Two days after roughly 4,000 BTC left the Liquid Federation wallet, the transaction data is telling a sharper story than the initial halt announcement did: nothing in the signing machinery was broken, the emergency recovery path was never touched, and the codebase running the federation's side of the peg may not have been meaningfully maintained for over two years.

No official root-cause analysis has been published. What follows is a reading of the on-chain and public-repository evidence, compiled by Protos and cross-checkable against mempool.space's real-time audit of federation holdings.

Eleven Signatures, Eighty-Three Inputs, One Routine Peg-Out

The drain transaction spent 83 inputs from the federation wallet, each with exactly 11 valid signatures on the federation's 11-of-15 branch — the quorum the wallet is designed to accept. The attacker did not force or forge anything at the signing layer. According to Protos, they used a regular peg-out request, and because unbacked L-BTC had already been created upstream by an Elements validation bug, the peg-out machinery processed the order exactly as designed.

The detail that stands out to protocol engineers is what was bypassed. Liquid's wallet includes an emergency recovery path — two of three backup keys plus roughly 8,064 blocks (about 56 days) of waiting — built for exactly the scenario where the primary signing branch is compromised. It went unused. The emergency machinery exists for attackers who break the rules; this one followed them.

The Elements Commit Trail

The coins exited through SideSwap's peg-out authorization key (PAK) — the standard mechanism for authorizing withdrawals. Liquid has stated that the PAK "was not compromised, nor were any others," consistent with the emerging picture: the failure was in Elements, the open-source Bitcoin Core fork that largely Blockstream maintains, where a validation flaw allowed L-BTC to be created without backing.

The Elements public commit log shows a run of validation fixes in the first week of September. One, authored on the morning of September 1, is titled "Validation: always validate and retain dynafed header block_height" — its message notes that before the change, "a dynafed header with a mismatched height could be accepted." Protos could not establish that this specific commit fixes the bug the attacker used, and no maintainer has publicly confirmed the root cause. The timing is suggestive, not conclusive.

A Functionary Codebase Untouched Since April 2024

Casa security chief Jameson Lopp noted that the public repository for the federation's functionary software — the code the federation members run to sign and validate — appears not to have been touched in about two years, with the last commit recorded on April 19, 2024. That is two years and four months before 95% of the wallet's BTC walked out the door.

For a system whose entire security model is "a federation of reputable functionaries runs well-maintained software," a stale functionary codebase is the quiet finding of this incident: the 11-of-15 multisig enforced its quorum perfectly, on behalf of software nobody had updated in living memory.

The Dashboards That Disagreed

Mempool.space, itself a Liquid federation member, logged "an unauthorized -4019 BTC withdrawal" in its real-time audit within minutes, and its Liquid.network explorer promptly reflected the loss. The official Liquid.net dashboard did not — a divergence that has happened before, in January, when Adam Back attributed an earlier discrepancy to stale node software at mempool.space. This time, mempool.space was the accurate one.

As of Monday, mempool.space's data showed roughly 4,205 L-BTC outstanding against about 197 BTC of actual reserves — under 5% backing — while the attacker's address held 3,998 BTC pending the outcome of the on-chain negotiation with Blockstream, in which the actors claim to be white hats and have conditioned any return on the Elements bug being patched across every node.

The Open Questions

Three remain. What exactly in Elements accepted the unbacked issuance — and whether the September 1 validation fix closes it. Why the federation's functionary software went uncommitted for two years without triggering any internal alarm. And whether a federation whose signing quorum executed a $320 million payout on coins that never existed can restart without independently verifiable proof that every node runs patched code.

The uncomfortable summary: the multisig worked, the emergency path was irrelevant, and the bug lived one layer below everything the security model was designed to watch.

TrustGrade tracks the security posture of exchanges, sidechains, and the infrastructure between them. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.