Tuesday Brief: 3,996 BTC out, 3,400 BTC back
All 83 inputs carried 11 valid federation signatures: a bug in Elements let invalid L-BTC through the peg-out, and Liquid released 3,996 BTC of real Bitcoin against it. The negotiation happened in OP_RETURN, Blockstream offered a 98 BTC bounty, and 3,400 BTC went back on Monday. Meanwhile Circle's regulated wrapper has sat at 40 BTC for five weeks.
On Sunday afternoon a single Bitcoin transaction spent 4,019.44426085 BTC from the Liquid Federation's wallet and paid 3,996.01834922 BTC to one outside address. It cost 0.00034097 BTC in fees, about $27.
No federation key has been reported compromised, and the transaction bears that out: we checked the witness data, and all 83 inputs carry exactly 11 valid signatures on the federation's 11-of-15 branch. Blockstream and SideSwap both say no Peg-out Authorization Key was taken. A bug in Elements — the open-source node software Liquid runs, built on Bitcoin Core's codebase — let invalid L-BTC through the peg-out path, and the federation released real Bitcoin against it, exactly as it is built to do.
On Monday evening the party holding the coins sent 3,400 BTC back. Everything below is current as of 8 September 2026, 10:10 UTC. The Liquid reconstruction and the Notional balances are ours, read from Bitcoin and Ethereum mainnet; the method sits with each section.
Liquid: 83 inputs, 11 valid signatures each
Liquid is Blockstream's Bitcoin sidechain. BTC pegs in, becomes L-BTC, and pegs out again when a federation of functionaries signs a release. The security model is explicit and always has been: you are trusting the federation and the code it runs, not Bitcoin's consensus.
The code was the part that broke, and the signing worked. At 14:28:56 UTC on 6 September, in Bitcoin block 965,783, transaction 8db751a6…b140 spent 83 inputs from the federation address bc1qdlld6a…uhwxxr into 13 outputs. Every input's witness carries 11 DER signatures against a script beginning OP_11, so this was the 11-of-15 federation quorum authorising a release in the ordinary way. We pulled it apart:
bc1qdlld6a…uhwxxr.bc1qgslsydz…, later consolidated onward.a6d697a2…, block 965,950.For the first day nothing left that address at all. It looked busy — funded with 15,993.99 BTC across 39 outputs, spent 11,995.49 BTC across 26 — but the spends were self-sends of the whole balance back to itself, and the balance never moved off 3,998.4988.
Then it moved. At 16:09:25 UTC on 7 September, in block 965,950, transaction a6d697a2… sent 3,400.00000000 BTC to bc1qdlld6a…uhwxxr — the federation address the coins were taken from, and the one the attacker had named on chain fifteen hours earlier. We confirmed it from both sides: the attacker's balance fell from 3,998.49879600 to 598.49992880 BTC, and it is the only inbound transaction over 100 BTC the federation has seen since the exploit.
The negotiation is happening in public, in OP_RETURN
The attacker did not email anyone. They wrote to Blockstream in the OP_RETURN field of Bitcoin transactions, and Blockstream wrote back the same way. We pulled every message on the address and decoded them. Here is the thread:
6 Sep 18:30
6 Sep 19:31
7 Sep 01:49
1176 542D A98E 71E1 3372 2EF7 4AC8 CC88 6844 A2D6.7 Sep 02:20
bc1qdlld6a…uhwxxr, is that ok”. That is the federation address the coins came from.7 Sep 03:30
7 Sep 03:30
7 Sep 09:41
7 Sep 15:13
bc1qdlld6a…, instead we have a clean route address”. It did not work.7 Sep 16:09
Three details stand out.
They called themselves whitehats; nobody has established that they are. What is established is that they named the return address before anyone asked, that it is the exact federation address the 83 inputs came from, and that fifteen hours later 3,400 BTC went to it. Ledger CTO Charles Guillemet's scepticism was reasonable at the time — people who mean to give money back do not usually take $319M first — and the coins then moved the way the messages said they would.
Blockstream negotiated a bounty in public, at block 965,912: return 3,900 BTC, keep 98. The attacker sent 3,400 and is still holding 598.50 BTC, six times the offer. Neither side has said whether that is a counter-offer, a staged release, or the end of it.
And the channel is open to everyone, which showed. Between the real messages sat a Monero swap service advertising "$700M+ done", an exchange billing itself as "the biggest one to launder money", a memecoin launched on the attacker's address, a New York lawyer touting for the mandate, and a run of accusations that the hack was an inside job by named Blockstream staff. One message at block 965,945 impersonated the payee and asked the attacker to send the coins to a different "clean route" address. Half an hour later the 3,400 BTC went to the correct one.
The patching condition follows from where the bug was. Elements is the software every Liquid functionary and node runs, so a fix is not something Blockstream can apply centrally and be done with — it has to reach the whole set before a restart is safe. That is why the attacker asked for every node to be patched, why Blockstream's reply was specifically that its bridge nodes were, and why the network is still down.
Liquid is still stopped, even after the money came back. Its tip is block 4,051,232, timestamped 7 September 04:49:10 UTC, on a chain that normally produces a block every sixty seconds. That block is now over 28 hours old.
Even after returning 3,400 BTC, one unidentified party still holds fifteen times more Bitcoin than Circle's regulated wrapper. Most of the Bitcoin DeFi actually uses sits with BitGo and Coinbase. People have argued about whether that is acceptable for years without much changing. On Sunday one of the alternatives lost 95% of its reserves in a single transaction, and got most of it back because whoever took it decided to give it back.
How we got these numbers. Transaction 8db751a6…b140 decoded from Bitcoin mainnet via the Blockstream API, including all 83 inputs and 13 outputs and the fee. Address bc1ql4mfu6…qjlte read for balance, funded and spent totals, and its full 39-transaction history; the OP_RETURN outputs decoded from scriptpubkey_asm on every transaction touching it. Liquid's chain tip read from the Liquid API. Wrapper supplies read with totalSupply() against WBTC, cbBTC, tBTC and cirBTC on Ethereum. BTC valued at $79,427.
cirBTC: the opposite bet, and nobody is taking it
cirBTC is Circle's wrapped bitcoin, at 0x72DFB2E4…5075E on Ethereum. One token, one bitcoin, redeemable one for one. Circle's 4 September post set out the reserve and proof-of-reserves architecture; the token itself is older than that, and we read its whole history off the chain rather than off the announcements. The BTC sits with Circle National Trust, a federally chartered national trust bank supervised by the OCC, segregated from Circle's own balance sheet, with reserves published through Chainlink Proof of Reserve. Circle's Arc L1 goes to mainnet on 16 September, with DTCC and BlackRock named as partners, and cirBTC is promised native support there.
Circle is betting that institutions want a name on the custody agreement and a regulator behind it. Liquid's federation and Circle's trust bank answer the same question — who can sign your Bitcoin away — and they differ mainly in who you sue afterwards.
The contract was deployed on 2 April 2026 and first minted on 6 April, 0.0001 cirBTC. By 8 June, the day Circle announced it was live on Ethereum, supply was 0.00060450. It crossed 40 between 1 July and 1 August, and it has not moved since: 40.01869681 on 1 August, 40.02378367 this morning. Five weeks flat, at roughly $3.14M, against WBTC's 116,132 BTC.
Circle's own reserve page reports a slightly larger figure and more BTC in reserve than tokens outstanding, which is what an overcollateralised buffer looks like. The Ethereum supply is the number above.
So the model answers the failure Liquid just had, and for five weeks nobody has bought it. If this week moves that number, it will be the clearest price anyone has put on custody assurance in DeFi.
Notional: a contract nobody had turned off
The third one is small, and it is the one most likely to happen to somebody reading this.
At 00:01:35 UTC on 4 September, Notional Finance's legacy V1 escrow at 0x9abd0b88…f683 was emptied. We bracketed it to the block:
4 Sep 00:01:23 UTC
4 Sep 00:01:35 UTC
$1,727,782 at par, in one block, twelve seconds. The mechanism was an unsafe uint128 downcast: two mintfCashPair() calls built a liability of −2¹²⁸ which truncated to zero in free-collateral valuation, so the position looked fully collateralised while owing everything. The proceeds went to roughly 689 ETH and then through Tornado Cash, with 0.07 ETH tipped to the block builder Titan to keep the trade out of the public mempool.
Notional V1 was superseded years ago. V2 and V3 are different contracts and were not touched. What was touched was an escrow that had been left deployed, still funded, and still callable, long after the product around it had moved on.
Worth being precise about the bug, because the easy version is wrong. Solidity 0.8 added checked arithmetic, so an overflowing addition reverts. It did not make narrowing conversions safe: uint128(x) still silently truncates, and that is exactly what happened here. A compiler upgrade would not have caught this. A SafeCast library or an explicit range check would.
What the age of the contract explains is why nobody looked. V1 was superseded years ago, so the code sat deployed, funded and callable with no reason for anyone to audit it again. Deprecating a contract does not stop it working. If you have shipped more than one version of anything, go and check what the old one still holds and who can still call it.
The pattern, now with a number on it
TRM Labs published its 2026 count last week, and it puts the last three of these briefs in context. Thirty-two price-manipulation exploits so far this year, against twelve in all of 2025. That is roughly one in every eight of the 207 crypto hacks TRM logged in 2026. The mechanism is the one we have now written up three weeks running: inflate a thin token, post it as collateral, borrow something real, leave.
CertiK's August tally sets the size: $215M of total crypto losses for the month, $144.6M of it in DeFi. The three lending exploits we covered on 1 September were most of that.
The defensive note in TRM's data is unglamorous and matches what Aave's deprecation is doing by other means: protocols using time-weighted prices, multiple oracle sources or liquidity circuit breakers came through the year materially better. None of that is new technique. It is a list of things that cost money to run on markets that do not earn much.
The money has not gone anywhere, either. Lending TVL reads $50.11B this morning, up from $49.2B a week ago, and Morpho's outstanding loans hit a record $5B on 1 September — 95% of it denominated in stablecoins, 62% in USDC alone. Thirty-two exploits have not dented the aggregate; they have concentrated the damage in markets nobody was watching.
Follow-ups
Moonwell published its post-mortem, and it names the donation. Last week we reported, from the chain, that the MAMO exploit had two multipliers rather than one: a 40.9x oracle pump and a direct transfer of MAMO into the market contract that lifted the exchange rate without minting a single mToken, walking straight past a supply cap. Moonwell's own account now says the same thing, in the protocol's words: the attacker "transferred another 53,393,290 MAMO directly into the mMAMO contract without minting new mMAMO," which raised the exchange rate "by approximately 3.68 times without consuming the market's mint-path supply cap."
The numbers reconcile to within a rounding error. We read 15,089,603 MAMO supplied and 53,393,291 transferred, at 09:19:59 and 09:21:09 UTC; the post-mortem says 15,089,595 and 53,393,290, at the same two timestamps. Moonwell puts gross borrowings at $11,028,762 against our independent $11.05M, and remaining borrower obligations at ~$9.131M against our $9.27M read of surviving debt.
Two things the post-mortem adds that we could not see. The attacker started with $1.947M of USDC and spent about $7.50M gross buying MAMO across venues, which prices the whole operation rather than just the slice we measured in the main Aerodrome pool. And the emergency response is timestamped: borrow caps went to 1 wei at 10:53:43 UTC, the supply cap at 11:09:43 — 83 and 99 minutes after the last borrow.
Those caps are still 1 wei this morning, eleven days on. Moonwell's TVL was $71.76M before the exploit and is $31.2M today, another $3.8M lower than when we wrote last week. What the post-mortem does not contain is any supplier remediation framework: it quantifies the borrower debt and stops.
Aave's offboarding has not moved. CRV, UNI and 1INCH still read LTV 0 with borrowing disabled on Ethereum, and still are not frozen, with supply caps unchanged from last week. The asset half executed; the tidy-up has paused.
What we are watching
- The remaining 598.50 BTC. Blockstream offered a 98 BTC bounty and asked for 3,900 back; 3,400 arrived. About $47M is still at an address nobody has identified, and neither side has said what happens to it.
- The Elements patch. The return was conditioned on a fix to a bug neither side has described publicly. Whatever it is should be visible in Elements before Liquid restarts, and that commit is the only public account of the vulnerability anyone is going to get.
- When Liquid restarts, and what it says about the peg-out path. The sidechain has been stopped since Sunday. A federated chain can stop; the question is what changes before it starts again.
- Arc's mainnet on 16 September. Circle's own L1, with DTCC and BlackRock attached, is where cirBTC is meant to be native. Eight days out.
- Whether cirBTC's 40 BTC moves. Supply has been flat for five weeks, and a wrapper built on segregated custody and an on-chain reserve feed just had the best possible week for its pitch. If institutional demand for verifiable custody is real, it should show up in that number within the month.
- Legacy contracts at every protocol that has shipped a V2. Notional's escrow was drained four years after the product left it behind. The check takes an afternoon: enumerate old deployments, read their balances, and find out which entrypoints are still live.
- The CLARITY Act cloture vote on 15 September. It is a vote on whether the Senate may begin debating market structure, not on the bill. It needs 60; Republicans hold 53, so seven Democrats have to cross. Failure does not amend anything, it just ends the 2026 attempt, and the SEC's Regulation Crypto Assets comment window closes on 20 October either way.
- Glamsterdam. Ethereum's largest change since the Merge is scheduled to fork Sepolia around 21 September and Hoodi in early October, with mainnet in November. Anything that reads Ethereum state for a living has a testnet window opening in a fortnight.
- Whether the August bid survives September. Spot Bitcoin ETFs took $3.52B in August, their best month of 2026, alongside a 25% price gain. The first day of September gave back $236.5M, and BTC trades near $78,400 this morning against a 15–16 September Fed decision that futures price at roughly a 60% chance of a hike — a probability, not a settled outcome.
Sources: TRM Labs' 2026 exploit count via Cryptobriefing and CoinDesk; CertiK's August figures via The Crypto Times. Moonwell's account from its post-mortem, with our own figures from last week's brief; Aave reserve configuration and Moonwell caps re-read by us from Ethereum and Base this morning, TVL from DefiLlama. CLARITY vote arithmetic from The Crypto Times; Glamsterdam timing and ETF flows from Crypto University and Investing News. Liquid transaction data, address balances, OP_RETURN contents and the chain tip read by us from Bitcoin and Liquid mainnet through the Blockstream API; witness data (11 DER signatures per input against an OP_11 script) decoded by us from the same transaction; the Elements bug, the SideSwap Peg-out Authorization Key and the patch confirmation from The Block, Cryptobriefing and Protos; cirBTC's deployment block, first mint and full supply history bisected by us on Ethereum; reporting and the white-hat framing from The Defiant, BeInCrypto and Cointelegraph, with Charles Guillemet's scepticism reported by BeInCrypto. cirBTC contract state read from Ethereum mainnet; product details from Circle and CoinDesk. Notional escrow balances read by us at the surrounding blocks on Ethereum mainnet; the exploit mechanism, attacker addresses and fund routing from BeInCrypto, crypto.news and The Crypto Times. Lending TVL read by us from the DefiLlama API, Morpho's outstanding-loan record via Cryptopolitan, and Arc's mainnet date from Circle.