TL;DR:
- On September 10, 2026, the Liquid Network federation resumed block generation following a four-day technical suspension.
- A vulnerability in the Elements software enabled the unbacked minting of nearly 4,000 LBTC and the withdrawal of 3,996 BTC on September 6, 2026.
- Operating reserves dropped from 4,205 BTC to 197 BTC during the exploit, followed by the return of 3,400 BTC on September 7, 2026.
This Thursday, September 10, sidechain Liquid Network resumed controlled block production following a security incident valued at $320 million. Blockstream and the federation of operators launched the first phase of technical recovery without opening commercial transactions to end users.
LIQUID NETWORK UPDATE: OPERATIONS RESUMED, RECOVERY ONGOING
Status as of September 10, 2026, 10:00 UTCRecovery Status
The Liquid Network has entered the next phase of its controlled resumption. As a precautionary measure, block production has resumed without transactions while… https://t.co/PbyBXIzdQc
— Liquid Network 🌊 (@Liquid_BTC) September 10, 2026
The reboot took place at 12:26 UTC after federated node upgrades were completed. Validators began signing empty blocks while overall system stability is being monitored.
Deposit and withdrawal operations remain disabled as a precaution. According to market report, conversion features will remain frozen while the full restitution of underlying Bitcoin reserves progresses.
The security breach was detected on September 6, 2026, at network block 4,050,336. A flaw in the open-source Elements codebase allowed an attacker to mint nearly 4,000 units of Liquid Bitcoin (LBTC) without depositing collateral.
These synthetic funds were routed through the SideSwap exchange service via a peg-out authorization key (PAK). Federation nodes validated the transaction because the flaw occurred at the pre-transaction validation level.
This exploit slashed the federated multisig wallet balance from 4,205 BTC to 197 BTC within minutes. Technical reports confirmed that none of the private keys belonging to the 15 federation members were compromised.
Other assets issued on the network, such as the stablecoin Tether (USDT) and various real-world asset (RWA) tokens, remained untouched throughout the forced halt.
SideSwap released a detailed post-mortem on September 9, 2026, acknowledging operational oversights. The platform had kept the PAK key connected to the internet and lacked automated velocity checks or per-wallet volume thresholds.

Technical Recovery Plan and Reserve Backing
The attacker returned 3,400 BTC to the network’s multisig address on September 7, 2026, identifying themselves as a security researcher via on-chain messages. To date, 598.5 BTC—valued at roughly $47 million—remain unrecovered.
The attacker demanded a 10% bounty payout to return the outstanding balance. Blockstream representatives have not officially classified the demand as an authorized bug bounty program.
The federation deployed emergency patch Elements v23.3.4 on September 9, 2026. The fix addressed cache key management within range proofs following joint audits with specialized security firms, including Bitcoin Red Team and Alpen Labs.
Blockstream CEO Adam Back stated publicly that the 1:1 peg between LBTC and BTC will be fully covered. According to market analysts, this institutional backing may help curb the risk of panic selling across over-the-counter (OTC) desks.
The recovery roadmap consists of three consecutive phases: the first focuses on generating controlled blocks; the second involves re-executing verified legitimate transactions; and the third will re-enable pegs once all reserve funds are fully secured.
The next formal step announced by the federation will be the release of a comprehensive technical audit of the incident alongside the completion of stress testing ahead of fully reopening the liquidity bridges.





