Tokens created out of thin air may explain how $320 million in Bitcoin left the Liquid sidechain



Researchers examining the roughly $320 million Liquid Network incident have identified an alleged failure in the software’s transaction-validation cache, offering a more specific explanation for how unbacked tokens could be redeemed for real Bitcoin.

Accounts also raise a deployment question. Mononaut said the exploited bug had entered Elements’ master development branch the previous week but had never appeared in a tagged release. Liquid’s federation functionaries apparently ran that code, he said, while other nodes rejected the invalid transactions.

That deployment account remains unconfirmed by Blockstream in the available statements. If established, it would put the software rollout at the center of an incident in which valid signing credentials authorized the release of Bitcoin against allegedly bug-created L-BTC.

Liquid is a Bitcoin sidechain whose L-BTC tokens are intended to be backed one-for-one by BTC held by its federation. As CryptoSlate previously reported, SideSwap said a customer submitted 4,000 L-BTC through its peg-out service on Sept. 6, prompting the release of approximately 3,996 BTC.

Related Reading

A whitehat hacker is holding $320 million in drained Bitcoin until developers prove they patched a fatal network flaw

Liquid said neither SideSwap’s peg-out authorization key nor other federation keys had been compromised.

The emerging technical accounts focus on how the tokens reached that withdrawal process.

Calle described a flaw involving range proofs, which let nodes check that hidden transaction amounts fall within an allowed range without revealing those amounts.