Particle.news

Liquid Network Recovers 3,400 BTC After Software Exploit, 598.5 BTC Still Held

The episode shows a node‑level bug can bypass a federated multisignature peg, leaving L‑BTC backing and the network restart timetable unresolved.

Overview

  • A vulnerability in Elements, the open‑source node software Liquid runs on, allowed creation of unbacked L‑BTC that was cashed out through SideSwap in a peg‑out that moved roughly 3,996–4,019 BTC from the federation wallet.
  • Blockstream engaged the actors through signed on‑chain messages and patched Liquid’s bridge nodes, after which the party returned about 3,400 BTC but kept roughly 598.5 BTC in the withdrawal‑linked address.
  • Bridge nodes, peg services and exchange L‑BTC deposits and withdrawals were paused after the Sept. 6 transaction and remain suspended while operators reconcile reserves and confirm network safety.
  • Liquid’s federated model relied on 11‑of‑15 signatures but the bug operated at the node/validation layer, showing that software consensus failures can enable peg‑outs even when private keys and HSMs are not compromised.
  • The unresolved 598.5 BTC raises legal and operational questions about bounties versus coercion, and Liquid has not published a technical post‑mortem or given a firm timeline for reopening services, leaving L‑BTC holders and counterparties in limbo.