Liquid’s Bitcoin Recovery Has Three Tests
The code repair tackles a verification shortcut. Restored transactions and the return of BTC redemptions need their own evidence.

Explainer
Liquid has a software repair and a reported return to transactions. Getting bitcoin back out of the network is a separate recovery milestone. That distinction matters more to an L-BTC holder than the dispute over whether the exploiter deserves a bounty.
On September 11, Blockstream refused to pay for the return of about 598.5 BTC still withheld after the exploit, following an earlier return of roughly 3,400 BTC, The Block reported. Its update said transactions had resumed on September 10 while peg-outs remained disabled.
The public repair explains a less obvious part of the story: a shortcut for remembering successful checks could confuse different inputs. Understanding that flaw, then separating software repair, network activity and redemption, gives holders a clearer way to assess the next recovery announcement.
The flaw was in remembering what had passed verification
Blockstream’s initial incident notice said roughly 4,000 BTC had been withdrawn through SideSwap’s peg-out authorization key, while stating that no keys were compromised. That directs attention to validation as well as key custody.
The Elements 23.3.4 release contains a proof-cache repair. The merged change explains that cached results represented successful verification, but different groups of inputs could produce an identical key. A result from one check could therefore be accepted for the wrong inputs.
For an illustrative example, joining AB with C produces the same string as joining A with BC. Hashing either gives the same result because the input is already identical. This is a field-boundary problem, not evidence that SHA-256 itself was broken.
The patch records field lengths before hashing. It also adds previously missing asset tags to the surjection-proof cache key and tests whether changes to relevant inputs produce distinct entries. The purpose is to bind a remembered approval to the complete input it actually checked.

Three recovery tests, with different evidence
Liquid’s documentation describes peg-out as the process that destroys L-BTC on Liquid and releases BTC on Bitcoin. Ordinary users generally access it through a participant or service with the required authorization. Moving L-BTC between Liquid addresses and receiving BTC on the main chain are different operations.
That makes a single “network is back” verdict too broad. Here is the dated record checked for this article:
| Test | Dated evidence | What to look for next |
|---|---|---|
| Software repair | Elements 23.3.4 contains the fix. Blockstream’s September 10 notice says required node updates were deployed. | A technical postmortem connecting the failure, repair and validation work. |
| Network activity | The Block’s September 11 report says transactions resumed September 10. | Sustained transaction processing and clear disclosure of any remaining restrictions. |
| BTC redemption | The same September 11 report says peg-outs remained disabled. | A dated reopening notice, reserve accounting and documented completion of BTC redemptions. |
Sources: release notes, Blockstream’s status notice and The Block’s update. The final column is our proposed recovery checklist.
The timestamps explain an apparent mismatch: Blockstream’s notice is labelled September 10, 10:00 UTC and describes blocks resuming without transactions. The later report describes transactions restarting that day. The older notice should not be read as contradicting the later stage, or as a current withdrawal-availability test.
The next update needs to explain how holders exit
A useful reopening announcement would identify which peg-out routes are available, any limits or queues, and how any remaining reserve shortfall will be handled. If funds remain unrecovered, holders need to know who supplies the missing backing and on what terms. An announcement about software alone cannot answer those operational questions.
Nor should a successful trade or swap automatically settle the redemption question. Liquid’s documentation describes third-party swaps as another way to move between the systems. Our distinction is practical: a counterparty willing to buy L-BTC provides a route to liquidity; restored federation peg-outs demonstrate that the underlying redemption mechanism is operating again.
Reporting and disclosure: Sources checked September 12, 2026. The September 11 development is attributed to The Block; the original X statements were inaccessible. This is a public-source explainer, without interviews, an independent exploit audit or a live redemption test. Research and writing used AI assistance. See our editorial guidelines.
Editorial revision, September 12, 2026: Reframed as an explainer, expanded the repair and redemption explanation, and removed a generic community quotation and repetitive presentation. The headline changed; the original publication date is retained.




