SlowMist: Liquid Network Cache-Key Collision Bug Led to 3,998.5 Unbacked LBTC Mint

AI Market Summary
SlowMist attributes the Liquid Network incident to a consensus-layer rangeproof cache collision in Elements, enabling ~3,998.5 unbacked LBTC to bypass verification and be redeemed for mainnet BTC. Although ~3,400 BTC was returned, ~598.5 BTC remains with the attacker and peg operations are suspended during recovery. The episode heightens counterparty and bridge/federation risk perceptions around Bitcoin-adjacent infrastructure.
Impact level
● High
Affected assets
BTC/USDT+0.19%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
SlowMist said the September 6 incident on Blockstream's Liquid Network stemmed from a consensus-layer weakness tied to a rangeproof verification cache collision in the Elements codebase. The firm estimates roughly 3,998.5 LBTC entered circulation without any corresponding Bitcoin pegin, then was quickly consolidated and redeemed via the federated pegout process for real BTC on the Bitcoin mainnet. According to SlowMist's reconstruction, the attack did not require stolen signing keys or a compromised pegout authorization key. Instead, it used a sequence of structured transactions. Two preparatory transactions placed range proofs and commitments on-chain while priming node caches with crafted data. A subsequent transaction reused a colliding cache key with different field boundaries. When nodes registered a cache hit, they skipped cryptographic verification and minimum-value checks, allowing a counterfeit commitment to be accepted. SlowMist attributed the root cause to cache-key construction that concatenated variable-length fields without length prefixes, making it possible for different input sets to hash to the same key. The issue affected Elements versions prior to 23.3.4, including builds released after an August 3 patch that added missing fields but did not properly protect field boundaries. Elements 23.3.4, released September 8, introduced length prefixes and added an emergency option to disable the rangeproof cache entirely. SlowMist said the update closes the specific collision pathway that turned a performance optimization dating back to 2016 into a consensus-level vulnerability. Liquid restarted block production in a controlled manner on September 10, initially without user transactions, as federation members updated nodes and continued monitoring before gradually restoring service. The financial fallout remains unsettled. Roughly 3,400 BTC was returned to the federated peg wallet the next day, while 598.5 BTC remained under the attacker's control at the time of SlowMist's publication. SlowMist said the attacker continued moving funds and embedded messages demanding a 10% bounty. Pegin and pegout operations remain suspended. Blockstream has rejected the bounty demand, and Adam Back said the peg will be fully covered, leaving the timing of reserve replenishment as the main outstanding question.