
Liquid Network has initiated an independent security audit of Elements v23.3.4 in preparation for restoring Bitcoin withdrawal operations. The audit began after a September incident where approximately 4,000 BTC were withdrawn from the federation's reserves. In an update on September 28, Liquid stated that the current audit is external and part of efforts to safely restore withdrawal operations, with the federation also updating the list of PAK authorization keys. Liquid has not provided an exact date when these operations will resume.
The PAK update includes replacing existing records and ensuring secure cold storage of keys. These actions are aimed at improving the security of the Bitcoin withdrawal system, considering the vulnerability revealed during the September incident. On September 6, an attacker was able to create about 4,000 unsupported LBTC and use the standard withdrawal process to access Bitcoin from the reserves. From its assessment after the incident, Liquid noted that the vulnerability was related to how Elements cached verification results – this created a consensus bug that was exploited during the attack.
The past incident exposed flaws in the authorization key configuration within the federation. Specifically, SideSwap, a member of the Liquid Federation, processed the withdrawal without being informed of the need to change or suspend the use of the online key. SideSwap is now reviewing its authorization key storage procedure before resuming its services. The audit of Elements v23.3.4 and the update of PAK records have become key steps in Liquid Network's recovery process. Currently, withdrawal operations remain suspended, and new updates on recovery are expected soon.





