Liquid Network Recovers 3,400 BTC After Major Weekend Exploit

Liquid Network recovered 3,400 BTC after a weekend exploit. About 600 BTC remains with the attacker. Operations remain paused as operators patch Elements, verify reserves, and prepare to restore one-to-one L-BTC backing safely before restarting.
Liquid Network Recovers 3,400 BTC After Major Weekend Exploit
Written By:
Yusuf Islam
Reviewed By:
Manisha Sharma
Published on
Updated on

Liquid Network recovered 3,400 BTC worth about USD 268 million on Monday after a weekend exploit drained roughly 4,000 BTC from its reserves. About 600 BTC, or 15% of the withdrawn amount, remains with the attacker. L-BTC deposits and withdrawals remain suspended as operators work toward a safe restart.

Elements Bug Allowed Unbacked L-BTC Creation

Liquid disclosed the attack on September 6 and said stolen private keys did not cause the incident. SideSwap also said attackers did not breach its systems during the event.

Instead, the vulnerability appears to have come from Elements, the Bitcoin Core fork that powers Liquid. A range-proof verification cache bug apparently allowed creation of L-BTC without matching Bitcoin backing.

The attacker then used those unbacked tokens to obtain real BTC through Liquid’s normal peg-out process. Liquid took its federation wallet and bridge nodes offline after detecting the abnormal withdrawals.

Hacker Returns Most Funds After Patch

The self-described white-hat hacker pledged to return most funds after Blockstream fixed the underlying software flaw. In messages to Blockstream, the party requested patches across every node before returning Bitcoin.

Blockstream later said its bridge nodes had received the patch and could safely accept the funds. Onchain data then showed 3,400 BTC moving back to the Liquid Federation wallet.

About 598.5 BTC remains under the actor’s control. No public agreement explains whether those coins represent a bounty or whether the party plans another return. 

Ledger Chief Technology Officer Charles Guillemet questioned the white-hat label after the partial repayment. He said keeping approximately 600 BTC did not fit a genuine bug-bounty arrangement and described it as closer to extortion.

The return removed most of the immediate reserve shortfall, but it did not restore normal Liquid operations. The network still needs to verify backing and complete software deployment before reopening its bridge.

Also Read: Pi Network Climbs Toward USD 0.085 as Low Liquidity Boosts PI Recovery

Liquid Keeps Peg Services Paused

Liquid has not resumed normal operations while its operators prepare a safe restart. L-BTC deposits and withdrawals remain halted, including related services at centralized exchanges. Meanwhile, Bitcoin’s main network continues operating without disruption. The exploit also left other Liquid-issued assets untouched, including USDT, Depix, and real-world assets.

Liquid wallets such as Aqua face disruption only across their Liquid functions. Users can therefore access unaffected Bitcoin network services, while Liquid peg activity remains unavailable.

Before reopening the bridge, operators need to restore one-to-one backing for legitimate L-BTC. They also need to distribute the patched Elements release across the network and verify safe bridge operation. Liquid has not explained how it will cover any remaining gap in L-BTC backing. The network also has not published a timeline for restoring the sidechain and its peg services.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp
logo
Artificial Intelligence News & Cryptocurrency News: Latest Trends | Analytics Insight
www.analyticsinsight.net