$320 Million Bitcoin Heist: Researchers Reveal Cache Exploit
The $320 million incident on Liquid Network, a Bitcoin sidechain, has been attributed to an alleged failure in the software's transaction-validation cache. Researchers have identified that tokens created out of thin air may be responsible for the large-scale withdrawal of BTC from the network.
According to Mononaut, the exploited bug had entered Elements' master development branch the previous week but had never appeared in a tagged release. This raises questions about the deployment process and whether Liquid's federation functionaries ran the code that accepted invalid transactions while other nodes rejected them.
The incident occurred when a customer submitted 4,000 L-BTC through SideSwap's peg-out service on Sept. 6, prompting the release of approximately 3,996 BTC. The researchers suggest that the attacker could construct an invalid output and proof that matched the cache key associated with a previously valid check, allowing them to bypass a range check.
The actors controlling the withdrawn Bitcoin have described themselves as whitehats and have conditioned the return of most funds on the bug being fixed across affected nodes. A postmortem is needed to establish which code functions ran, why it was deployed, and how its validation behavior differed from the nodes that rejected the block.