Liquid Network Holds Bitcoin Redemptions Frozen at 86% Reserve Coverage After 4,000 BTC Exploit
Thirty-five days after an attacker drained nearly 4,000 BTC from Blockstream's Liquid Network, users still cannot redeem their L-BTC tokens for actual bitcoin. Reserve coverage sits at approximately 85.8%, leaving a gap of roughly 603 BTC.
Thirty-five days after an attacker drained nearly 4,000 BTC from Blockstream's Liquid Network, users still cannot redeem their L-BTC tokens for actual bitcoin. Reserve coverage sits at approximately 85.8%, leaving a gap of roughly 603 BTC between what the protocol holds and what it owes.
The exploit, which targeted a vulnerability in Liquid's underlying Elements software in mid-September, represents one of the largest sidechain security breaches on record. At typical 2026 valuations, 4,000 BTC translates to somewhere between $160 million and $200 million in exposure. Blockstream has recovered 3,400 BTC of the stolen amount, but the remaining shortfall is enough to keep peg-outs, the mechanism by which users convert Liquid's LBTC tokens back to native bitcoin, fully suspended.
The protocol has been direct about its conditions for resumption. Peg-outs require full reserve backing and completed security reviews before they can restart. That means the freeze will not lift until an independent external security audit clears the network and the 603-BTC gap is closed. Neither condition has been met as of October 11.
The 603-BTC shortfall is not trivial. At conservative estimates, that figure represents $24 million to $26 million in uncovered exposure. But context matters here: the recovery of 3,400 BTC from a 4,000-BTC theft is not nothing, and the decision to freeze redemptions entirely rather than allow partial payouts reflects a deliberate choice to protect the remaining user base rather than accelerate a run. A protocol that permitted withdrawals at 86 cents on the dollar would almost certainly trigger exactly the kind of panic it is trying to prevent.
Sidechain bridges have a grim track record when reserves come under pressure. The 2022 Ronin Bridge hack resulted in $625 million in losses with no meaningful recovery. The 2021 Poly Network exploit saw funds eventually returned by the attacker, but only after days of uncertainty. Liquid's situation sits somewhere between those extremes: significant theft, partial recovery, ongoing audit, and a protocol choosing a full freeze over a disorderly unwind. Whether that approach preserves or erodes long-term trust will depend entirely on how quickly the audit completes and whether Blockstream can close the reserve gap.
The broader implication for Bitcoin sidechain infrastructure is uncomfortable. Liquid has been positioned as a serious institutional-grade layer for Bitcoin settlement, used by exchanges and trading desks that want faster, confidential transactions without touching the base chain. A 35-day redemption freeze at any reserve shortfall undermines that positioning, regardless of how the recovery ultimately concludes. Custodial risk in sidechain models has always been the central criticism from Bitcoin purists, and this incident hands that argument new ammunition.
The freeze also raises questions about the adequacy of the Elements software's pre-exploit security posture. Liquid's architecture relies on a federated multisig model, where a set of functionaries control the peg. If a software vulnerability in Elements was sufficient to drain nearly 4,000 BTC, the audit now underway will need to assess not just the specific bug but the broader attack surface of the federation's signing infrastructure.
For LBTC holders still waiting, the path forward is narrow. Full reserve restoration and a clean audit bill of health are the stated requirements. Blockstream has not published a timeline for either. Until both boxes are checked, bitcoin locked in Liquid stays locked.



