Liquid Network Bug Exposed: $320 Million Incident Traced to Software Flaw
A recent $320 million Liquid Network incident has been attributed to an alleged failure in the software's transaction-validation cache. Researchers have identified an exploited bug that allowed unbacked tokens to be redeemed for real Bitcoin.
According to Mononaut, the bug had entered Elements' master development branch a week prior but never appeared in a tagged release. Liquid's federation functionaries ran this code, while other nodes rejected the invalid transactions.
Liquid is a Bitcoin sidechain whose L-BTC tokens are intended to be backed one-for-one by BTC held by its federation. A customer submitted 4,000 L-BTC through SideSwap's peg-out service on Sept. 6, prompting the release of approximately 3,996 BTC.
The emerging technical accounts focus on how the tokens reached that withdrawal process. Calle described a flaw involving range proofs, which let nodes check that hidden transaction amounts fall within an allowed range without revealing those amounts.