()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.

When will Liquid Network restore Bitcoin peg outs?

Rony Roy
Edited by
News
When will Liquid Network restore Bitcoin peg outs? - 1

Liquid Network has moved closer to restoring peg out operations after starting an independent security audit of Elements v23.3.4 and coordinating changes to the authorization keys used in the withdrawal process.

Summary
  • Liquid Network has started an independent external security audit of Elements v23.3.4 before restoring peg out operations.
  • The Liquid Federation is replacing existing PAK entries and ensuring peg out keys are properly secured in cold storage.
  • Peg outs remain suspended, with Liquid yet to provide a firm date for when operations will resume.
  • The latest security work follows the September exploit that led to roughly 4,000 BTC being withdrawn from the federation reserve.

The Liquid Network said in its Sept. 28 ecosystem update that an external security audit of Elements v23.3.4 is now underway as part of its work to safely restore peg outs following the network’s September security incident.

At the same time, the Liquid Federation is updating its Peg out Authorization Key, or PAK, list. Existing entries are being replaced and the federation is working to ensure that all Bitcoin receiving keys associated with peg outs are properly secured in cold storage.

Liquid did not provide a date for withdrawals to restart. The network said the audit and PAK changes are steps toward resuming secure peg out operations, with another update on the restoration process expected shortly.

Liquid Network audit targets Elements v23.3.4

Elements v23.3.4 was released earlier this month to address the software flaw exploited during the Sept. 6 incident, when an attacker created roughly 4,000 unbacked LBTC and used Liquid’s normal peg out process to withdraw Bitcoin from the federation reserve.

The latest external audit adds another review of that release before peg outs are switched back on.

Elements is the open source blockchain platform behind Liquid. The network uses confidential transactions, which hide transaction amounts while cryptographic proofs allow nodes to verify that those amounts are valid.

Liquid’s post incident assessment said the vulnerability involved the way Elements cached the results of rangeproof verification. An earlier change had removed some transaction context from the cache key, creating a consensus flaw that could allow a cached verification result to be reused under different circumstances.

A subsequent fix addressed the initially identified problem, but a second issue involving how fields were combined in the cache key remained. The Sept. 6 attacker exploited that second weakness to create an output whose value was not backed by its inputs.

Elements v23.3.4 changed how rangeproof and surjection proof cache keys are constructed by serializing each field with a length prefix. Liquid said the change prevents different sets of inputs from producing the same cache key through the collision method used in the attack.

The hardened fix was merged into the Elements 23.3.x release branch on Sept. 8 and Elements v23.3.4 was published the following day.

As previously covered by crypto.news, Liquid resumed block production after functionary nodes received the required software updates, while peg operations remained disabled.

Transactions later returned to the network as Liquid proceeded through its staged recovery process. Peg outs have remained suspended while the federation completes work on the part of the system that releases BTC from the reserve.

Liquid Federation is replacing PAK entries

The second part of the Sept. 28 update centers on the PAK system used to authorize peg outs from Liquid to Bitcoin.

Under Liquid’s architecture, PAK entries contain two keys with separate functions. An offline component is derived from a member’s Bitcoin receiving wallet, while an online key signs peg out requests.

Functionary nodes use the offline component to verify that the Bitcoin destination belongs to a registered PAK entry. The private keys controlling the receiving Bitcoin are intended to remain offline.

The online component performs a different job. Its private key operates on an Elements node because it is needed to sign requests for Bitcoin to be released through the peg out process.

Liquid’s incident assessment said the offline wallet arrangement is intended to provide another layer of protection if an upstream system fails. Bitcoin released through a peg out would remain in a cold wallet and require a separate action before it could be moved onward.

The Sept. 6 incident exposed a weakness in that protection alongside the Elements consensus vulnerability.

After creating the unbacked LBTC, the attacker used SideSwap, a Liquid Federation member with a PAK, to process the peg out. SideSwap received roughly 4,000 LBTC through its service before federation signers released approximately 3,996 BTC on Bitcoin.

Liquid’s assessment said two separate problems allowed the Bitcoin to be taken: the Elements consensus vulnerabilities and a gap in the configuration of one federation member’s PAK signing process.

SideSwap has said the federation knew its peg out authorization key operated online and that this arrangement had been visible in its peg outs for years. The company said it had not been told to change how the key operated or suspend peg outs before the incident.

SideSwap said it was reviewing how its authorization key is held, as well as the limits and checks applied before payouts, and would not restore its peg services until it and the federation were satisfied with the new security setup.

Liquid’s latest update now confirms that the federation is replacing existing PAK entries and working to ensure the relevant peg out keys are held in cold storage before withdrawals resume.

Peg outs remain the final restricted operation

Normal transaction activity returned earlier in September, but the Bitcoin peg has remained subject to restrictions during the recovery.

Liquid initially halted bridge nodes on Sept. 6 after the attacker exploited the Elements flaw. Block production resumed on Sept. 9 using the corrected chain, followed by the return of user transaction activity as the federation monitored the network.

Peg outs stayed disabled throughout those stages.

The original incident resulted in approximately 4,000 BTC leaving the federation reserve after the attacker created unbacked LBTC. The actors identified themselves as white hats through an on chain message and later returned 3,400 BTC to the federation wallet after Blockstream confirmed that affected nodes had been patched.

Approximately 602 BTC remains subject to recovery efforts, according to Liquid’s latest detailed incident assessment.

Blockstream later rejected a bounty demand tied to the remaining funds, saying it would work with law enforcement, exchanges, forensic specialists and other service providers to pursue their recovery.

Liquid’s staged recovery plan calls for peg operations to resume after the network state has been restored and the required security work has been completed. The external audit of Elements v23.3.4 and replacement of PAK entries are the latest steps disclosed under that process.