Liquid Network Flaw Exposed: $320 Million in Bitcoin Released Against Unbacked Tokens
A recent investigation into the $320 million Liquid Network incident has revealed a potential software flaw that may have enabled unbacked tokens to be redeemed for real Bitcoin. Researchers believe a bug in the transaction-validation cache of the Liquid Network's software allowed invalid transactions to pass through, enabling the release of approximately 3,996 BTC.
The incident occurred on September 6 when a customer submitted 4,000 L-BTC (Liquid's tokens) through SideSwap's peg-out service. This prompted the release of Bitcoin against allegedly bug-created L-BTC. Blockstream has not confirmed whether the exploited bug had entered Elements' master development branch and was deployed by Liquid's federation functionaries.
Mononaut, a researcher examining the incident, stated that the exploited bug had never appeared in a tagged release but had entered the master development branch the previous week. The deployment account remains unconfirmed, and its establishment would place the software rollout at the center of the incident.