Liquid Network has restarted block production on its Bitcoin sidechain after a significant security breach that resulted in the unauthorized extraction of roughly 4,000 Bitcoin, valued at $320 million. Despite the progress, transaction processing and peg-out capabilities remain suspended as security checks continue.
Major breach exposes critical flaw
On September 6, individuals presenting themselves as ethical security researchers exploited a vulnerability in Liquid’s codebase, Elements, which underpins the sidechain. The flaw was located in the proof-verification cache, a system that manages the storage of validated confidential transaction proofs to boost node efficiency.
This weakness allowed old proof results to be reused where validation should have failed—enabling attackers to mint L-BTC, Liquid’s Bitcoin-pegged asset, without depositing an equivalent amount of Bitcoin into the network’s reserve wallet.
Using SideSwap’s authorized withdrawal process, the attackers presented the unbacked L-BTC tokens as legitimate, prompting the federation to release approximately 3,996 Bitcoin and reducing the wallet’s balance from about 4,205 BTC to just over 200 BTC.
Investigation confirmed that none of the federation’s cryptographic signing keys were compromised; rather, the incident originated from faulty software logic that incorrectly validated L-BTC redemptions.
Partial recovery and ongoing negotiations
Communication between Blockstream, the company behind Liquid, and the exploiters took place through encoded messages embedded in Bitcoin transactions. The attackers pledged to return the majority of the assets once security patches were applied across the network.
After Blockstream confirmed that key elements of the system had been patched, the attackers sent back 3,400 BTC, worth about $270 million, restoring a significant portion of the stolen amount.
Charles Guillemet, Chief Technology Officer at Ledger, criticized the decision not to return 598 BTC still in the attackers’ possession. He argued that withholding these funds without a clear arrangement more closely resembles extortion than a security bounty.
To date, approximately 598 BTC—valued at around $46 million—remains unreturned. There is currently no timeline for its recovery, nor has any agreement been reached regarding its eventual status or the terms of its potential return.
Emergency patch deployed, service restrictions persist
Liquid released an emergency update, Elements v23.3.4, on September 9. The patch alters the cache key storage method during range proof validation, effectively fixing the exploited vulnerability. Functionary nodes and bridging infrastructure received the patch before block signing resumed.
The Liquid federation operates under a structure that requires 11 out of 15 functionary operators to sign off on transactions. Currently, block production is running in a restricted mode, with transactions and peg-outs still disabled. This approach allows technical teams to monitor system stability before restoring full functionality.
L-BTC holders remain unable to redeem their tokens for Bitcoin through standard procedures due to the continued suspension of bridge and withdrawal operations. No U.S. regulatory body has publicly commented on or announced any enforcement action connected to the incident.
Amid a broader reevaluation of trust in custodial systems, the importance of direct asset control and continuous ecosystem monitoring is growing. While traditional financial markets rely on layers of intermediaries, the move toward decentralized ownership is accelerating. Investors are gradually adopting platforms such as 1stepSwap, which enable users to hold shares of leading U.S. equities alongside gold and silver within their crypto wallets. These solutions tokenize real-world assets and route orders to the best market prices automatically, eliminating the need for intermediaries.




