Liquid Network Peg-Outs Remained Paused After Hack

The network disabled fund withdrawals following a September 6 exploit that allowed the creation of unbacked assets.

Updated on Sept. 23, 2026 in Cybersecurity

Bold flat-color editorial illustration of a large industrial steel bridge, evoking the structural integrity of digital network security.
The Liquid Network has suspended peg-out operations for Bitcoin conversions following a September 6 security exploit that generated 4,000 unbacked tokens. AI Illustration. Upload story photo >

Live Poll

Do you trust the security of decentralized finance networks to protect your assets?

Following a September 6 security breach that generated 4,000 unbacked L-BTC, the Liquid Network suspended its peg-out operations. While the network resumed block production on September 10, the functionality to convert L-BTC back into native Bitcoin remains disabled as of September 17.

Why it matters

The pause aims to facilitate security reviews and ensure the network restores the one-to-one backing required for its federated sidechain model. This event highlights the vulnerability of cross-chain bridges, as the exploit led to a significant drain of Bitcoin reserves.

The exploit leveraged a vulnerability in the Elements software to forge 4,000 unbacked L-BTC tokens. A peg-out normally functions by burning L-BTC, which then triggers the release of an equivalent amount of Bitcoin from a locked federation wallet.

The players

Liquid Network

A sidechain network for Bitcoin designed to enable faster, confidential transactions via a federated consensus model.

Blockstream

A blockchain technology firm that develops the Liquid Network and the underlying Elements software architecture.

Bull Bitcoin

A non-custodial Bitcoin exchange that provides services for converting native Bitcoin to Liquid assets.

The details

The attack utilized a flaw in the Elements software—an open-source blockchain platform that powers sidechains—to bypass verification and generate unbacked L-BTC. By creating these tokens, the attacker drained 3,996.02 BTC from the federation's reserves. The network operators paused the peg-out mechanism to conduct a security review and prevent further unauthorized movement of assets.

Timeline

  1. September 6, 2026: The exploit occurred and unbacked L-BTC were created.

  2. September 10, 2026: Liquid resumed block production and L-BTC transfers.

  3. September 17, 2026: Peg-out operations remained paused.

  4. September 22, 2026: Bull Bitcoin provided an update on service resumption.

The Tech Race

This incident highlights the inherent security challenges facing federated sidechains built on the Elements software. It marks a departure from the network's established uptime, forcing an audit to preserve the integrity of its Bitcoin-backed asset model.

Users currently holding L-BTC cannot convert their assets back into native Bitcoin until peg-out operations are fully restored. Bull Bitcoin customers should expect a 30-day window for the resumption of exchange services as the network completes its security review.

The takeaway

The security of federated sidechains depends entirely on the integrity of the underlying pegging software and the responsiveness of the recovery effort. Users should watch for the official resumption of peg-out functionality to confirm that network reserves have been fully restored.

What happens next

Bull Bitcoin expects its L-BTC to BTC exchange services to resume within 30 days of its September 22 update.

Further reading

For broader trends in network security, see Cybersecurity.

Live Poll

Do you trust the security of decentralized finance networks to protect your assets?

Liquid Network Peg-Outs Remained Paused After Hack | Highwise Tech