Màn Vũ reveals that Liquid Network has been attacked by a vulnerability; attackers minted 3998.5 l-BTC
2026-09-11 20:15:02
According to CoinMeta, it was reported that on September 6th, Liquid Network suffered from a vulnerability attack involving cache key collisions caused by rangeproof. Without the corresponding BTC transfer (to peg-in), the attacker managed to mint approximately 3998.5 l-BTC without any collateral, and then exchanged these for Bitcoin mainnet BTC through peg-out within a few minutes. Subsequently, about 3400 BTC were returned to the Liquid federated pegged wallet, while around 598.5 BTC remained under the attacker's control. SlowMist stated that the vulnerability stemmed from the fact that Elements did not add a length prefix when concatenating multiple variable-length fields in the rangeproof validation cache keys, allowing different parameter combinations to generate the same cache key. The attacker exploited this by constructing transactions that triggered cache collisions, enabling nodes to receive a "validation passed" result and bypassing the secp256k1_rangeproof_verify check as well as the minimum amount verification, thus accepting outputs not supported by actual assets and completing the minting of l-BTC. SlowMist has traced the flow of funds on the Bitcoin side and completed an analysis of the incident.
Bullish 1
Bearish 0
Source:X
This content is for market information only and does not constitute investment advice.