The Liquid Network’s Recovery Efforts
The Liquid Network is making significant strides in reestablishing its peg out operations, which were temporarily halted due to a security breach earlier this month. A critical part of this recovery involves an independent security audit of its Elements v23.3.4 software, recently initiated to ensure the safe resumption of peg outs.
In an update dated September 28, 2026, the Liquid Network emphasized that this audit is a key step following a severe incident on September 6, when a vulnerability allowed an attacker to generate approximately 4,000 LBTC without backing, leading to unauthorized Bitcoin withdrawals from the federation’s reserve.
Security Enhancements and Audit
As the network updates its Peg Out Authorization Key (PAK) list, it is also ensuring that all Bitcoin receiving keys used for peg outs are securely stored offline. This precaution aims to bolster the security framework used for withdrawals, although no specific timeline has been given for when operations will resume. The Liquid Federation promised further updates as they continue to work towards reviving secure peg out functionalities.
The Elements v23.3.4 version was designed to rectify software flaws that permitted the aforementioned exploitation. This vulnerability was traced back to weaknesses in how the Elements platform managed rangeproof verification, which allowed flawed cached results to be reused, effectively letting the attacker create unsupported outputs during the peg out process.
In response, the latest software modifications include adjustments to the way cache keys are constructed, enhancing security by preventing input collisions that could exploit these weaknesses.
Impact of the September 6 Breach
Furthermore, the external audit adds another layer of scrutiny before peg out functionalities can be restored. Elements serves as the blockchain foundation for the Liquid Network, employing confidential transactions to mask the amounts being transacted while ensuring nodes can still validate them cryptographically.
The September 6 breach, which saw an estimated 4,000 BTC funneled out, underscored existing flaws within both the Elements software and the configuration of the involved federation members’ PAK processes.
Specifically, the SideSwap service, which was implicated in the illegal peg out execution, was previously aware of its PAK system’s online operation but had received no directives to adjust its operational practices prior to the incident. Although SideSwap has paused its peg out services, it is actively reviewing its security measures alongside the Liquid Federation to enhance future defenses.
Current Status and Future Plans
Following the incident, Liquid halted bridge node functions and resumed block production shortly thereafter, while regular transaction activities gradually resumed throughout early September. Still, peg out operations remain suspended as the federation meticulously ensures that the necessary security protocols are tightly implemented before allowing any Bitcoin withdrawals.
Liquid has outlined a staged recovery plan, with the latest updates indicating that they are focused on a safe restoration of operations, potentially aided by external oversight, to prevent future occurrences of similar breaches. Currently, about 602 BTC is still in recovery processes, as Liquid collaborates with law enforcement and other entities to retrieve these assets.
As further updates arise, stakeholders and users are urged to remain patient while Liquid completes these crucial steps towards enhancing security and resuming peg out functions.