Web3 Daily Exploits — 08 Sep 2026: Liquid $47M Still Out + BNB Router Drains

Liquid actors returned 3,400 BTC and kept ~598.5 BTC (~$47M) without a signed bounty. Two fresh BNB Chain drains: a DEX router approval sweep of ~62.28 BNB and a WealthManagementV2 owner-key hit for 26,414 USDT.

Web3 Daily Exploits — 08 Sep 2026: Liquid $47M Still Out + BNB Router Drains

The last 24 hours were an aftermath window, not a quiet one. The Liquid Network peg-out that dominated yesterday’s brief moved from “claimed whitehat, funds parked” to a partial return: 3,400 BTC came back on-chain; about 598.5 BTC (~$47M) did not. Separately, SlowMist and ExVul confirmed two BNB Chain incidents first reported in this window — a permissionless DEX-router callback that swept standing approvals for ~62.28 BNB, and a WealthManagementV2 owner-privilege change that printed 26,414 USDT of inflated interest.

Security monitors checked in the window include DefimonAlerts, CertiKAlert, Phalcon, GoPlusSecurity, SlowMist_Team, PeckShieldAlert, BlockSecTeam, Lookonchain, Immunefi, and related desks. ZachXBT and CyversAlerts had no qualifying incident posts in the cutoff. All dollar figures below are live amounts still outside protocol control unless a return is cited with a transaction.

Liquid Network (UPDATE) — 3,400 BTC returned, ~598.5 BTC (~$47M) still out (Bitcoin / Liquid) — Partial return / network still paused

What happened: After the 6 Sep unauthorized peg-out of approximately 3,996–3,998.5 BTC from the Liquid Federation reserve, on-chain monitors confirmed a 3,400 BTC return on 7 Sep. PeckShield, CertiK, and GoPlus all recorded the same split: 3,400 BTC back to the federation peg address, 598.5 BTC retained by the actors (15% of the original take). GoPlus noted that the 15% cut was taken unilaterally and that the project had not signed off on it. An encrypted on-chain ping from the project to the actor address followed the refund by roughly seven hours.

Protocol / chain / asset: Liquid Network (Bitcoin sidechain / Elements) / BTC and L-BTC.

Loss: Original take ~3,996.01834922 BTC (~$320M at contemporaneous prices). Returned 3,400 BTC (~$268M in CertiK’s contemporaneous print). Outstanding ~598.5 BTC (~$47M). Treat the remainder as live loss until it is returned or an official bounty is published.

Attack type: Consensus / rangeproof-verification cache issue in certain Elements builds, followed by a standard SideSwap peg-out. Federation keys and the SideSwap PAK themselves remain reported uncompromised.

Technical details: CertiK’s 8 Sep analysis aligns with Phalcon’s earlier preliminary read. Setup and inflation transactions landed on 6 Sep around 13:52–13:53 UTC. A cache-key encoding in Elements’ rangeproof verification cache allowed two different validation inputs to map to the same cached success, so rangeproof checks could be bypassed and unbacked L-BTC created. Those units were then pegged out through the normal SideSwap path (2.65138358 L-BTC, then 3,996.01834922 L-BTC). Bitcoin L1 executed a Federation-signed payout; it was not itself exploited. Independent nodes that rejected the divergent block stalled while Federation / Blockstream-advertised peers advanced — a clean consensus split around Liquid block 4,050,336.

Blockstream has since said bridge nodes are patched and Federation members are preparing a coordinated restart. The sidechain remains paused. Other Liquid assets (USDT, DePix, RWAs) were not reported as newly minted; they were frozen by the pause.

Explorer / status links: Return transaction: https://mempool.space/tx/a6d697a25266ce3c78774fd1d75f896b7af522ada209b0f6228ea497bc49a46d. CertiK write-up: https://www.certik.com/blog/liquid-network-incident-analysis.

Status: Partial return confirmed on-chain. ~598.5 BTC still held by the self-described whitehats. Network paused; restart being prepared. Whitehat label remains the actors’ own. No official signed bounty for the 15% retain was published in this window.

Sources: https://x.com/CertiKAlert/status/2097005227232612437, https://x.com/CertiKAlert/status/2097287047014752449, https://x.com/PeckShieldAlert/status/2097123918889062821, https://x.com/GoPlusSecurity/status/2097166847288496599, https://x.com/Phalcon_xyz/status/2096911556076572929

Unnamed BNB DEX router — ~62.28 BNB (BNB Chain) — Confirmed

What happened: An on-chain DEX aggregator / swap router on BNB Chain was drained for approximately 62.28 WBNB. ExVul flagged the attack on 7 Sep; SlowMist published a matching TI alert in this window. A no-capital attacker flash-swapped 1 WBNB from PancakeSwap, deployed a fake “pool,” and used the router’s existing user allowances to pull tokens from 29 wallets in a single contract-creation transaction, then dumped the proceeds for BNB.

Protocol / chain / asset: Unnamed DEX router / aggregator on BNB Chain. Assets swept were whatever those 29 addresses had approved to the router; realized profit reported as ~62.28 WBNB.

Loss: ~62.28 BNB. No recovery or project statement identified at time of writing.

Attack type: Unsafe Uniswap V3-style callback / allowance drain. The router did not verify that msg.sender was a factory-derived pool and did not bind the callback payer to a trusted swap context.

Technical details: SlowMist and ExVul describe the same primitive. The router exposes a permissionless swap entry and an unsafe uniswapV3SwapCallback that pays a caller-supplied payer via transferFrom. factoryV3 is reported as the zero address, so a canonical pool address cannot be recomputed. The attacker’s fake contract implemented the V3 pool swap selector, re-entered the router callback, named each victim as payer, and pulled tokens under standing infinite approvals. Tokens were dumped through Pancake pairs; the flash-swap was repaid; ~62.28 WBNB remained.

Users who ever approved the listed router should treat that allowance as live risk and revoke it. This brief does not list revocation steps beyond that warning.

Explorer links:

Status: Confirmed on-chain by ExVul and SlowMist. Funds moved. No public recovery.

Sources: https://x.com/exvulsec/status/2097004102240842230, https://x.com/SlowMist_Team/status/2097153762746159228

WealthManagementV2 — 26,414 USDT (BNB Chain) — Confirmed

What happened: SlowMist flagged a 26,414 USDT loss from a WealthManagementV2 contract after owner privileges were moved to an attacker-controlled address. With ownership, the new controller could rewrite plan parameters with no timelock and no bounds, mint inflated interest in one transaction, then unlock and withdraw it through a second investment.

Protocol / chain / asset: WealthManagementV2 on BNB Chain / USDT.

Loss: 26,414 USDT. No recovery reported.

Attack type: Suspected owner-key compromise (or illegal owner transfer) plus unbounded admin configuration.

Technical details: SlowMist’s TI note: the new owner called updatePlanConfig to set period=0 and interestMultiplier / unlockMultiplier=528,300,000. Investing and redeeming in the same transaction minted the inflated interest; a second investment unlocked and withdrew it. Root cause of the owner change is listed as suspected private-key leak, not a demonstrated authentication bypass in the contract itself.

Explorer links:

Status: Confirmed by SlowMist. Funds moved.

Sources: https://x.com/SlowMist_Team/status/2097222515009724817

Also noted

  • Defimon posted an on-chain SEAL 911-style recovery message aimed at the controller of 0xefeafc09e7f2c84fd11678093dbfde8cf386cbcf, proposing a 10% bounty on 12.237 ETH proceeds of MiniRouter2 transaction 0xacce7431a0019bda373f60f2da37f70b1415d077b6d62851bc17f6bf596b14ce on Robinhood Chain (4663). The original drain time is not independently dated in that post; treat as a recovery thread, not a newly confirmed first-report exploit. Source: https://x.com/DefimonAlerts/status/2097060513498718324
  • Cozy Finance (~$170k, Optimism) and Secured Finance (~$104k, Ethereum) remain confirmed from the prior brief. No material new loss figures in this window.
  • Notional V1 (~$1.73M, 4 Sep) received additional SlowMist analysis and a separate SlowMist watch on BSC copycat fCash positions that had not yet been fully executed as of 7 Sep 03:42 UTC. Those items sit at or outside the strict 24-hour new-incident cutoff and are not re-scored here.
  • Cronos / Tectonic rollback coverage recirculated in retail accounts during the window. The halt and rollback themselves were covered in the 31 Aug brief. No new confirmed loss figure in the last 24 hours.
  • Immunefi published monthly payout stats, not an incident. BlockSec posted marketplace availability on BNB Chain, not an incident.
  • ZachXBT and CyversAlerts: no qualifying posts in the window.

Sources & references

Editor’s note: Live-loss total on the card is the Liquid remainder (~$47M) plus the two new BNB Chain drains. Whitehat claims are recorded as claims. No how-to or exploit reproduction details are included. Verify explorers and official channels before acting on any alert.