Blockstream and the Liquid Federation have restarted block production on the Liquid Network four days after a consensus bug in the open-source Elements software let attackers mint about 4,000 unbacked Liquid Bitcoin (LBTC) and drain most of the federation’s Bitcoin (BTC) reserve.
Peg-in and peg-out operations remain suspended, and Blockstream Chief Executive Officer (CEO) Adam Back has publicly stated that the 1:1 LBTC to BTC peg will be covered.
Operations Resumed, Peg Still Frozen
The Liquid Network confirmed the controlled restart in an update posted at 12:26 Coordinated Universal Time (UTC) on September 10, 2026, and dated 10:00 UTC. Block production has resumed without user transactions while the network is monitored; functionary and bridge node updates have been deployed, and functionaries are signing and validating blocks. Peg-in and peg-out operations, including peg-outs authorised through Peg-out Authorization Keys (PAK), remain suspended, and the update said “restoring the BTC/LBTC reserve is in progress.”
Adam Back had previewed the move a day earlier, saying a security release and a network resumption plan were coming. On September 10 at 11:02 UTC, he wrote that “network resumption” was on the way and confirmed that the LBTC to BTC 1:1 peg will be covered, urging holders not to panic-sell LBTC over-the-counter (OTC) while Pablo Greco and the team push further system updates ahead of peg-in and peg-out being reactivated in a later step. A follow-up post at 13:13 UTC read: “and @liquid_btc – we’re baaack!” Back also said a full post-mortem is due.
What the Elements Bug Did
The Liquid Network is a federated Bitcoin sidechain launched by Blockstream in 2018. Its native token, LBTC, is designed as a 1:1 claim on Bitcoin held in a multi-signature wallet controlled by 15 federation functionaries, of which 11 must sign to move coins. Users move BTC in through peg-ins, and ordinary redemptions typically clear through a federation member that holds a PAK. SideSwap, a Liquid peg-out service, was the PAK holder in this incident.
According to the Liquid Federation’s official incident report, posted at 19:10 UTC on September 8, the exploit took place on September 6 at 15:53:10 UTC at Liquid block 4,050,336.
A vulnerability in Elements, the open-source software Liquid runs on, let attackers create approximately 4,000 LBTC that were not backed by any deposited Bitcoin. The unbacked tokens were routed through SideSwap’s PAK. Because the validation failure occurred at the transaction level before the peg-out was initiated, both SideSwap’s node and the Liquid Network’s globally distributed functionary nodes accepted the LBTC as valid.
The functionaries processed the peg-out as authorised, releasing about 4,000 BTC through SideSwap’s whitelisted address, which was then forwarded to the address specified by the attackers.
Before the incident, the Liquid reserve held approximately 4,205 BTC. After the malicious peg-out and additional peg-outs processed before operations were halted, the reserve balance fell to 197 BTC. No federation functionary keys, no SideSwap PAK, and no other private keys were reported compromised. Other assets issued on Liquid, including Tether (USDT), DePix, and various tokenised real-world assets (RWAs), were not exploited, though they were frozen during the pause.
SideSwap’s Post-Mortem
In a statement published on September 9, SideSwap gave a more granular timeline and timestamped the inflation transaction at 13:53 UTC on September 6 at the same Liquid block height, differing from the federation’s 15:53 UTC timestamp. SideSwap listed a 2.5 LBTC test peg-out at 14:00 UTC paid as 2.49749857 BTC, followed by the primary 4,000 LBTC peg-out submitted at 14:05 UTC and burned at 14:06 UTC.
The federation payout of 3,996.02 BTC on the Bitcoin main chain followed at 14:28 UTC, and SideSwap forwarded 3,995.99999857 BTC in the same block. SideSwap later returned its 0.1% peg-out fee of approximately 4 BTC to the federation.
SideSwap accepted blame for two operational failures. The PAK was kept online, allowing payouts to land in the same Bitcoin block as the peg-out order, and there were no meaningful size, rate, velocity, supply-cap, or wallet-history checks on peg-out orders, so a large order from a new wallet cleared automatically.
The Elements fault created the unbacked LBTC, but the hot key and missing limits are what converted that paper inflation into roughly 3,996 BTC leaving the federation wallet.
Containment, Return, and Emergency Patch
The Liquid Network’s first public alert was posted at 20:25 UTC on September 6. Bridge nodes were disabled, exchanges were asked to pause LBTC deposits and withdrawals, and the sidechain was effectively halted. Blockstream deployed a bridge-node patch at 01:09 UTC on September 7, and a Pretty Good Privacy (PGP) signed on-chain message from Blockstream confirmed to the actors that it was safe to return funds. The signature is verified against Blockstream’s published security key.
The actors, who identified themselves as “whitehats” through OP_RETURN messages on the Bitcoin main chain, returned 3,400 BTC to the federation peg wallet at 16:09:25 UTC on September 7. Approximately 598.5 BTC, worth roughly $47 million at the time, remains outstanding.
Samson Mow, the CEO of JAN3 and a former Blockstream executive, has publicly called on the actors to return the remaining Liquid Network Bitcoin, with on-chain plaintext from the actors on September 9 demanding that Blockstream “pay 10% using your own money as bug bounty” or “cause all your holders a 15% loss.” Blockstream has not publicly accepted that framing as an authorised bounty, and the Blockstream incident status page has continued to track the incident since the initial report.
The security fix followed on September 9 at 13:30 UTC, when the Liquid Federation released Elements version 23.3.4, which hardens the cache keys used for range proofs. The build was reviewed internally and externally by teams including the Bitcoin Red Team and Alpen Labs. Functionary operators were told to update immediately, and all Liquid node operators were advised to do the same.
The Three-Stage Recovery Plan
Liquid’s staged recovery plan, subject to change based on testing, is to resume block production while peg operations stay suspended, replay transactions verified as valid, and then resume peg operations only after the network state is restored, “including a return of funds.” Blockstream is running tests of the first two stages in parallel and has said no stage will proceed until it is considered safe.
The first stage is now live. SideSwap has said its instant swaps remain paused until Liquid confirms that transactions can clear and that peg-ins and peg-outs will not turn back on until both it and the federation are satisfied that the process is safe.
Analyst View
Three points can be true at once. First, Bitcoin’s base chain operated as designed. The peg-out transactions were valid Bitcoin payments from a federation-controlled wallet, and there was no Bitcoin inflation or compromise of BTC held outside Liquid.
Second, Liquid’s security model failed at the exact layer long flagged by critics: a federated peg combined with complex confidential-transaction code. An 11-of-15 functionary set backed by hardware security modules cannot help if the software those machines run accepts unbacked coins as valid.
Third, Back’s coverage pledge is the difference between a frozen redemption claim and a run. If the federation makes LBTC redeemable 1:1 once peg-outs reopen, the 598.5 BTC gap becomes a balance-sheet and legal question for Blockstream and the federation rather than a haircut for holders.
If “covered” resolves only into “we are working on it,” OTC discounts will persist until peg-outs actually print. The verifiable test remains stage three: peg-outs opened against a published reserve that matches circulating LBTC. Until that step lands, LBTC is a claim on a paused bridge rather than a live 1:1 Bitcoin equivalent. Empty blocks are progress, but they are not the peg.
The Liquid Federation has reminded users to rely only on official channels and warned that fake update websites are already in circulation. Users have been asked not to transfer funds to unknown channels or to disclose private keys or seed phrases.
Also Read: Cronos Rewound 10,961 Blocks to Reverse Tectonic Hack, $9.19M Still Missing
