Key Takeaways
- Block production has resumed on Liquid Network, though transaction processing and peg-in/peg-out services stay offline
- Individuals identifying as ethical hackers extracted approximately 4,000 Bitcoin valued at $320 million from the network
- Following node patches, 3,400 BTC (approximately $270 million) was sent back to the federation
- Roughly 598 BTC valued at $46 million has not been returned, with no official agreement disclosed
- Blockstream deployed Elements v23.3.4 as an emergency patch to resolve the proof-verification vulnerability
The Liquid Network has reactivated block generation on its Bitcoin sidechain infrastructure, though core transaction capabilities and bridging functions continue to be disabled after a major security breach resulted in the unauthorized withdrawal of $320 million worth of Bitcoin.
The Breach Explained
Individuals claiming white-hat hacker status successfully extracted close to 4,000 Bitcoin from Liquid’s federated custody system on September 6. This withdrawal accounted for approximately 95% of all Bitcoin held in the federation wallet at that moment.
The extraction became feasible due to a vulnerability in Elements, the foundational open-source codebase that operates the Liquid platform. This security gap existed within the proof-verification caching mechanism, a component designed to store validated confidential transaction proof outcomes to prevent redundant computational processes across network nodes.
The vulnerability allowed previously validated proof results to be inappropriately reused in contexts where verification should have returned a failure. This enabled the attacker to mint L-BTC, the network’s Bitcoin-pegged asset, without the required collateral of actual Bitcoin being secured in the federation’s custody first.
The attacker subsequently submitted these unbacked L-BTC tokens via SideSwap’s authorized peg-out mechanism. The system executed the withdrawal request as if it were legitimate, triggering the federation to release approximately 3,996 actual Bitcoin. This drained the wallet from roughly 4,205 BTC down to just 202 BTC in a single transaction.
Importantly, no federation cryptographic signing keys were compromised. The vulnerability existed purely in the validation logic that determines whether L-BTC tokens presented for redemption are authentically backed.
Fund Repatriation Timeline
Communication between Blockstream and the individuals behind the withdrawal occurred through on-chain messaging encoded within Bitcoin transactions. The actors indicated their intention to repatriate the extracted funds once network nodes received proper security patches.
Following Blockstream’s verification that all bridge infrastructure nodes had been successfully updated, the actors transferred back 3,400 BTC, representing approximately $270 million in value at that time. This returned about 85% of the total amount originally withdrawn.
Approximately 598 BTC, currently valued at roughly $46 million, continues to remain in addresses associated with the original withdrawal transaction. No public disclosure has clarified whether this represents an agreed-upon bug bounty compensation or if additional returns are expected.
Charles Guillemet, serving as Chief Technology Officer at Ledger, openly challenged the white-hat characterization of the actors. He expressed concern that retaining approximately 600 BTC without transparent terms resembles extortion rather than conventional responsible disclosure practices.
Technical Remediation and Network State
Liquid distributed an urgent software patch, Elements version 23.3.4, approximately 24 hours before reinitializing block production capabilities. This update fundamentally modifies the cache key generation methodology used during range proof validation processes, effectively eliminating the exploit vector.
Both functionary signers and bridge nodes implemented the security update prior to the resumption of block signing operations. Liquid’s federated model incorporates 15 functionaries in a rotating configuration, with 11 signatures required to authorize fund movements.
While block generation has resumed, the network currently operates in a restricted mode without processing user transactions. Liquid indicated this precautionary measure allows thorough validation of deployment stability before reactivating additional network capabilities.
All peg operations, including PAK-authenticated withdrawals, remain completely suspended. Liquid has not provided a specific timeline for when transaction processing or bridge functionalities will be restored to full operation.
Token holders currently have no ability to convert their L-BTC back into native Bitcoin through standard redemption channels. As of this writing, no United States regulatory body has publicly announced enforcement actions or investigations connected to this security incident.





