Liquid Network resumes block production after attack, but transactions remain suspended
Liquid Network has resumed block production after an attack that allowed the creation of nearly 4,000 LBTC without Bitcoin support. The network has been back online, but users still have to wait for a while before making transactions or converting BTC to L-BTC.
Quick overview of core points
- Liquid has resumed block production several days after the network stopped operating.
- Elements v23.3.4 fixes a vulnerability related to caching used to verify proof of scope.
- The transaction and anchoring (Peg) operation between Bitcoin and Liquid remains suspended.
- About 3,400 BTC items have been returned after the attack, but some of the funds are still missing.
Liquid restarts block production
Restoring block production does not mean that the network will immediately resume normal operation. Although Liquid has restarted block generation, it has not yet opened up user transaction functions. The move aims to allow operators to verify the normal operation of the network before gradually reopening other services.
The vulnerability exploited on September 6 involved Elements, the open source software used by Liquid. According to a report released by the team, the vulnerability affects the way node caches verify proof of scope. The attackers used this to create approximately 4,000 LBTC coins, which were not backed by bitcoins in the reserve. To prevent further losses caused by the attack, the network subsequently suspended operations.
Fix measures hit the heart of the problem
To fix this vulnerability, Elements developers released version 23.3.4 on September 9. The most important change this time concerns the caching mechanism for proof of scope: the key used by the mechanism has been enhanced and a new option has been added to allow this caching feature to be completely disabled. Liquid immediately began updating its nodes with a clear goal: to ensure network security before allowing money to flow again.
The attack resulted in the transfer of approximately 95% of the bitcoins in the alliance wallet. Attackers who call themselves "white hat" hackers claim they will return funds after fixing the vulnerability. In the end, about 3,400 BTC were returned, while funds for nearly 600 BTC were still missing.
L-BTC is still under close surveillance
The main problem at the moment is Bitcoin reserves. Liquid continues to suspend the anchoring operation, which prohibits the conversion of BTC to L-BTC and vice versa. This suspension is crucial because each L-BTC must correspond to a Bitcoin in the Liquid Reserve. Exchange services cannot be restored under normal conditions until the team replenished and verified the reserves.
Liquid is adopting a step-by-step strategy. The team has resumed block production, and then needs to restore the transaction function before finally opening the anchoring operation. As of September 7, approximately 598 BTC (worth nearly US$46 million) were still missing. Liquid has not said who will bear the loss: whether it will be the L-BTC holder, the alliance or a potential insurer.
This incident also highlights the seriousness of software risks in the cryptocurrency network. Liquid fixed the vulnerability and restarted its online service in a few days, and now must prove to users that every L-BTC in circulation is backed by real Bitcoin to rebuild user confidence.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC