PublicAML
← All reports

Protocol attack report VR-717BCCC5

Investigator report

Filed by a vetted PublicAML investigator rather than by an anonymous reader. The account itself has not been independently re-checked.

The addresses below carry a risk label from this report.

Type
Hack
Reported as
Protocol attack
Chain
bitcoin
Reported by
DenysInvestigator
Incident date
Sep 7, 2026
Published
Sep 8, 2026

What happened

Liquid Network (Liquid Federation) protocol exploit, 7 September 2026. An Elements minting bug allowed the creation of unbacked L-BTC, which was then routed out through SideSwap's peg-out. Federation keys were not compromised and the transaction appeared valid β€” this was a protocol-level flaw, not a key compromise. Approximately 4,000 BTC (~$320M at the time) was siphoned from the Liquid Federation wallet and consolidated into bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte. The party left an on-chain message reading "we are whitehats. contact us on chain." On 8 September 2026 roughly 3,400 BTC (~$315M) was returned, while 598.5 BTC (~$47.4M) was retained at the same address and has not been returned. Reported by PeckShieldAlert on X, 7 September 2026. This report is filed by PublicAML from public sources, not by a victim of the incident. The address is recorded as the consolidation point of exploited funds; the "whitehat" claim is the actor's own and is not independently verified.

Addresses named in this report

Named here and believe it is wrong? Open the address page above and use the flag on the assessment. Every dispute is read.

Protocol attack report VR-717BCCC5 | PublicAML