Liquid details the mechanics of ~4,000 BTC exploit

AI Market Summary
Liquid's incident report confirms ~4,000 unbacked LBTC were minted via an Elements rangeproof verification caching flaw, then converted into real BTC through an authorized pegout path, draining federation reserves. Although no private keys were compromised, the event highlights sidechain trust and operational risks, with Liquid still offline pending an emergency Elements release and reserve re-collateralization. ~598.5 BTC remains outstanding.
Impact level
● Medium
Affected assets
BTC/USDT-0.35%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
The Liquid Federation published an incident report outlining how attackers minted roughly 4,000 unbacked LBTC by abusing a flaw in Elements' rangeproof verification caching. The counterfeit LBTC was then routed through SideSwap's authorized pegout process and exchanged for real BTC. Liquid's functionaries treated the transactions as valid and released about 4,000 BTC from the federation reserve. The federation said no private keys were compromised and that the pegout mechanism functioned as intended. Liquid held about 4,205 BTC prior to the incident; the reserve dropped to as low as 197 BTC before operations were stopped. The group describing itself as white hats has returned 3,400 BTC, leaving approximately 598.5 BTC outstanding. Liquid remains offline while Blockstream prepares an emergency Elements v23.3.4 release and works to restore the network with 1:1 BTC backing.