Highlights
- Liquid Network has resumed block production as of 10:00 UTC September 10, four days after a $320 million exploit.
- Transactions are still not being processed while the network completes its recovery.
- Blockstream says updated Functionary and bridge nodes are now signing and verifying blocks as expected.
- Peg-out operations, including PAK-authorized withdrawals, remain suspended during the final recovery phase.
- The update follows the return of 3,400 BTC from the incident, with roughly 598.5 BTC still unresolved.
Liquid Network has entered a controlled recovery phase following the roughly $320 million exploit that drained its federation wallet on September 6, with block production resuming as a precautionary measure as of 10:00 UTC on Thursday, according to an update from Blockstream. Transactions are not yet being processed even though blocks are once again being produced, and the network continues monitoring to confirm full stability before restoring normal operations. The update marks the latest step in a recovery effort that began within a day of the exploit, when a vulnerability in the open-source Elements software Liquid runs on allowed roughly 4,000 BTC to leave the network's federation address.
What's Working Again, and What Isn't
Blockstream said the Functionary nodes and bridge nodes required to run the network have had their necessary software updates successfully deployed, and Functionary nodes are now signing and verifying blocks as expected, the clearest sign yet that the underlying vulnerability has been patched at the infrastructure level.
Peg operations remain suspended, however, including PAK-authorized peg-outs, meaning users cannot yet move BTC off the Liquid sidechain even though the chain itself is producing blocks again. Blockstream described the current phase as the network's final stage of recovery, which includes restoring BTC and L-BTC reserves to their pre-exploit state before peg operations and full transaction processing can resume. The staged approach, block production first, then transactions, then peg operations, reflects a cautious sequencing meant to avoid reintroducing the same class of vulnerability before each layer of the system has been independently verified as stable.
Related: Core Lightning Tells Node Operators to Patch or Go Offline After AI-Found Bugs
The Recovery So Far
Thursday's update follows a recovery effort that has already produced one of the more unusual outcomes in a major crypto exploit this year. The attacker returned 3,400 BTC to the federation address shortly after Blockstream patched the affected bridge nodes, while keeping the remaining roughly 598.5 BTC, worth close to $47 million, as what they characterized as a bounty for identifying the flaw. That framing has been met with skepticism from parts of the community, and the attacker has separately escalated demands, seeking a payment equal to 10% directly from Blockstream's own funds rather than simply keeping a portion of what was already taken. The dispute over how much of the exploited funds the attacker is entitled to keep remains unresolved even as the underlying network infrastructure moves back toward normal operation, illustrating how a technical recovery and a negotiation over stolen funds can proceed on separate, only loosely connected tracks. Liquid initially paused entirely after the drain, with doubts raised from the outset about whether the attacker's self-described whitehat framing was genuine or an after-the-fact justification.
What to Watch Next
The next milestone is the restoration of peg operations, which would let users move BTC and L-BTC across the sidechain boundary again and would signal Blockstream considers the network fully stabilized. Transaction processing is likely to resume before peg-outs are re-enabled, given the more cautious sequencing described in Thursday's update, and any resumption will be watched closely for confirmation that reserves have been fully restored to their pre-exploit levels. The unresolved question of the roughly $47 million the attacker is still holding, and whether Blockstream ultimately pays any additional bounty beyond what has already been returned, will likely be settled separately from the technical recovery timeline, but it remains the biggest open variable in how this incident is ultimately resolved.
FAQ
What is the current status of Liquid Network?
As of 10:00 UTC on September 10, Liquid Network has resumed block production as a precautionary measure, but transactions are not yet being processed while the network completes recovery from a $320 million exploit.
What caused the original Liquid Network exploit?
A vulnerability in the open-source Elements software Liquid runs on, related to how nodes cache range-proof verifications, allowed roughly 4,000 BTC to leave the network's federation wallet on September 6.
How much of the stolen funds has been recovered?
The attacker returned 3,400 BTC to the federation address after Blockstream patched the affected nodes, while keeping roughly 598.5 BTC, worth close to $47 million, which they have framed as a bounty.
When will peg operations and transactions fully resume?
Blockstream has not given a firm date, saying the network is in its final recovery stage, which includes restoring BTC and L-BTC reserves before peg-outs and full transaction processing can resume.
