC to BTC stayed suspended, showing the operational fallout of such exploits.
Liquid Network operates as a federated Bitcoin sidechain, using a multi-signature model for custody and peg-out operations. Its security depends not only on private key management but also on the integrity of the Elements software and consensus among federation members. This layered approach means that both technical and procedural safeguards must function correctly to protect user assets.
Coinbase, for example, says its crime insurance covers only a portion of digital assets in storage and warns that total losses could exceed insurance recoveries. The policy also excludes losses from unauthorized access to individual accounts caused by compromised credentials. Two customers with missing funds could end up with very different outcomes depending on how the loss happened. The word "insured" on a website rarely tells the whole story.
Who bears the loss
Unlike FDIC insurance for U.S. bank deposits, which directly protects account holders, private crypto insurance usually covers the company itself. Whether customers are made whole depends on the company's obligations, the size of the insurance payout, and whether the business has enough capital to cover any shortfall. If the insurer pays less than the total loss, the company must find other resources to fill the gap-or customers may be left with unrecovered losses.
Responsibility for making users whole isn't always clear. If a storage provider relies on third-party software and that software fails, the provider might seek reimbursement from its own insurer or try to claim against the software vendor. Meanwhile, customers want their funds back right away, but payouts and legal disputes can drag on. The process of recovering assets and sorting out responsibility often happens in parallel, with users caught in the middle.
Asset recovery and user impact
After the Liquid exploit, about 3,400 BTC were returned to the federation, while the attacker kept roughly 598.5 BTC, according to BlockSec. Blockstream refused to pay a ransom for the remaining funds, stating: "Taking assets without authorization and withholding their return is a crime, not responsible disclosure... It is theft." Each coin returned reduces the reserve's deficit, but doesn't settle the bigger question of who is responsible for any remaining shortfall. The transaction record alone can't establish legal or financial obligations.
Repayment agreements may specify a dollar value instead of the original number of coins, exposing users to price swings while they wait. If Bitcoin's price rises between the loss and the payout, users may get less Bitcoin than they lost, even if the dollar amount is fully repaid. If the price falls, the same dollars could buy more Bitcoin. The risk of price movement during the claims process is often on the user, unless the contract says otherwise.
Insurance agreements also need to spell out what happens if stolen assets are later recovered. Who gets the returned coins-the insurer, the company, or the customers-depends on the policy terms and repayment structure. Meanwhile, users may go weeks or months without access to their funds, with no compensation for lost opportunities or delayed payments unless the agreement specifically provides for it.
For most users, the technical and legal details behind these incidents are nearly impossible to audit. Few can review the software that approves withdrawals, and even fewer have access to the insurance contracts between companies and insurers. As reported earlier, the complexity of crypto security and insurance leaves many users exposed to risks they can't easily evaluate or control.
According to available data, the Liquid exploit led to the unauthorized withdrawal of nearly 4,000 BTC on September 6, with 3,400 BTC returned by attackers on September 7. The remaining shortfall and the process for compensating affected users have not been fully resolved as of the latest reporting. The incident shows how large losses can happen even when private keys are not compromised, and highlights the need to understand both technical and financial protections in place.
Crypto users who rely on third-party services for custody or tokenization should demand clear, plain-language explanations of what happens if something goes wrong. Providers need to spell out which losses they will cover, whether reimbursement will be in coins or dollars, and how they plan to fund any gap between what they owe and what insurance pays. Without this transparency, users are left to absorb risks they may not even know exist. Security measures can reduce the chance of loss, but only clear financial commitments determine who ultimately pays when defenses fail.
Private key security is still a core part of crypto protection, but it's not a guarantee against loss. Software bugs, flawed processes, and unclear insurance coverage can all undermine user confidence and financial safety. The Liquid incident is a reminder that technical security and financial protection are separate issues-and both need to be addressed for users to have real confidence in the systems they trust with their assets.
Insurance in the crypto sector is fundamentally different from traditional deposit insurance. Most crypto insurance policies are negotiated between companies and insurers, not directly with end users. Coverage is often limited by policy terms, exclusions, and payout caps. Users should not assume that the presence of insurance means their assets are fully protected, or that reimbursement will be timely or complete. Understanding the difference between technical security and financial guarantees is essential for anyone entrusting assets to a third-party crypto service.