SlowMist Uncovers Liquid Network Flaw That Minted 3,998 Unbacked L-BTC

SlowMist traces Liquid’s 3,998.5 unbacked L-BTC mint to a cache collision as 598.5 BTC remains with the attacker and peg operations stay suspended.
Table of Contents

TL;DR:

  • SlowMist traced the Liquid exploit to a range-proof cache collision that let approximately 3,998.5 unbacked L-BTC enter circulation without a corresponding Bitcoin peg-in.
  • Two setup transactions seeded node caches, allowing a later transaction to reuse a colliding key and bypass cryptographic verification before the assets were redeemed for BTC.
  • About 3,400 BTC was returned, while 598.5 BTC remained with the attacker and peg operations stayed suspended during ongoing network recovery.

SlowMist has traced the September 6 Liquid Network incident to a consensus-layer flaw that allowed approximately 3,998.5 unbacked L-BTC to enter circulation without any corresponding Bitcoin peg-in. The security firm reconstructed the Liquid-side transaction path and identified a range-proof verification cache collision inside Blockstream’s Elements codebase. The alarming detail is that the network accepted fabricated value because a performance shortcut caused distinct verification inputs to share the same cache key. Within minutes, the newly created L-BTC was consolidated and redeemed through the federated peg-out mechanism for real Bitcoin on the mainnet during the sudden breach.

The exploit relied on structured transactions rather than stolen signing keys or a compromised peg-out authorization key. Two setup transactions placed range proofs and commitments onchain while seeding node caches with crafted data. A third transaction then reused a colliding cache key with different field boundaries. Once nodes recorded a cache hit, they skipped cryptographic verification and minimum-value checks, allowing the counterfeit commitment to pass as valid. SlowMist said the vulnerability originated in cache-key construction that concatenated variable-length fields without length prefixes, creating the conditions for two different argument sets to generate the same hash.

SlowMist traced the Liquid exploit

Elements Patch Targets The Cache Collision Mechanism

The flaw affected Elements versions before 23.3.4, including releases issued after an August 3 patch that added missing fields but failed to protect their boundaries. Version 23.3.4, released September 8, introduced length prefixes and an emergency switch that can disable the range-proof cache entirely. The fix addresses the exact collision mechanism that transformed a performance optimization dating back to 2016 into a consensus-level vulnerability. Block production resumed in a controlled restart on September 10, initially without user transactions, while federation members updated nodes and continued monitoring the network before the network gradually returned to service.

The financial aftermath remains unresolved. About 3,400 BTC was returned to the federated peg wallet the next day, but 598.5 BTC remained under the attacker’s control when SlowMist published its analysis. The attacker continued moving those funds and embedding messages demanding a 10% bounty. Liquid’s recovery now depends on restoring the reserve while preserving the promised 1:1 backing between L-BTC and Bitcoin. Peg-in and peg-out operations remain suspended, Blockstream has rejected the bounty demand, and Adam Back has said the peg will be fully covered, leaving timing and reserve replenishment as the key unanswered questions.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews