SlowMist: Cache-Key Collision Bug Drove $320M Liquid Network Exploit

AI مارکیٹ کا خلاصہ
SlowMist detailed a $320M Liquid Network exploit where a cache key collision in Elements' rangeproof verification enabled minting ~3,998.5 unbacked LBTC and rapid peg-outs to real BTC, draining ~95% of federation reserves. Although keys weren't compromised and a patch (v23.3.4) plus peg suspension limited further loss, the incident underscores smart-contract-like implementation risk in Bitcoin-adjacent systems and can weigh on trust in sidechains and related infrastructure.
اثر کی سطح
● ہائی
متاثرہ اثاثے
BTC/USDT+0.14%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
SlowMist says a single bug in Blockstream's Elements codebase let an attacker mint nearly 4,000 LBTC with no backing, redeem the tokens for real Bitcoin, and siphon away about 95% of the Liquid Federation's reserves within hours. In a report published Sept. 11, SlowMist detailed the Sept. 6 exploit, calling it the largest publicly disclosed security incident involving a Bitcoin sidechain so far this year. The firm estimates the impact at about 3,998.5 LBTC minted and pegged out, worth roughly $320 million. Liquid's reserve wallet balance fell from more than 4,200 BTC to around 197 BTC. SlowMist attributes the breach to a cache-key collision vulnerability inside the rangeproof verification workflow. Range proofs are cryptographic checks used to validate that transaction amounts are within allowed limits without revealing the exact amounts, a core component of Liquid's confidential transactions. Elements sped up validation by caching previously verified proofs to avoid rechecking them. Before v23.3.4, the cache keys were generated without length prefixes, allowing two different inputs to produce the same key. With a collision, the software could treat an invalid proof as already verified if it matched the cache entry of a legitimate one. SlowMist says the attacker used this bypass to create LBTC not backed by Bitcoin in the federation's peg wallet, then quickly pegged the tokens out to Bitcoin mainnet BTC. After the exploit was detected, Blockstream suspended peg operations to stop further outflows and paused block production. The network restarted on Sept. 10 after the release of Elements v23.3.4, which patched cache key management by adding proper length prefixes. Blockstream said the incident stemmed from a software defect, not a compromise of the federation's signing keys. The attacker communicated through Bitcoin OP_RETURN messages embedded in transactions, describing themselves as a whitehat and requesting a 10% bounty. After the fix, roughly 3,400 BTC was returned to the federation peg wallet. About 598.5 BTC was retained by the attacker, implying a take closer to 15% of the total, above the 10% originally requested. SlowMist emphasizes that the weakness was not tied to federation governance or key management, but to a performance optimization that was implemented unsafely. The network was down for four days, and most reserves were drained before detection. The firm also highlights the missing length prefixes in cache key construction as the critical enabling detail, urging other projects with similar caching patterns to audit for the same class of flaw.