Liquid Network says it has taken another step toward restoring Bitcoin peg-outs, launching an independent external security audit of Elements v23.3.4 while the federation updates the authorization keys used for withdrawals.
The network has not given a date for peg-outs to resume. It described the audit and Peg-out Authorization Key, or PAK, changes as part of the security work still required after the Sept. 6 exploit that led to about 4,000 BTC leaving the federation reserve.
Audit and key replacement now underway
In a Sept. 28 ecosystem update, Liquid said an outside review of Elements v23.3.4 is in progress before peg-out operations are turned back on. At the same time, the Liquid Federation is replacing existing PAK entries and working to make sure all Bitcoin receiving keys tied to peg-outs are secured in cold storage.
Liquid said another update on the restoration process is expected shortly, but it did not set a firm restart date for withdrawals. Peg-outs remain suspended even as these latest steps move the network closer to reopening that part of the system.
What the software update is meant to fix
Elements is the open-source blockchain platform that powers Liquid. The network uses confidential transactions, where transaction amounts are hidden while cryptographic proofs still let nodes verify that those amounts are valid.
Liquid’s post-incident assessment said the September vulnerability involved how Elements cached the results of rangeproof verification. An earlier change removed some transaction context from the cache key, creating a consensus flaw that could let a cached verification result be reused in different circumstances. A later fix addressed the first identified issue, but a second weakness remained in how fields were combined in the cache key.
According to Liquid, the Sept. 6 attacker exploited that second weakness to create an output whose value was not backed by its inputs. Elements v23.3.4 changed the construction of rangeproof and surjection proof cache keys by serializing each field with a length prefix. Liquid said that hardening prevents different input sets from producing the same cache key through the collision method used in the attack. The fix was merged into the 23.3.x branch on Sept. 8, and v23.3.4 was published the next day.
How the peg-out process became part of the breach
The latest update also focuses on the PAK system that authorizes peg-outs from Liquid to Bitcoin. Under Liquid’s design, a PAK entry contains two keys with different roles: an offline component derived from a member’s Bitcoin receiving wallet, and an online key that signs peg-out requests. Functionary nodes use the offline component to confirm that a Bitcoin destination belongs to a registered PAK entry, while the private keys controlling the receiving Bitcoin are supposed to stay offline.
Liquid has said this arrangement is intended to add protection if an upstream system fails, because Bitcoin released through a peg-out should still land in a cold wallet and require another action before moving further. But the Sept. 6 incident exposed a weakness in that protection alongside the Elements consensus flaw.
After creating unbacked LBTC, the attacker used SideSwap, a Liquid Federation member with a PAK, to process the peg-out. SideSwap received roughly 4,000 LBTC through its service before federation signers released about 3,996 BTC on Bitcoin. Liquid’s assessment said two separate problems enabled the loss: the Elements consensus vulnerabilities and a gap in the configuration of one member’s PAK signing process. SideSwap has said it was reviewing how its authorization key is stored, along with the limits and checks applied before payouts, and would not restore peg services until it and the federation were satisfied with the revised security setup.
What has resumed and what remains unresolved
Liquid previously resumed block production after functionary nodes updated their software, and ordinary transaction activity later returned as the network moved through a staged recovery. Peg-outs, however, have remained the final restricted operation while the federation completes work on the mechanism that releases BTC from the reserve.
The original exploit resulted in about 4,000 BTC leaving the reserve after unbacked LBTC was created. The actors later identified themselves as white hats in an on-chain message and returned 3,400 BTC after Blockstream said affected nodes had been patched. Liquid’s latest detailed incident assessment says about 602 BTC is still subject to recovery efforts.
For now, the next confirmed step is the completion of the external audit and the replacement of PAK entries with the related receiving keys secured in cold storage. Liquid has said peg operations will resume only after the network state has been restored and the required security work is finished.
Source: crypto.news