On September 6, 2026, an attacker exploited a vulnerability in Elements' rangeproof verification cache to create 4,000 unbacked LBTC on the Liquid sidechain, then withdrew approximately 4,000 BTC through the peg-out process. The attacker returned 3,400 BTC after negotiations, leaving about 602 BTC outstanding, while Blockstream deployed emergency patches to address the vulnerability.