Liquid Network Hack Exposes Flaw in Transaction-Validation Cache
A recent incident on the Liquid Network resulted in approximately $320 million worth of Bitcoin being withdrawn from its reserves. Researchers have identified an alleged failure in the software's transaction-validation cache as a possible explanation for how unbacked tokens could be redeemed for real BTC.
The cache-key collision allowed invalid transactions to bypass Liquid's range-proof checks, which are intended to prevent newly created tokens from appearing to balance mathematically. This flaw was reportedly exploited by an attacker who constructed an invalid output and proof that matched the cache key associated with a previously valid check.
A reported node split may explain why some Liquid systems accepted the exploit while others rejected it. The nodes that accepted the transaction, including those powering mempool's Liquid explorer, approved withdrawals and continued building blocks.