SlowMist Uncovers Liquid Network Flaw That Minted 3,998 Unbacked L-BTC

TL;DR:
- SlowMist traced the Liquid exploit to a range-proof cache collision that let approximately 3,998.5 unbacked L-BTC enter circulation without a corresponding Bitcoin peg-in.
- Two setup transactions seeded node caches, allowing a later transaction to reuse a colliding key and bypass cryptographic verification before the assets were redeemed for BTC.
- About 3,400 BTC was returned, while 598.5 BTC remained with the attacker and peg operations stayed suspended during ongoing network recovery.
SlowMist has traced the September 6 Liquid Network incident to a consensus-layer flaw that allowed approximately 3,998.5 unbacked L-BTC to enter circulation without any corresponding Bitcoin peg-in. The security firm reconstructed the Liquid-side transaction path and identified a range-proof verification cache collision inside Blockstreamโs Elements codebase. The alarming detail is that the network accepted fabricated value because a performance shortcut caused distinct verification inputs to share the same cache key. Within minutes, the newly created L-BTC was consolidated and redeemed through the federated peg-out mechanism for real Bitcoin on the mainnet during the sudden breach.
โฆ Continue reading the full article at the original source below.



