- Following the $320 million exploit, Liquid Network has started producing blocks again, and peg-in and peg-out activities are still on hold.
- By taking advantage of a flaw in Elements, the underlying software of Liquid, attackers created almost 4,000 unbacked LBTC.
- The federation’s Bitcoin stockpile was depleted by about 3,996 BTC, with about 598.5 BTC remaining after 3,400 BTC were reimbursed.
Blockstream and the Liquid Federation restarted controlled block production on September 10. Four days before that, a weakness in the free Elements software let attackers create 4,000 Liquid Bitcoin that had no backing. Blockstream and the Liquid Federation worked fast to keep the network safe.
The network is currently producing blocks without user transactions as operators monitor the system. Functionary and bridge nodes have been updated, but peg-in and peg-out operations remain suspended.
Before the exploit, the Liquid reserve held around 4,205 BTC. After the malicious peg-out and other transactions processed before the network was halted, the balance dropped to roughly 197 BTC.
Back said the LBTC-to-BTC 1:1 peg would be covered and urged holders not to panic-sell LBTC over the counter while the recovery process continues.
Elements Bug Let Attackers Create 4,000 LBTC Out Of Thin Air
The assault took advantage of a consensus flaw in Elements, the program that powers Liquid. Attackers were able to create 4,000 LBTC without putting in the required Bitcoin because of the vulnerability.
The transaction was carried out using SideSwaps Peg‑out Authorization Key (PAK), which was employed to move the LBTC. In the end, 3,996 BTC were sent from the federation‑controlled wallet to an address controlled by attackers.
No Bitcoin was stolen from the Bitcoin network, and no federation keys were compromised during the incident.
3,400 BTC Recovered
The people who attacked later said they were “whitehats”, and they sent back 3,400 BTC to the federation peg wallet on September 7. Around 598.5 BTC, which was worth around $47 million at that time, is still not returned.
LIQUID NETWORK UPDATE: OPERATIONS RESUMED, RECOVERY ONGOING
Status as of September 10, 2026, 10:00 UTCRecovery Status
The Liquid Network has entered the next phase of its controlled resumption. As a precautionary measure, block production has resumed without transactions while… https://t.co/PbyBXIzdQc
— Liquid Network 🌊 (@Liquid_BTC) September 10, 2026
On September 9, the Liquid Network announced the emergency release of Elements v23.3.4, which addresses the proof-verification cache vulnerability by hardening the cache keys used for range proofs. Functionary nodes were being updated immediately, while all Liquid node operators were advised to install the release. The update underwent internal and external reviews involving the Bitcoin Red Team, Alpen Labs and other security researchers.
SideSwap also acknowledged operational weaknesses, including keeping its PAK online and lacking effective limits based on transaction size, velocity, supply or wallet history.
The Elements vulnerability created the unbacked LBTC, while these operational gaps allowed the fraudulent tokens to be converted into real Bitcoin.
@liquid_btc network resumption coming up.
obvious question will LBTC:BTC 1:1 peg be covered; answer YES, so do not panic sell OTC as @PabloSGreco and team are working on more system updates to resume the peg in/out, which happens in a later step. https://t.co/eQAVbQKNi3— Adam Back (@adam3us) September 10, 2026
Liquid Begins Three-stage Recovery
Liquid is following a staged recovery plan. The first stage, restarting block production, is now underway. The network plans to replay valid transactions before eventually restoring peg-ins and peg-outs. Elements version 23.3.4 was released on September 9 with a security fix targeting the range-proof cache vulnerability.
Stay informed with the latest trends in Web3, blockchain innovation, and cybersecurity updates at 3verseTV
You need to login in order to Like










Leave a comment