Skip to content
Independent crypto & security journalism

Search Block Magnates

Explore reporting on markets, regulation, blockchain and security.

Security Lab

Liquid’s Bitcoin Recovery Has Three Tests

The code repair tackles a verification shortcut. Restored transactions and the return of BTC redemptions need their own evidence.

A white hat rests on a locked blue glass box of bitcoin beside an open tray of returned coins in a sunny workshop.
Illustration: Block Magnates, created with AI.

Liquid has a software repair and a reported return to transactions. Getting bitcoin back out of the network is a separate recovery milestone. That distinction matters more to an L-BTC holder than the dispute over whether the exploiter deserves a bounty.

On September 11, Blockstream refused to pay for the return of about 598.5 BTC still withheld after the exploit, following an earlier return of roughly 3,400 BTC, The Block reported. Its update said transactions had resumed on September 10 while peg-outs remained disabled.

The public repair explains a less obvious part of the story: a shortcut for remembering successful checks could confuse different inputs. Understanding that flaw, then separating software repair, network activity and redemption, gives holders a clearer way to assess the next recovery announcement.

The flaw was in remembering what had passed verification

Blockstream’s initial incident notice said roughly 4,000 BTC had been withdrawn through SideSwap’s peg-out authorization key, while stating that no keys were compromised. That directs attention to validation as well as key custody.

The Elements 23.3.4 release contains a proof-cache repair. The merged change explains that cached results represented successful verification, but different groups of inputs could produce an identical key. A result from one check could therefore be accepted for the wrong inputs.

For an illustrative example, joining AB with C produces the same string as joining A with BC. Hashing either gives the same result because the input is already identical. This is a field-boundary problem, not evidence that SHA-256 itself was broken.

The patch records field lengths before hashing. It also adds previously missing asset tags to the surjection-proof cache key and tests whether changes to relevant inputs produce distinct entries. The purpose is to bind a remembered approval to the complete input it actually checked.

GitHub repair note: a collision in a cache of successful verification results could allow an attacker to bypass verification.
Elements repair, September 8. The highlighted passage identifies the bypass risk. Browser capture: September 12, 2026; cropped, with an orange box added by Block Magnates. Enlarge screenshot.

Three recovery tests, with different evidence

Liquid’s documentation describes peg-out as the process that destroys L-BTC on Liquid and releases BTC on Bitcoin. Ordinary users generally access it through a participant or service with the required authorization. Moving L-BTC between Liquid addresses and receiving BTC on the main chain are different operations.

That makes a single “network is back” verdict too broad. Here is the dated record checked for this article:

Liquid recovery: repair, activity and redemption
TestDated evidenceWhat to look for next
Software repairElements 23.3.4 contains the fix. Blockstream’s September 10 notice says required node updates were deployed.A technical postmortem connecting the failure, repair and validation work.
Network activityThe Block’s September 11 report says transactions resumed September 10.Sustained transaction processing and clear disclosure of any remaining restrictions.
BTC redemptionThe same September 11 report says peg-outs remained disabled.A dated reopening notice, reserve accounting and documented completion of BTC redemptions.

Sources: release notes, Blockstream’s status notice and The Block’s update. The final column is our proposed recovery checklist.

The timestamps explain an apparent mismatch: Blockstream’s notice is labelled September 10, 10:00 UTC and describes blocks resuming without transactions. The later report describes transactions restarting that day. The older notice should not be read as contradicting the later stage, or as a current withdrawal-availability test.

The next update needs to explain how holders exit

A useful reopening announcement would identify which peg-out routes are available, any limits or queues, and how any remaining reserve shortfall will be handled. If funds remain unrecovered, holders need to know who supplies the missing backing and on what terms. An announcement about software alone cannot answer those operational questions.

Nor should a successful trade or swap automatically settle the redemption question. Liquid’s documentation describes third-party swaps as another way to move between the systems. Our distinction is practical: a counterparty willing to buy L-BTC provides a route to liquidity; restored federation peg-outs demonstrate that the underlying redemption mechanism is operating again.

Reporting and disclosure: Sources checked September 12, 2026. The September 11 development is attributed to The Block; the original X statements were inaccessible. This is a public-source explainer, without interviews, an independent exploit audit or a live redemption test. Research and writing used AI assistance. See our editorial guidelines.

Editorial revision, September 12, 2026: Reframed as an explainer, expanded the repair and redemption explanation, and removed a generic community quotation and repetitive presentation. The headline changed; the original publication date is retained.

Block Magnates

About the author

Block Magnates

Block Magnates covers crypto security, markets, and infrastructure.

View all articles