Liquid Network has moved a step closer to restoring peg out operations after launching an independent external security audit of Elements v23.3.4 and coordinating a full replacement of the authorization keys used in the withdrawal process. The moves are the latest stage in the federation’s staged recovery from the September 6 exploit that saw roughly 4,000 BTC drained from its reserve, and they signal that the network’s operators want every layer of the peg out path re-verified before Bitcoin can once again leave the federation reserve.
In its September 28 ecosystem update, Liquid confirmed that the external audit of Elements v23.3.4 is now underway, providing what the network described as an additional layer of validation as it works toward the safe restoration of peg outs. The federation did not offer a firm date for when withdrawals will restart, saying only that the audit and key changes are steps toward resuming secure operations and that another update on the restoration process is expected shortly.
Elements v23.3.4 was released earlier in September to patch the exact software flaw exploited during the incident. According to Liquid’s post-incident assessment, the vulnerability involved the way Elements cached the results of rangeproof verification. An earlier change had removed some transaction context from the cache key, creating a consensus flaw that allowed a cached verification result to be reused under different circumstances. A first fix addressed the initially identified problem, but a second issue involving how fields were combined in the cache key remained, and it was that second weakness the attacker exploited on September 6 to create an output whose value was not backed by its inputs — roughly 4,000 unbacked LBTC that were then pushed through Liquid’s normal peg out process to withdraw real Bitcoin.
The patched release changed how rangeproof and surjection proof cache keys are constructed by serializing each field with a length prefix, preventing different sets of inputs from producing the same cache key through the collision method used in the attack. The hardened fix was merged into the Elements 23.3.x release branch on September 8 and published the following day. Block production resumed once functionary nodes received the required software updates, and transactions gradually returned to the network, but peg outs have remained suspended throughout while the federation completes work on the part of the system that actually releases BTC from the reserve.
The second half of the September 28 update concerns the Peg out Authorization Key, or PAK, system used to authorize withdrawals from Liquid back to the Bitcoin mainchain. Under Liquid’s architecture, each PAK entry contains two keys with separate functions. An offline component is derived from a member’s Bitcoin receiving wallet, while an online key signs peg out requests from an Elements node. Functionary nodes use the offline component to verify that the Bitcoin destination belongs to a registered PAK entry, and the private keys controlling the receiving Bitcoin are intended to remain offline. The September incident exposed weaknesses in that protection alongside the Elements consensus bug, and the federation is now replacing existing PAK entries entirely while ensuring that all Bitcoin receiving keys associated with peg outs are properly secured in cold storage.
The layered design is deliberate. Even if an upstream system fails, Bitcoin released through a peg out should remain in a cold wallet and require a separate action before it can be moved onward. Whether that containment held under the September 6 attack has been a central question of the incident response, and the wholesale PAK replacement suggests the federation is treating the authorization layer as compromised until proven otherwise.
For users of the sidechain, the practical picture is mixed. Liquid’s confidential transactions, which hide transaction amounts while cryptographic proofs allow nodes to verify that amounts are valid, continue to function, and block production has been stable since the recovery began. But the ability to exit back to Bitcoin mainnet remains the core value proposition of any federated sidechain, and until peg outs return, LBTC trades at the mercy of market confidence in the federation’s reserves. The roughly 4,000 BTC shortfall from the exploit also hangs over the question of how the federation will make reserve holders whole.
The independent audit is a notable escalation in rigor. Elements v23.3.4 already fixed the technical flaw, but the federation has chosen to have an external team validate the release before re-enabling the flow of Bitcoin out of the reserve — an acknowledgment that a second consensus failure would be far more damaging than the first, both financially and to the credibility of the Liquid Federation’s 60-plus member institutions.
Market context remains cautious across Bitcoin ecosystems more broadly. Bitcoin was last changing hands around 83,513 USD according to a cached CoinGecko snapshot, down roughly 1.2 percent on the day, while Ethereum traded near 2,681 USD and Solana near 118 USD. The Liquid situation is a reminder that even infrastructure built atop Bitcoin’s security assumptions carries its own distinct technical risk, as Immunefi’s CEO noted when describing the attacker’s actions as having crossed from exploitation into outright theft.
No firm timeline has been given for peg outs to resume. What is clear from the September 28 update is the sequence: complete the external audit, finish the PAK replacement, verify cold storage arrangements, and only then re-enable withdrawals. For a network that processes institutional flows including issued assets, stablecoins and federated peg operations, the federation appears to have concluded that speed of restoration matters far less than certainty that the same door cannot be opened twice.
replacing the peg-out keys is the right move but 4000 unbacked LBTC from a cache key bug is still wild. two flaws stacked in the same release, nobody caught either
at least they patched elements 23.3.4 before restarting block production instead of rushing peg outs back online. federation moves slow but thats kinda the point
External audit before restoring withdrawals is the correct order of operations. The real test is whether LBTC trades back at par once peg-outs resume.
Full key replacement plus an external audit before reopening peg outs is the only sane path after 4000 BTC walked out the door. Glad they are not rushing this.
Agreed, but the scary part is the first patch missed the second cache key issue. Two flaws in one rangeproof verification path is not a great look.
The detail that got me: the attacker reused a cached verification under different inputs and minted unbacked LBTC. Length prefixing the serialized fields should have been there from day one.
Exactly. A consensus bug disguised as an optimization. Whoever wrote the original cache key change probably assumed those fields could never collide.
No firm date for withdrawals restarting is the right call, but L-BTC holders have been stuck since September 6. Hope the audit moves fast.