Liquid Network resumed block production on Thursday, though operations are running entirely without user transactions. The initial recovery phase comes after an exploit drained approximately 3,996 BTC - worth $320 million - from its primary reserves.
The exploit originated from a verification vulnerability within the Elements software. The attacker leveraged the flaw to mint unbacked L-BTC tokens without actual Bitcoin collateral behind them. These uncollateralized assets were then used to withdraw 3,996 real BTC via SideSwap’s peg-out service. The Liquid federation wallet, which initially held 4,205 BTC, plummeted sharply to leave just 202 BTC. The single withdrawal drained roughly 95% of the network’s total reserve funds in a short span.
Code Patch and Frozen Transactions
Developers released an emergency Elements v23.3.4 update shortly after the incident. This technical patch alters how cache keys function during the range proof validation process. The code adjustment aims to ensure that valid verification results cannot be reused across different transaction contexts.
The software update enabled functionary nodes to resume block production, but user asset traffic remains halted. All ingress and egress options - including peg-ins, peg-outs, and Peg-out Authorization Keys (PAK) features - remain disabled. Regular L-BTC transfers between wallets are also completely frozen.
Developers stated that pausing transactions was necessary to ensure network stability before reopening remaining services. As of now, there is no definitive timeline for when operations and the bridge to the Bitcoin mainnet will fully return to normal.
Attacker’s Message and SideSwap’s Clarification
The actor behind the massive withdrawal left a message embedded within a Bitcoin transaction. The message claimed that they were acting as a group of white-hat hackers. The Liquid team responded to the written claim by characterizing the perpetrator as merely an entity “claiming” to be a white-hat.
SideSwap, acting as the facilitator service, shared an internal summary from the provider side. Their peg-out service processed the user’s incoming 4,000 L-BTC like a standard transaction, unaware of the exploit on the underlying Liquid network. SideSwap confirmed that their system authorization keys remained secure from external access and were never hacked or compromised.
Liquid’s infrastructure is gradually being reactivated following the $320 million loss. Although blocks are being produced again, users must still wait for further fixes before the system is securely reconnected to Bitcoin.
Reported by crypto.news.
Previously: Blockstream Bargains for Remaining 600 BTC - But Ledger Chief Calls It Extortion
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




