Liquid Network披露約4,000 BTC被盜鑄漏洞細節

AI 市場總結
Liquid's incident report confirms ~4,000 unbacked LBTC were minted via an Elements rangeproof verification caching flaw, then converted into real BTC through an authorized pegout path, draining federation reserves. Although no private keys were compromised, the event highlights sidechain trust and operational risks, with Liquid still offline pending an emergency Elements release and reserve re-collateralization. ~598.5 BTC remains outstanding.
影響等級
● 中
主要受影響標的
BTC/USDT-0.35%
AI 觀點 · BTC/USDTAI 觀點
▼ 看空
立即交易
⚠️ AI觀點僅為演算法基於新聞內容的自動生成分析,不構成投資建議,不代表BingX立場。市場有風險,投資需謹慎。
Liquid Federation公布事故調查報告,確認攻擊者利用Elements在rangeproof驗證快取機制上的漏洞,生成約4,000枚未有足額支持的LBTC。其後,攻擊者透過SideSwap的授權pegout通道,將無效LBTC兌換成真實BTC。 報告指出,Liquid的functionaries當時將相關交易判定為有效,並從聯邦儲備釋出約4,000 BTC。事件未涉及私鑰外洩,pegout機制本身亦按設計運作。 事故前,Liquid儲備約為4,205 BTC;在暫停營運前,儲備一度降至最低約197 BTC。自稱"white hats"的人士其後已歸還3,400 BTC,仍有約598.5 BTC未追回。 目前Liquid仍維持離線。Blockstream正準備緊急推出Elements v23.3.4,並著手在恢復網絡運作時重建1:1的BTC儲備支持。