NewsCryptoLiquid Network Recovers 3,400 BTC, but Peg-Out Gap Highlights Bridge Accounting Risk

Liquid Network Recovers 3,400 BTC, but Peg-Out Gap Highlights Bridge Accounting Risk

Author: Cryptopolitan·

Key Takeaways

  • The actors returned 3,400 BTC, about 85% of the lost funds, to the Liquid Federation on September 7, retaining 598.5 BTC valued at approximately $47.3 million.
  • Blockstream identified a failure in Elements software as the root cause, which enabled the generation of invalid, unbacked L-BTC.
  • No authorization keys were stolen; the peg-out proceeded through a legitimate SideSwap authorization despite the tokens lacking proper backing.
  • Communication between Blockstream and the actors occurred through messages embedded in Bitcoin transactions, ending after Blockstream signed a note stating bridge nodes were patched.
  • The recovery addresses the missing BTC but leaves unresolved the peg-mechanism flaw that allowed invalidly created L-BTC to be redeemed for real Bitcoin.
Liquid Network Recovers 3,400 BTC, but Peg-Out Gap Highlights Bridge Accounting Risk

The Liquid Network has recovered a substantial portion of the Bitcoin (BTC) taken from its federation wallet over the weekend, but the incident leaves a more serious issue unresolved: a peg-out can proceed through the expected authorization route even when the L-BTC involved in the transaction should never have been created.

On Monday, September 7, the group responsible for the withdrawal refunded 3,400 BTC to the federation — roughly 85% of the lost funds. The actors retained 598.5 BTC. For consistency, all dollar conversions in this article use CoinMarketCap’s Bitcoin-to-USD rate of $79,001.61, recorded on September 7.

Liquid, developed by Blockstream, is a federated Bitcoin sidechain that uses a two-way peg: members of a federation custody BTC on the main chain and issue corresponding L-BTC for use on the sidechain, where it circulates for faster settlement and asset issuance. That design makes the correctness of the peg mechanism — not just the security of keys — central to the system’s assurances.

A valid peg-out the federation says it never authorized

At first glance, the transaction appeared routine. According to SideSwap, at 14:05 UTC on Sunday a customer transmitted 4,000 L-BTC to its peg-out service. After presenting a valid SideSwap peg-out authorization, roughly 3,996 BTC was released from the federation’s wallet at 14:28:56 UTC (transaction).

The authorization key, however, was not stolen. Liquid reported that SideSwap’s authorization key was not used improperly. SideSwap added that Blockstream later determined the root cause was a failure in Elements software, which enabled the generation of invalid L-BTC. As a result, the peg-out mechanism allowed incorrect tokens that appeared legitimate to slip through, even though they lacked the backing L-BTC is supposed to have.

This distinguishes the incident from typical key-compromise cases and places it squarely in the domain of accounting problems. According to Liquid’s whitepaper, L-BTC is defined as Bitcoin that enters the sidechain via a two-way peg, with federation-held BTC used to redeem the coin. If L-BTC can enter invalidly through its redemption path, the integrity of reserves becomes as critical as the authorization keys themselves. It is a category of risk familiar from cross-chain bridges elsewhere in the crypto industry, where failures in minting or redemption logic — rather than stolen keys — have repeatedly allowed unbacked assets to be created and redeemed for real funds.

Negotiations conducted through Bitcoin transaction messages

Communication between Blockstream and the actors took place through messages embedded in Bitcoin transactions. A timeline posted by Samson Mow indicated the actors were pressing Blockstream to fix the vulnerability before returning the funds.

Blockstream later issued a signed note stating, “Bridge nodes are patched, safe to return the funds.” The actors confirmed the final destination with Blockstream and returned 3,400 BTC to the Liquid Federation at 16:09:25 UTC on September 7.

Why the missing 598.5 BTC keeps the reserve question open

Recovering 85% of the funds is significant, but it does not resolve the challenges facing a system that relies on one-to-one backing. Approximately 598.5 BTC remains outside the federation, representing about $47.3 million at the market price used in this calculation.

As previously reported by Cryptopolitan, a peculiar aspect of the event was that it used the SideSwap peg-out authorization mechanism even though no breach occurred at the key level. The Bitcoin base layer also functioned properly. The problem lay upstream, where falsely minted L-BTC passed through a redemption mechanism designed to release real BTC.

The takeaway for users of bridged Bitcoin is that this was more than a private-key theft. It demonstrated how a software fault can produce a legitimate-seeming redemption request without actual reserves behind it. Even if the remaining bitcoin is returned, the underlying issue persists: Liquid’s peg-out process converted real BTC for L-BTC that should never have been considered validly collateralized. What to watch going forward is whether Blockstream publishes further detail on the Elements software fault and any verification changes to the peg-in and peg-out path, since the returned funds address the symptom — the missing BTC — rather than the mechanism that permitted invalid L-BTC to be redeemed in the first place.