Hasty Briefsbeta

Bilingual

Liquid Network Security Incident Assessment

4 hours ago
  • On September 6, 2026, an attacker exploited a cache vulnerability in Elements' rangeproof verification to inflate LBTC supply by ~4,000 LBTC, later withdrawn as ~4,000 BTC.
  • The root cause was two related bugs (Bug A and Bug B) in the rangeproof cache key construction; the fix for Bug A introduced a length-framing issue enabling collision attacks.
  • The attacker routed the unbacked LBTC through SideSwap, a federation member with a Peg-out Authorization Key, bypassing offline security requirements, and returned 3,400 BTC after on-chain negotiations.
  • The incident triggered a network halt, an emergency patch, and a staged chain recovery that replayed validated transactions without the buggy cache; ~602 BTC remains outstanding as of the latest update.
  • Corrective actions include stronger cache-key design, recurring consensus-code review, expanded fuzzing/symbolic execution, and strengthened external researcher reporting pathways.