Network Enters Controlled Recovery After $320 Million Exploit
Liquid Network has resumed block production following the roughly $320 million exploit that drained most of the Bitcoin backing its L-BTC token, but normal transactions and peg operations remain disabled as operators work to restore the network’s BTC reserves.
In an update dated September 10 at 10:00 UTC, Liquid said it had entered the next stage of a controlled resumption. Functionary nodes are again signing and validating blocks after required updates were deployed to functionary and bridge nodes, but the network is deliberately producing blocks without processing normal user transactions while operators monitor stability.
Peg operations also remain suspended, including peg-outs authorized through Peg-out Authorization Keys, or PAKs. Liquid said restoration of the BTC/L-BTC reserve remains in progress.
That means the network is technically producing blocks again but has not yet returned to normal economic operation.
The cautious restart follows the September 6 exploit in which an attacker created unbacked L-BTC through a flaw in Elements, the open-source software underlying Liquid, and then used the tokens to withdraw nearly 4,000 BTC from the federation wallet.
The transaction moved approximately 3,996 BTC through SideSwap’s authorized peg-out system. Liquid and SideSwap have said the relevant PAK was not compromised. Instead, the exploit stemmed from a transaction-validation problem that allowed invalid L-BTC to be treated as legitimate before being redeemed for actual Bitcoin.
At the time, the federation wallet held roughly 4,200 BTC, meaning the withdrawal removed about 95% of the reported reserve backing L-BTC.
The actors responsible identified themselves through on-chain messages as white hats and said they would return the funds after the underlying vulnerability was patched.
On September 7, they returned 3,400 BTC to the Liquid Federation wallet after Blockstream told them that affected bridge nodes had been patched. Approximately 598.5 BTC remained in the withdrawal-linked address after that repayment.
The remaining amount has become one of the most important unresolved questions in the recovery.
A subsequent on-chain message attributed to the actors demanded that Blockstream fund what they described as a 10% bug bounty with its own money rather than pass a loss on to L-BTC holders. Blockstream has not publicly accepted that demand as an agreed bounty.
Meanwhile, Blockstream released Elements version 23.3.4 on September 9 as part of the recovery effort.
The official GitHub release includes a change that hardens the cache keys used for range proofs and adds an option to disable the relevant range-proof cache. Liquid said the release addressed the proof-verification cache vulnerability involved in the incident.
The recovery plan outlined by Liquid involves several stages.
The first is restarting block production while keeping peg operations suspended. The next involves replaying transactions that have been verified as valid. Peg operations are expected to resume only after network state has been restored, including the restoration of funds needed for the backing reserve.
The latest restart therefore represents progress, but not full recovery.
Community frustration had already started to emerge before block production resumed. In a discussion on Blockstream’s Reddit community, one user questioned who would ultimately cover the missing roughly 600 BTC, while another complained on September 10 that an expected 48-hour recovery period had passed while the network remained unavailable.
Blockstream co-founder and CEO Adam Back sought to address the reserve concern on September 10, saying publicly that the L-BTC-to-BTC peg would be covered 1:1 and urging holders not to panic-sell L-BTC in over-the-counter markets while further system updates were completed.
Back said peg-ins and peg-outs would return at a later stage.
Liquid’s own documentation defines the peg on the same basis: every L-BTC is intended to be backed by an equivalent amount of BTC held by the federation, with L-BTC destroyed when users peg out and Bitcoin released from the federation wallet.
For now, however, users still cannot fully test that promise because peg-outs remain disabled.
The Real Recovery Test Is the 1:1 Reserve
Restarting block production is technically important, but it is not the point at which this incident becomes economically resolved.
The decisive moment will come when Liquid reopens withdrawals.
As long as transactions and peg-outs remain disabled, the network does not have to satisfy a wave of users trying to convert L-BTC back into BTC at the same time. That gives operators room to repair network state, reconcile balances and restore reserves without immediately exposing any shortfall.
Once peg-outs reopen, that changes.
Liquid’s core promise is straightforward: one L-BTC corresponds to one BTC. Its own documentation describes the relationship as a 1:1 peg, not a floating reserve ratio or partially collateralized token.
That makes the remaining roughly 598.5 BTC more important than the fact that most of the original withdrawal has already been returned.
Recovering 3,400 BTC dramatically reduced the size of the problem, but it did not automatically restore full backing.
Someone still has to close the gap if the remaining coins are not returned.
Back’s public statement that the peg will be covered is therefore significant. It tells L-BTC holders what outcome Blockstream expects, but it does not yet tell them how that outcome will be financed.
There are several possibilities.
The remaining Bitcoin could still be returned by the actors. Blockstream or another party could contribute BTC. Federation members could share the cost. An insurance or reserve mechanism could be used. Or some combination of those options could close the difference.
Until Liquid explains the source of the restored reserve, investors do not yet know where the economic loss ultimately lands.
That distinction matters because the exploit was not simply a temporary liquidity event.
Unbacked L-BTC was created and successfully converted into real Bitcoin. The software failure therefore transformed a validation bug directly into a reserve loss.
The recovery now has two separate tasks: prove that the code path which allowed that to happen has been fixed, and prove that every legitimate L-BTC still outstanding is once again matched by a real BTC.
Elements v23.3.4 addresses the first problem by hardening range-proof cache verification.
The second problem is financial rather than purely technical.
That is why restarting blocks without transactions is a sensible intermediate step but should not be mistaken for a full reopening.
The network can produce perfect blocks and still have an unresolved backing issue.
Liquid’s credibility will therefore depend heavily on what happens immediately before peg-outs resume. Ideally, operators will disclose the restored reserve position, explain whether the 598.5 BTC was recovered or replaced, and confirm that the circulating L-BTC supply is fully collateralized before users are again allowed to redeem.
If that happens, the episode becomes a costly software failure followed by a managed recapitalization and recovery.
If the network reopens without clearly demonstrating full backing, attention will quickly shift from the original exploit to whether L-BTC can still be treated as unquestionably redeemable at par.
For Liquid, getting blocks moving again was the first test.
Restoring the 1:1 peg before users can move their money is the more important one.
Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.
He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.
Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

