Glass Ledger

Liquid Network Restart: What Actually Came Back

Liquid resumed block production on September 10, but transactions and pegs stay suspended and 598.5 BTC is still out. What the restart really restored.

Split myth-versus-reality panel contrasting the headline claim that Liquid is back against a status readout showing blocks producing but transactions and peg operations suspended.

At 10:00 UTC on September 10, 2026, four days after a consensus bug in the open-source Elements software let attackers mint roughly 4,000 unbacked Liquid Bitcoin and drain most of the federation's Bitcoin reserve, the Liquid Network resumed producing blocks. Blockstream chief executive Adam Back marked it publicly the same afternoon. Within hours the shorthand version had spread across timelines and aggregators: Liquid is back, the funds came home, the story is over. Almost every part of that shorthand is either incomplete or wrong. Here is what the restart actually restored, claim by claim, against what the network's own status updates say.

Myth: The Liquid Network Restart Means the Network Is Operating Normally

Reality: block production resumed, and almost nothing else did. The network's own update, posted at 12:26 UTC and dated 10:00 UTC, describes a controlled recovery phase in which blocks are produced without user transactions being processed. Functionary and bridge node updates have been deployed and functionaries are signing and validating blocks as expected, which is a meaningful technical milestone. But peg-in and peg-out operations are still suspended, including peg-outs authorised through Peg-out Authorization Keys, and restoring the Bitcoin to Liquid Bitcoin reserve is described as still in progress. A chain that produces empty blocks under continuous monitoring is a chain being tested, not a chain in service. Blockstream's own staged plan makes the sequencing explicit: resume block production while peg operations stay suspended, replay transactions verified as valid, and only then resume peg operations once the network state is restored, including a return of funds. The company has said no stage proceeds until it is considered safe.

Myth: The Attackers Returned the Money

Reality: they returned most of it. The actors, who identified themselves as white hats through OP_RETURN messages written on the Bitcoin main chain, sent 3,400 BTC back to the federation peg wallet at 16:09:25 UTC on September 7, the day after the incident. Against a drain of roughly 4,000 BTC, that leaves about 598.5 BTC outstanding, worth in the region of 47 million dollars at the time it was counted. Those two figures are consistent with each other and worth checking rather than taking on trust: 4,000 minus 3,400 leaves 600, and the reported outstanding balance of 598.5 sits just inside that, which is what you would expect when the larger number is an approximation. Samson Mow has publicly urged the return of the remainder. Until that happens, the reserve is short, and "the funds were returned" describes 85 percent of an event rather than the event.

A detail in how the return happened deserves more attention than it has had. Blockstream did not ask the actors to trust a tweet or a support email. It published a PGP signed message on chain confirming that it was safe to return funds, verifiable against Blockstream's own published security key. In an incident defined by a system accepting something that looked valid, the recovery ran on a signature anyone could check independently. That is the correct instinct, and it is the same instinct behind the offline-checkable payout receipts documented on NexusPool's Glass Ledger page.

Myth: Somebody's Keys Were Stolen

Reality: no key was compromised, and that is the uncomfortable part. The failure was a consensus bug in Elements, the open-source software the sidechain runs on, which allowed Liquid Bitcoin to be minted without a corresponding Bitcoin deposit behind it. The unbacked tokens then moved through a legitimate peg-out path. Every signature involved was genuine, produced by real functionaries doing exactly what the protocol told them to do. A stolen key is a containable problem with a known remedy. A system correctly authorising a withdrawal against value that was never deposited is a validation problem, and no amount of key hygiene addresses it. The lesson is not that the signers were careless. It is that a signature proves who approved something, never that the thing approved was true.

Myth: Adam Back's Pledge Means Holders Are Already Whole

Reality: the pledge matters, and it is not the same as recovery. On September 10 at 11:02 UTC, Back stated that the Liquid Bitcoin to Bitcoin one-to-one peg will be covered and urged holders not to panic-sell over the counter while the team works toward reopening peg operations. Taken at face value, that converts a shortfall in the reserve from a haircut borne by token holders into a balance sheet and legal question for Blockstream and the federation. That is a considerably better outcome for holders than the alternative. It is still a commitment about a gap that exists rather than a gap that has closed, and peg-outs remain suspended, so the promise has not yet been tested by anyone actually redeeming at scale. Back has also said a full post-mortem is due, which is the document worth waiting for.

Myth: The Liquid Network Exploit Says Something About Bitcoin

Reality: it says something specific about federated custody, which is a different thing. Liquid is a sidechain secured by a federation of functionaries, and the incident lived entirely inside that model and its software. Bitcoin's base chain produced blocks throughout without interruption or ambiguity, and the return transaction itself settled on it. What generalises from this is narrower and more useful than "sidechains are unsafe": when your coins are represented by a token that some group of signers can redeem on your behalf, the integrity of that representation is a thing you are trusting, separately from the cryptography that looks like it is protecting you. NexusPool's answer to that category of question is to avoid creating the representation at all. A block found by a NexusPool miner on Bitcoin, Litecoin, Dogecoin, or Bitcoin Cash pays through the coinbase transaction straight to the miner's own address, with a 0 percent pool fee, so there is no pool-held balance to be minted against, frozen, or negotiated over afterwards. The mechanics are set out on NexusPool's technology page, the pre-block payout check is on NexusPool's Payout Preflight tool, and current service state is published on NexusPool's status page.

The Reality, In Short

Liquid is producing blocks again, not processing transactions. About 598.5 BTC has not come back. The peg is pledged, not restored. No key was stolen, which makes the underlying bug harder to reason about, not easier. Every one of those is a fact the network's own updates state plainly, and every one of them gets flattened by the headline version.

Two honest limits on all of the above. None of this changes anyone's odds of finding a block on any chain, which are set by a miner's own hashrate divided by network difficulty and are identical at every pool, on every protocol, under every custody model. And nothing here is investment advice, a verdict on whether Liquid or its federation is safe to use going forward, or a claim that NexusPool's own core software is open source or public today. For the full timeline of the restart and Back's statements, see The Crypto Times on the Liquid Network restart.

Trust nothing. Verify what a "network restored" announcement actually restored before you move funds through it.