TLDR
- Liquid Network has restarted block production while maintaining suspension of transaction and peg-out services
- Self-proclaimed white-hat hackers extracted approximately 4,000 Bitcoin valued at $320 million
- Roughly 3,400 BTC worth approximately $270 million was reimbursed following Blockstream’s node patch confirmation
- Approximately 598 BTC valued at roughly $46 million has not been returned with no clear restitution timeline
- Critical software patch Elements v23.3.4 was deployed to repair the proof-verification cache vulnerability exploited in the attack
Liquid Network has reactivated block generation on its Bitcoin sidechain infrastructure, though transaction processing and peg-out mechanisms continue to be disabled after a $320 million Bitcoin extraction that revealed a critical vulnerability in its underlying software.
The Exploit Details
On September 6, individuals identifying themselves as ethical hackers extracted approximately 4,000 Bitcoin from Liquid’s federation custody wallet. This amount constituted about 95% of the wallet’s entire holdings at that moment.
The extraction was enabled by a vulnerability within Elements, the open-source codebase underlying Liquid’s infrastructure. The weakness resided in the proof-verification cache mechanism, a component designed to store validation results for confidential transaction proofs, eliminating redundant computational checks by network nodes.
This vulnerability allowed previously validated proof outcomes to be recycled in contexts where they should have been rejected. The exploiter leveraged this to mint L-BTC, Liquid’s Bitcoin-pegged token, without depositing equivalent real Bitcoin into the federation custody wallet.
The exploiter subsequently transmitted the fraudulent L-BTC through SideSwap’s authorized withdrawal mechanism. The service executed the withdrawal request following standard procedures, prompting the federation to release approximately 3,996 actual Bitcoin, depleting the wallet from roughly 4,205 BTC to approximately 202 BTC.
Importantly, no federation private keys were compromised. The vulnerability existed in the validation logic determining whether L-BTC submitted for redemption was legitimate.
Funds Recovery Developments
Blockstream and the exploiters established communication channels using messages encoded within Bitcoin blockchain transactions. The actors indicated they would repatriate the extracted funds once network nodes received security patches.
Following Blockstream’s verification that its bridge infrastructure had been secured, the actors reimbursed 3,400 BTC, valued at approximately $270 million. This restitution recovered roughly 85% of the initially extracted amount.
Approximately 598 BTC, currently valued at about $46 million, remains held in the address associated with the extraction. No formal arrangement has been publicly disclosed regarding whether this represents a negotiated bounty or if future repatriation is planned.
Charles Guillemet, Chief Technology Officer at Ledger, openly challenged the white-hat classification. He characterized the retention of approximately 600 BTC without transparent terms as resembling extortion rather than a legitimate security bounty.
Technical Remediation and Operational State
Liquid deployed an emergency software patch, Elements v23.3.4, approximately 24 hours before resuming block generation. The patch modifies the cache key storage methodology during range proof validation, eliminating the vulnerability the exploiter leveraged.
Functionary and bridge nodes implemented the security update prior to reactivating block signing operations. Liquid’s federation architecture employs 15 rotating functionary nodes and mandates 11 signatures for fund movements.
Block generation has resumed but operates without processing user transactions. Liquid indicated that maintaining transaction suspension allows the team to verify deployment stability before reactivating additional network services.
Peg-in and peg-out operations, including PAK-authorized redemptions, remain disabled. Liquid has not announced a specific timeline for restoring transaction processing or bridge functionalities.
L-BTC token holders presently cannot exchange their holdings for native Bitcoin through standard redemption channels. No United States regulatory authority has publicly disclosed enforcement actions concerning this security incident.


