A flaw in Liquid’s Bitcoin sidechain allowed an attacker to create 3,998.5 L-BTC without the Bitcoin needed to back them, according to blockchain security firm SlowMist. Detected Sept. 6, the exploit used a cache collision to bypass Elements’ range-proof checks and redeem the unbacked coins for Bitcoin.
The flaw affected Elements versions released before 23.3.4. An earlier patch issued Aug. 3 failed to address the weakness at the field boundary, leaving the system vulnerable.
SlowMist said the attacker used setup transactions to manipulate node caches before minting the unbacked L-BTC. The attacker later sought a 10% bounty through on-chain messages.
Version 23.3.4 fixed the issue by adding length prefixes and an emergency option to disable caching. The incident did not involve compromised private keys or smart contracts.
Liquid paused Bitcoin deposits and withdrawals through its peg while applying the updates, limiting further movement of funds.
Block production resumed Sept. 10 after a four-day halt. Liquid’s functionaries updated their nodes and began signing blocks again under close monitoring.
The recovery also included the return of 3,400 BTC to the federation wallet, leaving the attacker with 598.5 BTC.
