Liquid Network Resumes Operations After $320M Security Breach
The Liquid Network federation has resumed block generation after a four-day technical suspension following a security breach on September 6, 2026. The breach allowed an attacker to mint nearly 4,000 units of Liquid Bitcoin (LBTC) without depositing collateral and withdraw 3,996 BTC from the network's multisig wallet. This resulted in a loss of 4,205 BTC, leaving only 197 BTC in the federated wallet.
The attack was detected at block 4,050,336 and involved a flaw in the open-source Elements codebase that allowed the attacker to mint synthetic funds through the SideSwap exchange service via a peg-out authorization key (PAK). The PAK had been left connected to the internet without automated velocity checks or per-wallet volume thresholds.
The attacker returned 3,400 BTC to the network's multisig address on September 7, 2026, and demanded a 10% bounty payout to return the outstanding balance of 598.5 BTC. Blockstream CEO Adam Back stated that the 1:1 peg between LBTC and BTC will be fully covered.
The federation has deployed emergency patch Elements v23.3.4, which addressed cache key management within range proofs following joint audits with specialized security firms. The recovery roadmap consists of three consecutive phases, with the next formal step being the release of a comprehensive technical audit of the incident and completion of stress testing ahead of fully reopening the liquidity bridges.