Software flaw enabled unbacked token creation and reserve drain

Approximately 4,000 Bitcoin left Liquid’s reserve on September 6 through a withdrawal the network approved, even though the private keys authorizing it had not been stolen. Attackers exploited a software flaw to create L-BTC tokens without depositing corresponding Bitcoin backing, then exchanged those unbacked tokens for real coins held in the shared reserve.

Liquid operates as a separate blockchain for Bitcoin-backed tokens, allowing users to move funds faster and with greater privacy than on the main chain. Users deposit Bitcoin into a reserve and receive L-BTC tokens, each intended to represent one BTC. When users redeem tokens, corresponding coins exit the reserve. The flaw allowed attackers to bypass this deposit requirement entirely.

According to a Bitquery investigation, attackers returned 3,400 BTC on September 7, leaving approximately 600 BTC unrecovered. TRM Labs, a security firm, reconstructed the attack sequence.

Blockstream rejects bounty demand

Blockstream, which operates Liquid, rejected a bounty demand related to the incident, according to CryptoSlate reporting on September 12. The company did not publicly disclose the terms of its rejection or specify whether it would compensate affected users.

Insurance gaps in crypto custody

The incident exposes a critical gap in how cryptocurrency insurance covers software failures versus key theft. Coinbase’s crime insurance covers a “portion” of digital assets held across storage systems against theft and cybersecurity breaches, but explicitly excludes losses from compromised login credentials. This distinction matters: Liquid’s flaw was neither theft of keys nor a breach of credentials, but a structural software failure that the insurance framework may not address.

The FDIC protects eligible deposits when insured banks fail but does not insure digital assets, leaving custody providers to rely on specialized coverage. Relm, a specialist insurer serving crypto businesses, offers digital asset crime coverage for infrastructure exploits and smart contract theft, plus technology errors and omissions coverage. However, insurance policies typically cover the company holding assets rather than guarantee full customer reimbursement.

Compensation structures create price risk

Compensation agreements may specify dollar amounts rather than coin replacement, creating exposure to price fluctuations. If Liquid were to compensate users at a fixed dollar value, a customer who lost one Bitcoin when the price stood at $80,000 might receive only 0.8 BTC if the price had risen to $100,000 by the time of payment. This structure leaves customers bearing the risk of price appreciation between loss and reimbursement.

Liquid did not specify its contractual obligations to customers regarding loss replacement or the timeline for any repayment.