SlowMist: Liquid Network Exploit Minted 3,998 L-BTC
Security firm SlowMist has reportedly attributed a Liquid Network exploit that allowed an attacker to mint 3,998 L-BTC, a claim circulating in secondary reporti...
Security firm SlowMist has reportedly attributed a Liquid Network exploit that allowed an attacker to mint 3,998 L-BTC, a claim circulating in secondary reporting but not yet independently confirmed by an original SlowMist publication or on-chain records.
TLDR KEYPOINTS
- SlowMist is reported to have analyzed a Liquid Network exploit.
- The reported minting amount is 3,998 L-BTC.
- The supplied context does not establish the exploit mechanism, financial impact, or remediation status.
What SlowMist reports about the Liquid Network exploit
The core of this Liquid Network exploit story rests on a single attributed account. According to unconfirmed reports carried by Crypto Briefing, SlowMist published an analysis on September 11 describing an incident it dated to September 6. The original SlowMist writeup was not available at the time of reporting. For related coverage, see CrediX Faces $4.5M Exploit, Suspected Exit Scam.
The claim attributed to SlowMist
The attribution to SlowMist arrives second-hand. SlowMist’s own research channels did not carry a Liquid incident analysis at retrieval, and the firm’s Medium page was inaccessible. That gap means the minting claim should be read as reported, not verified. SlowMist has previously featured in incident work, including its disclosure of a supply chain attack on the BigONE exchange. For related coverage, see Crypto Investor Loses $1M in Ethereum Scam Exploit.
What the supplied headline establishes
Blockstream did confirm a Liquid incident occurred. In an official phishing alert published September 9, 2026, the company referenced a recent Liquid Network incident and warned that impersonators were posing as Liquid, Blockstream and support staff using reimbursement, re-peg and emergency-update lures. Blockstream said the incident does not require users to move funds, enter a recovery phrase, re-peg assets or install software sent by email.
The reported minting of 3,998 L-BTC
The reported amount and asset
The headline figure names 3,998 L-BTC as the amount reportedly minted. Notably, the underlying secondary report describes approximately 3,998.5 L-BTC minted and redeemed, a discrepancy that itself remains unresolved without primary transaction data.
What the minting claim establishes about losses
A reported mint is not a confirmed theft. The available context contains no transaction hashes, redemption records or incident-time valuation, so the figure should not be equated with an equivalent amount of Bitcoin stolen or a confirmed dollar loss. Related unconfirmed accounts describing an attacker demanding a bounty are covered separately in reporting that Liquid hackers sought a 10% return from Blockstream. The precise technical path of any unauthorized minting awaits a verified source.
What remains to be verified about the reported exploit
Source, timing, and technical scope
The original SlowMist report, the exact incident date and the affected component all require confirmation. Official elements-23.3.4 release notes list a change to harden range-proof cache keys and add a norangeproofcache option, but that patch evidence alone does not establish the full exploit sequence.
Impact and response
Operational status is only partly clear. Liquid’s official blog banner states that issued-asset transfers have resumed while L-BTC transfers and peg-out operations remain paused, with no incident timestamp supplied. Asset backing, any movement or recovery of funds, user impact and a fuller official response are unresolved in the available evidence. Their absence here does not prove that no response occurred, only that it was not documented in this material, unlike sharper post-mortems seen after events such as the GMX exploit tied to a design flaw.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
More From Crypto News
SlowMist: Aave V3 Loop Safe Module Exploited, 114.09 ETH Stolen
Aave v3 is one of the largest decentralized lending protocols by total value locked . A module-level exploit differs from a core protocol breach, but it still c...
Ripple reveals XRPL privacy and AI-agent upgrades in Seoul
Ripple used a Seoul event to outline two new development directions for the XRP Ledger: privacy upgrades and AI-agent capabilities.
Fed Bank Reserves Fall $88.236B as Weekly Average Rises
Federal Reserve bank reserves dropped $88. 236 billion between the September 23 and September 30 Wednesday snapshots, even as the weekly average for the same pe...
Crypto Hacks Totaled $766M in September, Led by Bitget and Liquid Losses
Crypto hacks and exploits drained a reported $766 million in September, with losses tied to Bitget and Liquid exchange incidents leading the monthly tally, maki...
US Banking Group Sues OCC Over Crypto Trust Bank Approvals
A US banking industry group has filed a lawsuit against the Office of the Comptroller of the Currency, challenging the federal regulator’s decisions to approve...
20,000 ETH Moved From Bitfinex to Aave: What It Means
On-chain monitoring service Whale Alert flagged a transfer of 20,000 ETH from Bitfinex to an address attributed to Aave on Oct. 3, 2026 at 14:06:47 UTC, valuing...
Author
Akita Inu
Akita Inu covers fast-moving crypto market updates, exchange news, and token ecosystem developments for CoinLive, with a focus on concise source-led reporting.