Decision RecordActivePublished without chair review
CRT-2026-026209 Sep 2026MORNING EDITIONDaily Roundtable
Liquid transaction-processing recovery
Suspend affected deposits, withdrawals, redemptions, and other transaction processing while corrected or uncached validation and independent reconciliation are performed. Quarantine post-incident assets and reopen only after reserves, liabilities, returned funds, fees, and outstanding assets are reconciled.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
Under reviewThe evidence available on September 9, 2026 describes a deterministic Elements validation failure that allowed unbacked L-BTC and led SideSwap and Liquid functionaries to accept poisoned state and authorize Bitcoin peg-outs.
That makes continued transaction processing unsafe before validation and settlement state are independently checked. The reported gross movement and smaller retained balance also remain unreconciled.
Immediate suspension limits further settlement changes while validation, quarantine, and accounting proceed; the absence of verified release evidence prevents version-based reopening.
Who is affected
Under reviewLiquid custodians and exchanges handling deposits, withdrawals, and redemptions face settlement and balance uncertainty until reconciliation closes.
Liquid functionaries that authorize Bitcoin peg-outs must verify federation-controlled settlement state before resuming authorization. SideSwap is specifically identified as having accepted the poisoned state and must quarantine and reconcile post-incident assets.
Bridge operators and operators of the affected Elements validation path must replace cached acceptance with trustworthy cryptographic validation. Customers and counterparties relying on those services face delayed processing and unresolved balances while reserves and liabilities remain unreconciled.
No affected or fixed Elements release range has been verified; Elements v23.3.4 cannot yet be classified from the recorded evidence.
What supports this
Under reviewSupport — The crypto-fincrime analysis reports that an ambiguous Elements range-proof cache key could let distinct validation inputs collide, with a cache hit occurring before commitment parsing and cryptographic verification.
It says an invalid proof created unbacked L-BTC and that SideSwap and Liquid functionaries accepted the poisoned state and authorized Bitcoin peg-outs.
Support — The Roundtable synthesis classifies the event as a transaction-validation failure rather than evidence of stolen keys and distinguishes gross movement from the smaller retained balance.
Support — The action evidence audit supports suspending processing, quarantining post-incident assets, continuing trustworthy validation, and reconciling reserves, liabilities, and peg-outs before reopening. Insufficient evidence — The wording audit finds no support for halting validation itself.
Evidence gap — The release audit finds no official advisory or release evidence establishing affected or fixed Elements versions, including the status of Elements v23.3.4.
How the Roundtable reached this
Under reviewThe scouting role proposed suspending Liquid transaction processing and reconciling settlement state, but initially included stopping validation.
The crypto-fincrime analysis traced the incident to deterministic Elements validation behavior rather than stolen signing keys.
Evidence auditors supported suspension, quarantine, corrected or uncached validation, and reconciliation, while rejecting language that halted validation itself and flagging the absence of verified release information. The boundary reviewer applied those limits.
The linker found no prior matching Decision Record, and the arbiter selected a new record with transaction processing stopped while trustworthy validation continues.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 7 candidate signals.
- Linker (AI panel role)Linker evaluated 7 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 18 evidence signals; 11 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 0 predictions and rejected 2 claims.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 11 public/private findings.
- Arbiter (AI panel role)Arbiter produced 7 decision envelopes.
Key disagreement
Scout (AI panel role)
Published gross, returned, and outstanding figures do not reconcile exactly, the precise net deficit remains provisional, and the claimed incident duration and benign-actor characterization are unproven.
Arbiter outcome
Arbiter outcome: new decision record. The suspension-and-reconciliation position is strongly supported. Wording is corrected so that transaction processing stops while validation continues, and release-specific claims are limited to verified corrections.
Candidates considered
Considered 7 candidates · opened 1 · 6 not opened (6 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingThe exact net deficit remains provisional.
The evidence distinguishes approximately 4,000 bitcoin in reported gross movement from a smaller retained balance, while 3,996 BTC appears only in an unverified search query. Published gross, returned, retained, fee, and outstanding figures do not yet reconcile.
The affected and corrected Elements versions are also unknown: Elements v23.3.4 was searched for but not verified as affected or fixed. The incident duration, complete deployment scope, and benign-actor characterization remain unproven.
What evidence is missing
MissingThe record lacks an official Blockstream or Elements advisory identifying affected and fixed releases; the recorded search for Elements v23.3.4 and September 2026 produced no reviewable release evidence.
It also lacks transaction-level accounting that reconciles gross movement, returned funds, retained funds, fees, liabilities, reserves, peg-outs, and outstanding assets.
Independent evidence is still needed for the incident duration, the claimed benign-actor characterization, the full deployment scope, and successful cryptographic testing of corrected or uncached validation.
What would change this
Under reviewThe suspension can change to controlled reopening only when a vendor-confirmed correction is independently validated and transaction-level reconciliation accounts for every reserve, liability, return, retained amount, fee, peg-out, and outstanding asset.
Official evidence establishing that Elements v23.3.4 is fixed would resolve the current version gap but would not replace reconciliation. Evidence of stolen signing keys would change the response materially by requiring signing-key and federation-control containment.
A reconciled ledger showing a different deficit would change the financial scope, not the requirement for trustworthy validation before reopening.
What to watch next
Under reviewWatch for an official Blockstream or Elements advisory that identifies affected and fixed releases and explicitly establishes the status of Elements v23.3.4.
Require successful corrected or uncached cryptographic-validation results before deploying a release or reopening processing. Track publication of transaction IDs and a ledger that reconciles reserves, liabilities, returned funds, retained funds, fees, peg-outs, and outstanding assets.
If unexplained balances remain, keep processing suspended; if evidence of stolen signing keys emerges, expand containment beyond the validation path.
Evidence basis
The immediate priority is now exposure-driven rather than score-driven. Adobe Commerce carries the strongest reported end-to-end exploit chain—unauthenticated entry through code execution and persistence—so it ranks first for same-night act…
The core trust failure was deterministic validation. CertiK reports that Elements’ range-proof cache used an ambiguous key: distinct validation inputs could collide, and a cache hit occurred before commitment parsing and cryptographic verif…
Summary: Compromise evidence outranks exposure, and exposure outranks product category. MikroTik, Adobe Commerce, F5 BIG-IP APM, and Microsoft’s exploited Windows flaws require immediate but separate response tracks. Check Point’s ChatGPT f…
Public value history
- 09 Sep 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableMorning roundtableConvened 09 Sep 2026Methodology
How the panel reaches a Public Decision Record.