Liquid has resumed block production and transactions after an Elements vulnerability created unbacked LBTC, while peg-outs remain suspended and Blockstream says 598.5 BTC is still outstanding.

Bitcoin mining hardware in a mining farm. Photo: Marko Ahtisaari via Wikimedia Commons (CC BY 2.0). Source
Liquid resumed transactions on Sept. 10 after pausing its network over an exploit that its operators say created roughly 4,000 LBTC without matching bitcoin in the federation reserve. The restart did not restore the system's full bridge function: block production and transactions were running again, but peg-outs, the process that turns LBTC back into bitcoin on Bitcoin's main chain, remained disabled while the final recovery stage continued, according to Liquid's latest status update.
The partial restart followed a week in which Liquid and Blockstream, its technical provider, described a software vulnerability, a halt to bridge operations, a patch, the return of 3,400 BTC, and an unresolved shortfall. On Sept. 11, Blockstream said it would not pay a ransom for the return of the remaining funds. It said it had tried in good faith to secure a return, but did not disclose the requested terms, identify the people it was communicating with, or state the amount of any demand in its public statement.
The companies' public accounts are the principal record of the incident. They establish a detailed chronology and describe the technical path they believe was used, but they are not an independent forensic report. Liquid said its investigation was ongoing on Sept. 8 and promised further detail; neither Liquid's incident report nor its later recovery status published a named attribution, a final technical report, a timetable for restoring peg-outs, or confirmation that the reserve had been made whole.
Liquid's Sept. 8 incident report placed the exploit at 15:53:10 UTC on Sept. 6, at Liquid block 4,050,336. It said a vulnerability in the open-source Elements software, involving how Liquid nodes cached range-proof verifications, allowed the creation of about 4,000 LBTC that was not backed by bitcoin held in reserve. A range proof is part of Liquid's confidential-transaction system, which normally allows nodes to verify a hidden transaction amount is valid without revealing that amount. The report did not say when the vulnerability entered the code or how the people behind the exploit found it. Liquid's incident report is the source for both the technical account and the figures.
LBTC is the bitcoin representation used on the Liquid sidechain. Under Liquid's published technical documentation, bitcoin moved into Liquid is represented as LBTC and is intended to have an equivalent amount of BTC secured by federation functionaries. The same documentation describes Liquid as an Elements-based sidechain with a federated consensus model, rather than Bitcoin's proof-of-work model. That structure is relevant here because the incident centered on LBTC accepted inside the sidechain and then exchanged for bitcoin from the federation's reserve. Liquid's technical overview describes the network architecture and the stated BTC-to-LBTC relationship.
According to Liquid, the people responsible used SideSwap, a Liquid Federation member holding a Peg-out Authorization Key, or PAK, to convert the unbacked LBTC through the regular peg-out mechanism. A PAK is a control used to authorize a destination for a withdrawal from Liquid to Bitcoin. Liquid's documentation says a peg-out burns LBTC on Liquid and causes the federation to release equivalent BTC on the Bitcoin chain, and that the general public ordinarily uses a federation member or exchange for that service rather than peg out directly. The peg-in and peg-out documentation explains that process and its access restrictions.
Liquid said the range-proof validation failure happened before the peg-out was initiated. On the company's account, SideSwap's node and Liquid's functionary nodes therefore accepted the LBTC as valid; the functionaries then processed the withdrawal to a SideSwap-whitelisted bitcoin address, and SideSwap forwarded bitcoin to an address supplied by the exploiters. That is Liquid's explanation of how the software flaw could lead to a main-chain withdrawal, not a finding independently established in the public updates. The incident report also said the SideSwap PAK itself was not compromised.
The reserve held about 4,205 BTC before the incident, Liquid said. After the approximately 4,000 BTC withdrawal and other peg-outs processed before operations stopped, it said the reserve balance had fallen to 197 BTC. The report said no private keys had been compromised, the federation functionaries had not been hacked, and the peg-out authorization mechanism operated as designed. It also said USDT and other Liquid-issued tokens were not affected by the identified vulnerability, although users could not use them while the network was paused. Those are all company statements about scope and controls, not conclusions from a released outside investigation. Liquid's Sept. 8 report provides the reserve figures and the clarifications.
Liquid had announced the incident two days earlier, describing the withdrawal as about 4,000 BTC and saying bridge nodes had been temporarily disabled so no new transactions could be submitted. It said exchanges had been notified and had already paused, or would pause, LBTC deposits and withdrawals. At that point, the network said Liquid wallets would be affected and the sidechain was effectively paused. The same initial notice said the people behind the withdrawal presented themselves as white-hat hackers and that Blockstream was trying to contact them with a signed on-chain message. Liquid's Sept. 6 notice did not establish their identity or independently validate that characterization.
Liquid said Blockstream deployed a patch to Liquid bridge nodes at 01:09 UTC on Sept. 7, describing the vulnerability as no longer exploitable after that deployment. Later that day, at 16:09:25 UTC, it said the exploiters returned 3,400 BTC to the Liquid Federation peg wallet. Liquid put the remaining amount at approximately 598.5 BTC, or 15% of the total involved. The figures are Liquid's reported balance of the recovery at that time; the update did not describe a later return, a source of replacement reserves, or an agreement that settled the remainder. The Sept. 8 incident report records the patch and return times.
The people who withdrew the bitcoin had left a public message on Bitcoin's main chain identifying themselves as white-hat security researchers and seeking contact, Liquid said. That claim initially framed the exchange as a discussion over recovery and disclosure. Blockstream took a different position on Sept. 11. It called the removal and continued withholding of funds theft rather than responsible disclosure, said it would not pay a ransom, and said the bitcoin could still be returned. If the funds were not returned, Blockstream said it would pursue lawful avenues and work with law enforcement, exchanges, service providers and forensic specialists to trace assets and identify those responsible. Blockstream's Sept. 11 statement is a declaration of the company's position and intended actions, not evidence that any law-enforcement action, tracing result, or recovery has occurred.
On Sept. 9, Liquid announced the emergency Elements v23.3.4 release and recommended that all Liquid node operators install it while functionary nodes were being updated. Liquid said the release hardened cache keys used for range proofs, and said it had received internal and external review, including from the Bitcoin Red Team and Alpen Labs. The public v23.3.4 release notes list a change to harden range-proof cache keys and add a -norangeproofcache option. The release notes do not provide a full incident analysis or claim to account for every condition that led to the exploit.
Liquid's recovery plan was initially conditional and explicitly subject to revision as testing and validation continued. Its Sept. 9 update anticipated three stages: resuming block production with peg operations suspended; replaying transactions verified as valid; and resuming peg operations after the network state had been fully restored, including a return of funds. It said Blockstream was testing the first two stages in parallel and would not proceed with a stage until it considered it safe. The Sept. 9 recovery update did not offer a date for the third stage.
By the morning of Sept. 10, Liquid said the necessary functionary and bridge-node updates had been deployed successfully and block production had resumed without transactions while the network was monitored for stabilization. Functionary nodes were signing and validating blocks, it said, while peg operations, including PAK-authorized peg-outs, remained suspended as the effort to restore the BTC/LBTC reserve continued. Liquid's first Sept. 10 update did not say whether the replay phase had been completed or how much bitcoin was then in the reserve.
That evening, Liquid said transactions had resumed. It described functionary nodes as signing and validating blocks and said testing, AI-assisted code scanning, and continuous monitoring by internal and external teams were under way. Peg-outs remained disabled as a precaution while the final recovery stage continued, and Liquid said it would provide more information on their resumption when available. The later Sept. 10 update is the latest user-facing operational status in the primary updates reviewed for this report.
For users, the distinction between transactions and peg-outs is material. A Liquid transaction can again move assets within the network, according to the Sept. 10 status. A peg-out is the separate process that releases BTC from the federation to the Bitcoin chain after LBTC is burned. Liquid's documentation says such withdrawals normally depend on the federation's processing and a valid PAK authorization. With peg-outs still disabled, the restart did not restore that route from LBTC to main-chain BTC. Liquid's recovery status and its peg-out documentation describe the current restriction and the ordinary mechanism.
Liquid told users on Sept. 10 that they did not need to take proactive steps, while urging node operators to update to Elements v23.3.4. It also warned of fraudulent update sites and messages. Blockstream separately said it would never ask users for a recovery phrase or PIN, ask them to send funds, or distribute an updated-software link in response to the incident. It identified supposed recovery addresses, migration sites, claim-LBTC or re-peg sites, unsolicited support messages, and unprompted white-hat or bounty outreach as scam patterns. Blockstream's phishing alert directs users to its official website and official app stores for verified information.
The latest published status leaves several questions open. Liquid's report says about 598.5 BTC remained outstanding after the Sept. 7 return, but the later restart notices do not publish an updated outstanding balance or say the reserve is again fully backed. They do not specify who will cover any unrecovered difference, whether negotiations continued after Blockstream rejected the ransom demand, or when deposits, withdrawals, and other suspended peg operations will return. Blockstream's Sept. 11 statement promises a lawful pursuit of funds if they are not returned, but it names no case, agency, exchange action, or deadline. Until either organization publishes those details, the confirmed user-facing status is narrower: Liquid transactions have resumed, while peg-outs remain disabled. Liquid's Sept. 10 status update provides no reopening timetable.