The Liquid Network has gradually resumed operations after a hack drained approximately $320 million from its federation wallet. Block production restarted on September 10, with functionary nodes successfully signing and validating blocks. Transactions were initially paused during monitoring but resumed later that evening, allowing users to transact with assets already on the network.
A critical function remains disabled: peg-outs, which enable users to move LBTC from Liquid back to the Bitcoin network in exchange for BTC. This restriction was implemented intentionally to prevent further attacks while Blockstream verifies the network's internal state and confirms that BTC and LBTC reserves have been correctly restored.
The hack exploited a proof-verification cache vulnerability in Liquid's underlying Elements software. Blockstream released Emergency Elements v23.3.4 to address the flaw by strengthening the cache keys used when verifying range proofs.
Approximately 85 percent of the stolen Bitcoin has been restored after white hat hackers returned 3,400 BTC, valued at roughly $268 million. An additional 598.5 BTC remains in a separate wallet designated as an unofficial bounty.
Blockstream stated it will not pay a ransom for the return of stolen funds, characterizing the incident as theft rather than legitimate white-hat hacking. The company said it has engaged in good faith negotiations but will now work with law enforcement, exchanges, blockchain investigators, and security experts to trace and recover the remaining stolen Bitcoin.


