Skip to content
Liquid Network Updates Peg-Out Recovery Steps Following Security Incident

Liquid Network Updates Peg-Out Recovery Steps Following Security Incident

Kucoin • September 29, 2026

The Liquid Network stated in its September 28 ecosystem update that, as recovery efforts progress following the September security incident, an external security audit of Elements v23.3.4 has been initiated, with the goal of completing necessary checks before restoring peg-out operations.

Meanwhile, the Liquid Federation is updating its Peg Out Authorization Key (PAK) list. Existing entries are being replaced, and the federation is working to ensure that all Bitcoin receiving keys related to peg-outs are securely stored in cold storage.

Liquid has not provided a date for when withdrawals will resume. The network stated that the audit and PAK adjustments are among the steps required to restore secure peg-out operations, and an update on the recovery progress is expected soon.

Liquid Network audit focused on Elements v23.3.4

Elements v23.3.4 was released earlier this month to fix the software vulnerability exploited during the September 6 incident. At that time, attackers created approximately 4,000 unbacked LBTC and used Liquid’s normal peg-out process to withdraw Bitcoin from the consortium reserves.

The most recent external audit was conducted prior to the reactivation of peg-out, to perform another review of this version.

Elements is the open-source blockchain platform behind Liquid. The network uses confidential transactions, which hide transaction amounts, while cryptographic proofs allow nodes to verify that these amounts are valid.

Liquid stated in its post-incident assessment that the vulnerability was related to how Elements caches the proof validation results. A change removed part of the transaction context from the cache key, creating a consensus defect that could cause cached validation results to be reused under different circumstances.

The initial issue identified has been resolved through subsequent fixes, but a second problem with the cache key field combination remains. On September 6, the attacker exploited this second vulnerability to create an output whose value was not supported by the input.

Elements v23.3.4 changed the construction of rangeproof and surjection proof cache keys by adding length prefixes during serialization of each field. Liquid states that this change prevents different input sets from generating the same cache key via the collision method used in this attack.

This security fix was merged into the Elements 23.3.x release branch on September 8, and Elements v23.3.4 was released the following day.

As previously reported by crypto.news, Liquid has resumed block production as function nodes received the required software updates, but peg operations remain disabled.

Subsequently, as Liquid progressed through its phased recovery process, trading resumed on the network. Peg-outs remained suspended until the consortium completed the system work required to release the BTC from its reserves.

Liquid Federation is replacing the PAK entry.

The second part of the September 28 update focuses on the PAK system used to authorize peg-outs from Liquid to Bitcoin.

In Liquid’s architecture, a PAK entry contains two keys with distinct functions: the offline component is derived from the member’s Bitcoin receiving wallet, while the online key is used to sign peg-out requests.

The functional node uses offline components to verify whether a Bitcoin receiving address belongs to a registered PAK entry. The private key controlling the received Bitcoin should remain offline.

The online component performs different responsibilities. Its private key runs on an Elements node, as it is required to sign requests to release Bitcoin through the peg-out process.

Liquid stated that the offline wallet arrangement is designed to provide an additional layer of protection in the event of an upstream system failure. Bitcoins released via peg-out remain in the cold wallet and require a separate action before any further transfer.

The September 6 incident also revealed a weakness in this protection mechanism, beyond the Elements consensus vulnerability.

After creating LBTC without asset backing, the attacker used SideSwap, a member of the Liquid Federation, to process a peg-out. SideSwap received approximately 4,000 LBTC through its service, after which the federation signers released approximately 3,996 BTC on the Bitcoin blockchain.

Liquid's assessment found that two separate issues led to the transfer of Bitcoin: an Elements consensus vulnerability and a gap in the signature process configuration of the coalition member PAK.

SideSwap stated that the consortium was aware its peg-out authorization key was operating online, and this arrangement had been consistently reflected in its peg-out operations for years. The company said it was not informed prior to the incident that the key’s operation needed to be changed or that peg-outs should be paused.

SideSwap stated that it is reviewing how its authorized keys are held, as well as the restrictions and checks applied before payments, and will only resume peg services once both SideSwap and its consortium are satisfied with the new security settings.

The latest update from Liquid confirms that the consortium is replacing the existing PAK entry and ensuring that the relevant peg-out keys are securely stored in cold storage before withdrawals are restored.

Peg out remains the last restricted operation.

Normal trading activities resumed in early September, but Bitcoin pegs remained restricted during the recovery period.

Liquid initially suspended its bridging nodes on September 6 after attackers exploited a vulnerability in Elements. On September 9, as the patched chain resumed block production, transactions restarted, and user transaction activity resumed during the consortium's network monitoring period.

Peg out remains disabled throughout the process.

The initial incident caused approximately 4,000 BTC to leave the federation reserve after the attacker created LBTC without asset backing. The party involved initially identified themselves as a white hat via on-chain messages and later returned 3,400 BTC to the federation wallet after Blockstream confirmed that the affected nodes had been patched.

According to Liquid's latest detailed incident assessment, approximately 602 BTC are still under recovery.

Blockstream subsequently rejected the bounty claim related to the remaining funds and stated that it would collaborate with law enforcement agencies, exchanges, forensic experts, and other service providers to pursue fund recovery.

Liquid’s phased recovery plan requires that peg operations be restored only after the network status has been recovered and necessary security work has been completed. The external audit of Elements v23.3.4 and the replacement of PAK entries are the latest steps disclosed under this process.

Extracted Entities