A software bug in Blockstream's Liquid Network let an attacker mint roughly 4,000 Bitcoin's worth of fake currency out of thin air, about $320 million at the time of the exploit. Unlike most crypto hacks that make headlines, nobody's private keys were stolen and no exchange's hot wallet was drained. The flaw sat in the code that verifies whether a cryptographic proof is legitimate, and once that check failed, the sidechain started treating invalid proofs as valid ones.
If some of that exposure touched your holdings, directly or through an exchange that settles in Liquid Bitcoin, the tax question in front of you isn't abstract. Here's what actually happened between September 6 and September 11, 2026. You'll also see why the attacker gave most of the money back, and what current US tax law says about a loss like this one. Then comes a question worth asking no matter how the tax side lands: what a sidechain-reserve exploit like this actually means for how you think about custody risk.
Key Takeaways
- The exploit was a software bug, not stolen keys: a flaw in Blockstream's Elements codebase, present in every version before v23.3.4, let an attacker mint about 4,000 unbacked L-BTC and drain roughly 95% of the Liquid Federation's Bitcoin reserve.
- $320 million was exposed, not fully lost: the attacker returned about 3,400 BTC, worth roughly $272 million, on September 7, 2026, a day after self-declaring as a "whitehat" through an on-chain message.
- Blockstream refused to pay the remaining ransom: as of September 11, 2026, roughly 598.5 BTC, about $47 million, stays unrecovered, and Blockstream has not agreed to the attacker's bounty demand.
- Blockstream and Liquid Network aren't the same thing: Blockstream built and maintains the sidechain's software, but Liquid Network is run by a wider federation, and the bug was a protocol-level defect, not a breach of any single company.
- Documentation matters regardless of the deduction outcome: proving what you held and when protects you whether or not a theft-loss deduction ends up applying to your situation.
What Happened: The Liquid Network Exploit, Step by Step
Liquid Network is a federated Bitcoin sidechain: a separate blockchain pegged to Bitcoin, run by a group of exchanges and institutions called the Liquid Federation, built to settle transactions faster and with more privacy than the Bitcoin mainchain itself. Users lock BTC with the federation and receive Liquid Bitcoin (L-BTC) in return, a token meant to always be redeemable one-to-one for real Bitcoin.
That one-to-one backing is exactly what broke. Blockstream, the company that built and maintains the open-source Elements codebase Liquid Network runs on, traces the exploit to a bug present in every version before v23.3.4. The flaw let range-proof verification cache keys collide, meaning the system could mark an invalid cryptographic proof as already verified simply because its cache key matched one that had genuinely passed. An attacker used that collision to mint approximately 4,000 unbacked L-BTC, tokens with no real Bitcoin behind them, then converted a large share of that fake supply into real BTC by pegging out through the exchange SideSwap. By the time the federation caught it, the attacker had drained roughly 95 percent of Liquid Network's Bitcoin reserve.
The exploit was disclosed on September 6, 2026, a Sunday. Because L-BTC settles inside several exchanges and trading venues, some of those platforms paused Liquid-related deposits and withdrawals as a precaution while the scope of the damage became clear.
| Date (2026) | Event |
|---|---|
| September 6 | Exploit disclosed. Attacker mints ~4,000 unbacked L-BTC, drains ~95% of the federation's BTC reserve, and leaves an on-chain message self-declaring as a "whitehat." |
| September 7 | Attacker returns ~3,400 BTC (~$272M, ~85% of the total) to the federation. |
| September 10 | Liquid resumes block production and, later that day, transactions; peg-outs stay paused. Blockstream's CEO states the 1:1 L-BTC/BTC peg will be covered. |
| September 11 | Blockstream publicly refuses the ransom demand for the remaining ~598.5 BTC (~$47M), which stays unrecovered. |
Add it up and total exposure comes to roughly $320 million, about 4,000 BTC at the time of the exploit. That figure hasn't been revised since. What changed in the days after is how much of it actually came back.
Know exactly what you held, and when
If your L-BTC or BTC touched an exchange affected by the Liquid Network exploit, CoinTracking shows you precisely what was in that wallet beforehand, timestamped and ready to back up your records.
Blockstream and Liquid Network: Related, But Not the Same Thing
It's easy to read headlines about this exploit and treat "Blockstream" and "Liquid Network" as interchangeable. They aren't, and the distinction matters for anyone trying to size up their own exposure. Liquid Network is the sidechain itself: the protocol and the federation of functionaries that operate it. Blockstream is the company that built the Elements software the sidechain runs on and that shipped the patched v23.3.4 release. Blockstream sits inside the Liquid Federation as one of its functionaries, but the federation includes other exchanges and institutions too, not Blockstream alone.
That separation matters because of what kind of bug this was. A cache-key collision in verification logic is a protocol-level software defect, the same category of risk as a bug in a blockchain's own consensus code, not a breach of Blockstream's corporate systems or a theft of anyone's private keys. Nobody's seed phrase was compromised, and no single institution's hot wallet was the point of failure. The federation's reserve came up short because the software let it verify fake proofs as real ones, not because an attacker got hold of a password or a signing key.
Do You Owe Tax on Crypto You Never Actually Controlled?
If you held L-BTC through an exchange or wallet exposed to this exploit, you don't owe tax on the exposure itself. A sidechain-reserve shortfall isn't a sale, a trade, or any other disposal you chose to make, so no taxable event arises just because the reserve behind your L-BTC came up short. The IRS's own digital asset guidance centers on selling, exchanging, or receiving digital assets, not on backing shortfalls in infrastructure you don't control.
Two things can still create a real tax obligation regardless of how this incident resolves. First, any gains you had already recognized on L-BTC or BTC before September 6, from an earlier trade or from a reward earned through a Liquid-connected service, were taxable when you received them and stay taxable no matter what happened to the reserve afterward. Second, if an exchange or the federation eventually compensates affected users for a shortfall, whether in BTC, a token swap, or some other settlement, that compensation may need its own tax evaluation depending on how it's structured. Blockstream's CEO has publicly said the 1:1 peg will be covered, but a stated intention is not an executed compensation process, and no formal one had been announced as of this article's publish date. Because a theft-loss deduction depends on having no reasonable prospect of recovery, even a statement like that is worth watching, not something to set aside until a process opens up.
Can You Deduct a Liquid Network Loss on Your Taxes? What Current Law Says
This is the harder question, and it depends on why you were holding the L-BTC or BTC exposed to this exploit. If you held it purely for personal use, the loss falls under the same rule as any other personal casualty loss: a deduction is generally not allowed unless the loss was caused by a federally or state-declared disaster, and a sidechain software exploit doesn't meet that bar. The IRS confirms that recent legislation made the disaster-only requirement permanent, rather than letting it expire and revert to the broader rules that applied before 2018.
Most people holding L-BTC or BTC through a Liquid-connected platform are holding it as an investment, not for personal spending, and that puts them in a different category. A theft loss on crypto held for investment or profit can still be deductible, disaster or no disaster. IRS legal guidance from 2025 on scam and hack victims confirms this path stays open, though it still depends on the specific facts: you generally need a genuine profit motive and no reasonable prospect of recovering the funds.
Form 4684 (Casualties and Thefts) reflects the same split. Section A covers personal-use property and is gated by the disaster requirement above. Section B covers investment and income-producing property, and it carries no disaster requirement at all.
Whether this specific exploit counts as theft under the relevant state law is worth raising with a tax professional directly. A cache-key collision that mints unbacked tokens is a different fact pattern from a stolen wallet or a phished password, and how it gets characterized could matter for the deduction analysis. Which category your own loss falls into, personal-use or investment-motivated, and whether it qualifies as theft at all, is something only a tax professional can determine for your specific situation.
Outside the US, the rules differ by jurisdiction. Australia's Tax Office, for instance, publishes its own guidance for loss or theft of crypto assets, worth checking if you file outside the US.
How to Document a Liquid Network Loss for Your Taxes
If the loss itself doesn't end up deductible for you, documenting it still matters. Good records protect you from a different problem: being unable to prove what you actually held, when the reserve behind it came up short, and what your cost basis was on everything before and after. That protects the accuracy of your remaining holdings and gives you something concrete if a compensation process eventually opens up or the deduction rules shift again.
The mechanics look a lot like building a Source of Funds report. Instead of proving where your money came from, you're proving what you had, at what point in time, and what happened to it next.
- Balance before September 6: a timestamped screenshot or export showing exactly what L-BTC or BTC you held through any exposed exchange or wallet immediately before the exploit.
- Transaction history and cost basis: the acquisition dates and cost basis of the specific coins involved, calculated the same way as any other taxable event, typically using FIFO or another accounting method.
- Official statements: save your own copy of any advisory from Blockstream, the Liquid Federation, or an exchange you used, since official pages get edited or taken down as an investigation continues.
- Any correspondence about compensation: if an exchange or the federation offers a refund, a swap, or a claims process, keep every message and date.
- A clear timeline: when you acquired the exposed L-BTC or BTC, when the exploit happened, and when, if ever, you learned about it.
A CoinTracking import does most of this automatically for anything already connected to your account. Every trade, deposit, and transfer carries its own timestamp and cost basis, so if a platform you use is ever caught up in a future incident like this one, you already have the record instead of reconstructing it from memory. Reporting crypto losses correctly for anything that's still deductible elsewhere in your portfolio still depends on that same clean transaction history.
Document the loss properly
CoinTracking imports your transaction history from over 400 exchanges, wallets, and blockchains, and generates a Source of Funds report that traces exactly where a withdrawal's crypto originally came from.
Sidechain Custody Risk vs. Exchange Custody Risk: What This Means for You
Most crypto hacks that make headlines fall into one of two buckets: an exchange's hot wallet gets drained, or a user's own keys get phished or stolen. The Liquid Network exploit is neither. Nobody's password or seed phrase was compromised, and no single custodian's wallet was the point of failure. What failed was the reserve mechanism itself, the software logic that's supposed to guarantee every L-BTC in circulation has a real Bitcoin sitting behind it.
That's a meaningfully different risk category. A federated sidechain concentrates trust in the software and the functionaries running it, rather than in a single company's operational security. When that trust model fails, it doesn't look like a stolen password. It looks like a shortfall in the reserve that every token-holder was relying on, spread across everyone who held the token rather than concentrated in whoever got hacked directly.
Scenario A: Your Funds Touched an Exchange That Paused L-BTC Activity
Save everything listed above now, while advisories and your own records are still easy to find. Check the exchange's or the federation's official channels for updates rather than third-party rumors, and don't assume a deduction is available before speaking with a tax professional. Documentation is what protects you either way.
Scenario B: You Hold Bitcoin Directly and Never Touched Liquid Network
Your BTC itself was never at risk. The exploit lived entirely inside the sidechain's reserve logic, and Bitcoin's own mainchain kept operating normally throughout. It's still worth understanding what happened here, since it shows how a technically sound base blockchain can carry real risk one layer up, in the bridges, sidechains, and federations built on top of it.
Scenario C: You're Deciding Where to Hold Crypto Going Forward
A federated sidechain, a centralized exchange, and self-custody each carry a different kind of custody risk, and this exploit is a useful data point for weighing them. An exchange concentrates risk in one company's operational security. Self-custody removes a third party from the equation but puts the entire burden of key management on you. A federated sidechain sits in between: it spreads trust across multiple functionaries, but as this exploit shows, a single software defect can still put the whole reserve at risk regardless of how many institutions are involved. None of those models is risk-free, and understanding which kind of risk you're taking on is the point, not picking a single option and assuming it's safe.
Conclusion
The tax answer depends on why you held the exposed L-BTC or BTC, personal use or investment, not on a blanket rule for sidechain exploits. Blockstream has said the 1:1 peg will be covered. If that commitment is fulfilled, it could reduce or wipe out any deductible loss, and it could also create its own taxable income if you already claimed a deduction before the compensation arrived. Document your balance, cost basis, and every official statement now, so you're ready whichever way the deduction question lands.
Keep your records ready for whatever comes next
CoinTracking has tracked crypto portfolios and calculated taxes for over 2.2 million users since 2012, across more than 400 exchanges, wallets, and blockchains. Import your history once, and you're ready the next time a sidechain, exchange, or protocol has a bad week.
Disclaimer
This article is for general informational purposes only and does not constitute financial, tax, or legal advice. Tax treatment of stolen or hacked cryptocurrency depends on your individual circumstances and on current law, which can change. Readers should consult a qualified tax professional before making decisions based on the information presented here. The author and publisher are not responsible for any losses or damages incurred as a result of using the information in this article.