SlowMist details Liquid Network exploit, attacker mints 3,998 L-BTC in largest Bitcoin sidechain hack of 2026

42 minutes ago 2



A single software bug in Blockstream’s Elements codebase allowed an attacker to conjure nearly 4,000 unbacked L-BTC out of thin air, peg them out for real Bitcoin, and drain roughly 95% of the Liquid Federation’s reserves in a matter of hours. SlowMist published its full analysis of the September 6 exploit on September 11, confirming what is now the largest publicly disclosed security incident involving a Bitcoin sidechain this year. The damage: approximately 3,998.5 L-BTC minted and redeemed, worth roughly $320 million. The Liquid Federation’s reserve wallet went from holding over 4,200 BTC to about 197 BTC. How a caching shortcut became a $320 million problem The root cause, according to SlowMist’s analysis, was a cache key collision vulnerability buried in the range-proof verification process. Range proofs are cryptographic checks that confirm transaction amounts fall within valid bounds without revealing exact values. They’re fundamental to Liquid’s confidential transaction model. To speed up verification, Elements cached previously validated proofs so it wouldn’t have to recheck them. The problem was how those cache keys were constructed. Prior to version v23.3.4, the software...

Read Entire Article