Community Trust ScoreVerified
Liquid Network is back producing blocks. Sort of. Transactions are still off, peg operations are frozen, and nearly 600 Bitcoin hasn’t come back yet.
The network confirmed its functionary nodes restarted block production after a staggering incident that saw roughly 3,996 BTC — about 95% of everything sitting in the federation wallet — drained in a single exploit. At the time, that haul was worth around $320 million. Blockstream, which launched Liquid back in 2018, moved fast on a software patch and opened a strange, tense back-channel with the people who took the money. The actors claimed to be white-hat hackers. Not everyone bought that.
The peg operations — the mechanism users rely on to swap L-BTC back for real Bitcoin — remain suspended while the network works to rebuild its reserve.
How the Exploit Actually Worked
The flaw lived inside Elements, the open-source software that powers Liquid. Someone found a way to game the range proof validation system. Range proofs are supposed to confirm that hidden transaction amounts are legitimate without actually revealing the numbers — it’s a core privacy feature. The bug let invalid proofs get reused, which meant an attacker could mint L-BTC that had zero Bitcoin backing it. Basically, they created money out of nothing.
Once the unbacked L-BTC existed, the actor pushed a peg-out through SideSwap. SideSwap’s process treated the request as legitimate. Real Bitcoin left the federation wallet. About 3,996 BTC worth, which is a pretty catastrophic outcome for a network built around the idea that every L-BTC is fully backed.
Liquid’s emergency fix came as Elements v23.3.4. The update changed how cache keys work during range proof validation, closing the hole that made reuse possible. Functionary nodes and bridge nodes both got the patch.
The federation structure itself — 15 rotating functionaries, 11 signatures required to move any funds — didn’t fail in the way you might expect. No signing key was stolen. The problem was purely in the software layer, not in the key management or the multi-sig setup. That’s a meaningful distinction, even if it doesn’t make the missing Bitcoin any less real.
Negotiations Over Bitcoin Transaction Messages
Here’s the part that’s genuinely strange. Blockstream and the actors didn’t communicate through lawyers or email or any normal channel. They embedded messages directly into Bitcoin transactions. The actors said they’d return the funds once the vulnerabilities were patched and confirmed. Blockstream patched. The actors, apparently satisfied, sent back 3,400 BTC. That’s roughly 85% of what was taken.
The remaining 598.5 BTC — worth around $46 million — hasn’t moved back. There’s no public agreement covering it. Liquid hasn’t called it a bounty. The actors haven’t publicly committed to returning it. It’s just… sitting there, unresolved.
Ledger’s CTO Charles Guillemet didn’t mince words on the white-hat framing. He said the situation looks more like extortion than ethical security research. He’s probably not alone in thinking that. White-hat hacking usually involves responsible disclosure before any funds move, not after draining 95% of a network’s reserves and then negotiating from a position of holding nearly $50 million.
What’s Still Broken and What Comes Next
Liquid is keeping transactions disabled for now. The logic is straightforward — restarting blocks without enabling transactions lets developers watch the system under real conditions without adding the pressure of live user activity. It’s a cautious move, maybe the right one, but it leaves the network in a pretty awkward half-operational state.
No timeline for full restoration has been shared publicly. Peg operations stay off until the reserve is rebuilt to a level the team considers safe. With 598.5 BTC still outstanding and no public deal in place, that rebuild depends partly on whether those funds ever come back.
No U.S. regulatory actions have been announced in connection with the incident. Whether that stays true as the situation drags on is unclear.
The broader question for Liquid’s users and the Bitcoin layer-2 space is what this episode says about proof-verification security in complex blockchain systems. The multi-sig federation held. The software didn’t. And 598.5 BTC, roughly $46 million, remains with actors whose next move nobody has officially confirmed.
Frequently Asked Questions
What caused the Liquid Network exploit that drained 3,996 BTC?
An actor exploited a flaw in Elements software that allowed invalid range proofs to be reused, enabling the creation of unbacked L-BTC which was then pegged out through SideSwap for real Bitcoin.
How much Bitcoin has been returned to Liquid Network so far?
3,400 BTC was returned to the federation wallet after vulnerabilities were patched, covering about 85% of the withdrawn funds. Approximately 598.5 BTC, valued at roughly $46 million, has not been returned.
Why It Matters
The ongoing situation with Liquid Network highlights significant vulnerabilities within federated blockchain systems, raising concerns about the security mechanisms in place for managing large reserves of Bitcoin. As the network struggles to restore normal operations and recover the missing funds, it may impact user confidence and prompt a reevaluation of risk management practices among similar platforms in the cryptocurrency ecosystem. This incident could also influence regulatory scrutiny, as the potential for high-profile exploits presents challenges for the broader adoption of decentralized finance solutions.




