Liquid Network bug enabled redemption of about 4,000 LBTC for BTC
AI Market Summary
Liquid Network reported an exploit in Elements range-proof validation that enabled ~4,000 LBTC to be minted without backing and then withdrawn via SideSwap into ~4,000 BTC released from reserves. The incident is negative for crypto market confidence, highlighting bridge/federated sidechain and software-validation risks. Near-term impact is likely concentrated in risk premia for Bitcoin-adjacent infrastructure and custodial withdrawal pathways.
Impact level
● High
Affected assets
BTC/USDT+0.84%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Liquid Network said in an incident report that a vulnerability in the open-source Elements software was exploited at 15:53:10 UTC on Sept. 6. The flaw involved range-proof validation tied to Liquid node caching, allowing an attacker to mint roughly 4,000 LBTC without corresponding Bitcoin reserves. The attacker then used Liquid's standard withdrawal process through Liquid Alliance member SideSwap to swap the LBTC for BTC, triggering the release and transfer of about 4,000 BTC to addresses controlled by the attacker.