SlowMist: Liquid Network Exploited via Rangeproof Cache Key Collision, 3,998.5 LBTC Minted Without Peg-ins
SlowMist said the Liquid Network was hit on Sept. 6 after an attacker exploited a vulnerability tied to Rangeproof verification cache key collisions. In a post on X cited by ME News on Sept. 11 (UTC+8), the security firm said the attacker minted about 3,998.5 LBTC without matching BTC peg-ins, then used peg-outs to swap the tokens into Bitcoin mainnet BTC within minutes.
Following the incident, roughly 3,400 BTC has been returned to the Liquid Federation peg wallet, while about 598.5 BTC remains under the attacker's control.
SlowMist attributed the issue to how Elements generates cache keys for Rangeproof verification. The mechanism concatenated multiple variable-length fields without adding length prefixes, allowing distinct parameter sets to produce identical cache keys. By crafting transactions that triggered these collisions, the attacker caused nodes to reuse a cached "verification passed" result, bypassing both secp256k1_rangeproof_verify and minimum-amount checks. Nodes then accepted outputs not backed by real assets, enabling the unauthorized LBTC mint.
SlowMist said it has traced the Bitcoin-side fund flows and completed its incident analysis. (Source: ODAILY)