Web3 Daily Exploits — 07 Sep 2026: Liquid $320M Whitehat Peg-Out + Cozy $170K

Liquid Network sees ~4,000 BTC (~$320M) unauthorized peg-out claimed as whitehat; Cozy Finance loses ~$170k on Optimism via UMA oracle abuse; Secured Finance ~$104k price-manipulation drain on Ethereum; Rocket $287k update.

Web3 Daily Exploits — 07 Sep 2026: Liquid $320M Whitehat Peg-Out + Cozy $170K

Last 24 hours produced one high-value sidechain incident and several smaller DeFi drains. Liquid Network recorded an unauthorized ~4,000 BTC peg-out (~$320M) that the actors labeled whitehat; Cozy Finance lost ~$170k on Optimism; Secured Finance saw ~$104k drained on Ethereum; Rocket’s $287k loss from 5 Sep received further confirmation and pause updates.

Security monitors including DefimonAlerts, SlowMist, CertiKAlert, Phalcon, GoPlus, PeckShield and BlockSec tracked the activity. All figures reflect amounts still outside protocol control at time of writing. No recovery has been confirmed for the major items.

Liquid Network — ~4,000 BTC (~$320M) Unauthorized Peg-Out (Liquid / Bitcoin) — Claimed Whitehat / Network Paused

What happened: On 6 Sep 2026 an unauthorized withdrawal of approximately 3,996–4,000 BTC left the Liquid Federation wallet via SideSwap PAK peg-out. Actors left an on-chain message claiming whitehat status and offering to return funds after nodes are patched.

Protocol / chain / asset: Liquid Network (Bitcoin sidechain) / BTC (L-BTC to BTC).

Loss: ~$320M at contemporaneous prices. Funds remain at collection addresses; no return confirmed.

Attack type: Consensus / rangeproof cache verification issue in certain Elements builds (preliminary analysis) enabling unbacked L-BTC mint and standard peg-out.

Technical details: Apparent consensus divergence around block 4,050,336. Preliminary reports point to a rangeproof-verification cache key that omitted asset commitment and scriptPubKey, allowing cache reuse across contexts. Peg-out executed via SideSwap; federation keys and PAK themselves reported uncompromised. Bridge nodes disabled; network effectively paused. Exchanges notified to pause L-BTC flows. Other Liquid assets (USDT, DePix, RWAs) reported unaffected.

Explorer / status links: Official Liquid statement and on-chain messages referenced in monitors; BTC payout addresses tracked by PeckShield, GoPlus, Phalcon.

Status: Network paused. Actors claim whitehat and condition return on full node patch. Funds still held. Treat as live loss until returned.

Sources: https://x.com/Liquid_BTC/status/2096696272447218108, https://x.com/CertiKAlert/status/2096753096542367837, https://x.com/Phalcon_xyz/status/2096911556076572929, https://x.com/GoPlusSecurity/status/2096859288585286025, https://x.com/PeckShieldAlert/status/2096770715475415121

Cozy Finance — ~$170k (Optimism) — Confirmed

What happened: Attacker drained approximately 163k USDC.e (~$170k) from Cozy Finance protection markets on Optimism on 7 Sep, burning ~1.6M CPT, then bridged funds within 13 minutes.

Protocol / chain / asset: Cozy Finance on Optimism / USDC.e.

Loss: ~$170k. Bridged out; no recovery reported.

Attack type: UMA Optimistic Oracle abuse / trigger logic flaw.

Technical details: SlowMist analysis: contract treated undisputed YES=1e18 UMA price proposals as external attack events without independent verification of underlying Aave/Curve events or pre-event holdings snapshot. Attacker-controlled executor submitted affirmative proposals; markets moved to TRIGGERED, enabling CPT redemption and payout. Attack contract deployed 2 Sep.

Status: Confirmed. Funds moved.

Sources: https://x.com/SlowMist_Team/status/2096881310237426062, Blockaid alerts, BeInCrypto coverage.

Secured Finance — ~$104k (Ethereum) — Confirmed

What happened: Lending market drained ~$104k via flash-loan self-trades that manipulated order-book average price used for collateral valuation. Original attacker partially failed; MEV frontrunner extracted majority of WBTC portion.

Protocol / chain / asset: Secured Finance fixed-rate lending on Ethereum / USDC, WBTC.

Loss: ~$104k total extracted.

Attack type: Price manipulation / order-book collateral valuation flaw (getMarketUnitPrice).

Technical details: Defimon flagged exploit contract 45 min prior. Collateral valued from current-block order fills controllable by attacker. Self-trades inflated price; fake positions treated as collateral. Team paused markets and investigating.

Status: Confirmed. Team investigating recovery.

Sources: https://x.com/DefimonAlerts/status/2096855557575458950

Rocket (UPDATE) — ~$287k — Confirmed / Paused

What happened: On 5 Sep attacker manipulated a dormant perpetual market with inflated self-trades, generated artificial PnL and withdrew ~$287k via Bridge. Deposits, withdrawals and trading remain paused. Team coordinating recovery and law enforcement.

Protocol / chain / asset: Rocket perpetual platform.

Loss: ~$287k still outstanding.

Attack type: Price manipulation on low-liquidity market.

Status: Confirmed. Services paused; recovery plan in progress prioritizing small accounts.

Sources: Project statements and DefimonAlerts coverage.

Also noted

  • Notional Finance V1 overflow analysis published by SlowMist (incident itself earlier).
  • No additional high-impact confirmed drains newly reported in the window after cross-checks of listed monitors.

Sources & references

Editor’s note: All amounts are live losses still outside protocol control. Whitehat claims are noted but not treated as recovered until on-chain return. No how-to or exploit reproduction details included. Verify on-chain and official channels before any action.