GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar
Liquid Network

Liquid Network

Active

Bitcoin layer-2 solution

News Heat Trend

Project Overview

The Liquid Network is a Bitcoin layer-2 solution that enables fast, confidential settlement and issuance of digital assets, such as stablecoins, security tokens, and other financial instruments, on top of the Bitcoin blockchain.

Liquid Network Releases Emergency Fix: Elements v23.3.4 Patches Proof Validation Cache Vulnerability

Odaily News: Liquid Network announced that the emergency release Elements v23.3.4 is now live, with Functionary nodes having immediately begun upgrades. All Liquid node operators are advised to update accordingly. This release addresses a previously identified Proof validation cache vulnerability by strengthening the cache keys used for Range Proofs.Regarding network recovery, Blockstream stated that a recovery plan is still being formulated, expected to proceed in three phases: **resume block production while continuing to pause Peg operations; replay verified valid transactions; restore Peg operations after the network state is fully recovered and fund returns are confirmed.** Currently, the first two phases are being tested in parallel, and any phase will only advance once confirmed secure.Liquid Network stated that Elements v23.3.4 has undergone multiple rounds of internal and external reviews, with participants including the Bitcoin Red Team, Alpen Labs, and other teams. Meanwhile, Liquid Network reminds users to be wary of fake upgrade websites exploiting this incident for scams. Information should only be obtained through official Liquid Network and Blockstream channels, and users should never send funds to strangers or disclose private keys or seed phrases.

Liquid Network: In discussions with white hat to recover remaining 598.5 BTC, network restoration efforts also underway

Liquid Network's official security incident report: On September 6, a vulnerability related to the range proof verification method in Liquid node caching within the open-source software Elements was exploited, resulting in the creation of approximately 4,000 LBTC tokens not backed by bitcoin reserves. The exploiter subsequently exchanged them for approximately 4,000 BTC via SideSwap and the Liquid standard Peg-out mechanism. Prior to the incident, Liquid's reserves stood at approximately 4,205 BTC. After the relevant Peg-out and other withdrawals completed before the network halt, reserves fell to 197 BTC.According to the official statement, the incident did not involve the compromise of Functionary nodes or private keys, and other issued assets on Liquid such as USDT were also unaffected by the vulnerability. The exploiter claimed to be a white hat security researcher and returned 3,400 BTC to the Liquid Federation Peg wallet on September 7. Approximately 598.5 BTC (about 15% of the funds involved) remain unrecovered, and Blockstream is in communication to recover the remaining assets.At present, the top priority is to recover the remaining funds and restore Liquid Network to normal operation as quickly and safely as possible. A fix for the vulnerability has been developed and is currently undergoing multiple rounds of internal and external review. Blockstream is preparing to urgently release Elements v23.3.4, which is expected to be rolled out as soon as preparations are complete, with a target launch within approximately 48 hours. Following the software update, Liquid Network Functionary operators will make further adjustments to restore full network functionality and resume a corrected network state, including rejecting previously invalid Peg-outs.

SlowMist Discloses Liquid Vulnerability Details: Attacker Minted 3,998.5 L-BTC Without Collateral, Approximately 598.5 BTC Still Not Returned

SlowMist has disclosed that the Liquid Network was attacked on September 6 via a Rangeproof verification cache key collision vulnerability. The attacker minted approximately 3,998.5 L-BTC without collateral — with no corresponding BTC peg-in — and then within minutes converted them to BTC on the Bitcoin mainnet via peg-out. After the incident, approximately 3,400 BTC was returned to the Liquid Federation peg wallet, but approximately 598.5 BTC remains under the attacker's control.SlowMist noted that the root cause of the vulnerability lies in the fact that the Rangeproof verification cache key in Elements did not include length prefixes when concatenating multiple variable-length fields, allowing different parameter combinations to potentially generate the same cache key. The attacker triggered a cache collision by constructing transactions, causing nodes to hit a "verification passed" cached result, thereby bypassing secp256k1_rangeproof_verify and the minimum amount check, ultimately accepting outputs not backed by real assets and completing the L-BTC minting. SlowMist stated that it has traced the fund flows on the Bitcoin side and completed its analysis of the incident.

Liquid Network white hat hacker returns 3,400 BTC, keeps about 598 BTC as bounty

According to on-chain monitoring by analyst PeckShield (@PeckShieldAlert), the Liquid Network was targeted by white-hat hackers. Approximately 4,000 BTC (roughly $320 million) were transferred from a Liquid Federation wallet. The funds were consolidated into address bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte, accompanied by an on-chain message: "We are white hats, please contact us on-chain." Subsequently, the hackers completed on-chain negotiations with Blockstream, returning 3,400 BTC (approximately $315 million, or 85% of the total) while retaining around 598.5 BTC (about $47.38 million) as a bug bounty.

Liquid Network hacker still holds 598.5 bitcoins, L-BTC-to-bitcoin redemption channel paused for 11 days

Odaily News: The Liquid Network attacker has returned 3,400 bitcoins after the September 6 exploit, accounting for approximately 85% of the transferred assets; they currently still hold 598.50 bitcoins, worth over $45 million.Blockstream, the digital asset infrastructure company responsible for maintaining the Liquid Network, has refused to pay a ransom for the remaining assets and is demanding the return of the relevant bitcoins. The network shows 4,234.76 L-BTC in circulation, while the bitcoin reserves stand at only 3,632.23.The L-BTC-to-bitcoin redemption function has still not been restored, with Sideswap stating that redemptions are currently unavailable; Blockstream founder Adam Back said that L-BTC will be backed 1:1 by bitcoin reserves and reminded holders not to sell L-BTC off-market at a discount.As of now, Blockstream has not yet issued an announcement that "redemptions are live." The attacker's wallet continues to receive on-chain messages and has been subjected to address poisoning attacks and scam messages, with the related attacks inducing transfers by generating visually similar addresses. (Bitcoin.com News)

Liquid Network hit by major exploit, Bitcoin News publishes security incident newsletter

Odaily News: According to Bitcoin News monitoring, its latest newsletter reviewed multiple security incidents over the past eight weeks involving projects that Bitcoin users rely on in their daily activities, with a focus on the latest major exploit targeting Liquid Network.

Hacker Exploits Symbiosis Bitcoin Bridge Vulnerability to Mint ~$46.1 Billion in Face Value syBTC, Cashes Out Only $336,000

Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)

SlowMist Discloses Liquid Vulnerability Details: Attacker Minted 3,998.5 L-BTC Without Collateral, Approximately 598.5 BTC Still Not Returned

SlowMist has disclosed that the Liquid Network was attacked on September 6 via a Rangeproof verification cache key collision vulnerability. The attacker minted approximately 3,998.5 L-BTC without collateral — with no corresponding BTC peg-in — and then within minutes converted them to BTC on the Bitcoin mainnet via peg-out. After the incident, approximately 3,400 BTC was returned to the Liquid Federation peg wallet, but approximately 598.5 BTC remains under the attacker's control.SlowMist noted that the root cause of the vulnerability lies in the fact that the Rangeproof verification cache key in Elements did not include length prefixes when concatenating multiple variable-length fields, allowing different parameter combinations to potentially generate the same cache key. The attacker triggered a cache collision by constructing transactions, causing nodes to hit a "verification passed" cached result, thereby bypassing secp256k1_rangeproof_verify and the minimum amount check, ultimately accepting outputs not backed by real assets and completing the L-BTC minting. SlowMist stated that it has traced the fund flows on the Bitcoin side and completed its analysis of the incident.

Blockstream Refuses to Pay Ransom, Vows to Recover Stolen Bitcoin from Liquid Network

Blockstream officially announced on the X platform that Liquid Network has suffered a Bitcoin theft incident. The company explicitly stated its refusal to pay any ransom and characterized the act as a crime rather than a white-hat disclosure. Blockstream has collaborated with law enforcement agencies, exchanges, forensic experts, and other parties to trace the stolen assets through on-chain tracking and other means. It also called on current holders to voluntarily return the Bitcoin, warning that they will face full legal action otherwise.

Liquid Network Vulnerability Disclosure Handling Sparks Public Dispute Between Samson Mow and Bitcoin Red Team

Bitcoin News posted on X stating that Samson Mow and Bitcoin Red Team researcher Calle are engaged in a public dispute over whether security warnings related to a Liquid Network exploit were properly handled. Calle claims that Blockstream did not act on the Red Team's email, ultimately resulting in a loss of 600 BTC; Mow responded by saying "no email was ignored." Calle stated that once Blockstream restores normal Liquid operations and publishes a post-mortem report, the Red Team will release a full account of the disclosure process. Mow separately warned against blindly trusting AI-generated security reports, saying that unverified fixes could introduce new vulnerabilities, and criticized researchers who prioritize pursuing "clout" over protecting Bitcoin.

Liquid Network hacker still holds 598.5 bitcoins, L-BTC-to-bitcoin redemption channel paused for 11 days

Odaily News: The Liquid Network attacker has returned 3,400 bitcoins after the September 6 exploit, accounting for approximately 85% of the transferred assets; they currently still hold 598.50 bitcoins, worth over $45 million.Blockstream, the digital asset infrastructure company responsible for maintaining the Liquid Network, has refused to pay a ransom for the remaining assets and is demanding the return of the relevant bitcoins. The network shows 4,234.76 L-BTC in circulation, while the bitcoin reserves stand at only 3,632.23.The L-BTC-to-bitcoin redemption function has still not been restored, with Sideswap stating that redemptions are currently unavailable; Blockstream founder Adam Back said that L-BTC will be backed 1:1 by bitcoin reserves and reminded holders not to sell L-BTC off-market at a discount.As of now, Blockstream has not yet issued an announcement that "redemptions are live." The attacker's wallet continues to receive on-chain messages and has been subjected to address poisoning attacks and scam messages, with the related attacks inducing transfers by generating visually similar addresses. (Bitcoin.com News)

Liquid Network hit by major exploit, Bitcoin News publishes security incident newsletter

Odaily News: According to Bitcoin News monitoring, its latest newsletter reviewed multiple security incidents over the past eight weeks involving projects that Bitcoin users rely on in their daily activities, with a focus on the latest major exploit targeting Liquid Network.

Hacker Exploits Symbiosis Bitcoin Bridge Vulnerability to Mint ~$46.1 Billion in Face Value syBTC, Cashes Out Only $336,000

Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)

SlowMist Discloses Liquid Vulnerability Details: Attacker Minted 3,998.5 L-BTC Without Collateral, Approximately 598.5 BTC Still Not Returned

SlowMist has disclosed that the Liquid Network was attacked on September 6 via a Rangeproof verification cache key collision vulnerability. The attacker minted approximately 3,998.5 L-BTC without collateral — with no corresponding BTC peg-in — and then within minutes converted them to BTC on the Bitcoin mainnet via peg-out. After the incident, approximately 3,400 BTC was returned to the Liquid Federation peg wallet, but approximately 598.5 BTC remains under the attacker's control.SlowMist noted that the root cause of the vulnerability lies in the fact that the Rangeproof verification cache key in Elements did not include length prefixes when concatenating multiple variable-length fields, allowing different parameter combinations to potentially generate the same cache key. The attacker triggered a cache collision by constructing transactions, causing nodes to hit a "verification passed" cached result, thereby bypassing secp256k1_rangeproof_verify and the minimum amount check, ultimately accepting outputs not backed by real assets and completing the L-BTC minting. SlowMist stated that it has traced the fund flows on the Bitcoin side and completed its analysis of the incident.

Liquid Network Vulnerability Disclosure Handling Sparks Public Dispute Between Samson Mow and Bitcoin Red Team

Bitcoin News posted on X stating that Samson Mow and Bitcoin Red Team researcher Calle are engaged in a public dispute over whether security warnings related to a Liquid Network exploit were properly handled. Calle claims that Blockstream did not act on the Red Team's email, ultimately resulting in a loss of 600 BTC; Mow responded by saying "no email was ignored." Calle stated that once Blockstream restores normal Liquid operations and publishes a post-mortem report, the Red Team will release a full account of the disclosure process. Mow separately warned against blindly trusting AI-generated security reports, saying that unverified fixes could introduce new vulnerabilities, and criticized researchers who prioritize pursuing "clout" over protecting Bitcoin.

Liquid Network resumes block production after a $320 million exploit

Liquid Network resumed empty block production after deploying an emergency patch, following a core software vulnerability that resulted in nearly $320 million in assets being withdrawn. Asset recovery and system stability monitoring are currently ongoing.

Related news

Liquid Network hacker still holds 598.5 bitcoins, L-BTC-to-bitcoin redemption channel paused for 11 days

Odaily News: The Liquid Network attacker has returned 3,400 bitcoins after the September 6 exploit, accounting for approximately 85% of the transferred assets; they currently still hold 598.50 bitcoins, worth over $45 million.Blockstream, the digital asset infrastructure company responsible for maintaining the Liquid Network, has refused to pay a ransom for the remaining assets and is demanding the return of the relevant bitcoins. The network shows 4,234.76 L-BTC in circulation, while the bitcoin reserves stand at only 3,632.23.The L-BTC-to-bitcoin redemption function has still not been restored, with Sideswap stating that redemptions are currently unavailable; Blockstream founder Adam Back said that L-BTC will be backed 1:1 by bitcoin reserves and reminded holders not to sell L-BTC off-market at a discount.As of now, Blockstream has not yet issued an announcement that "redemptions are live." The attacker's wallet continues to receive on-chain messages and has been subjected to address poisoning attacks and scam messages, with the related attacks inducing transfers by generating visually similar addresses. (Bitcoin.com News)

Liquid Network hit by major exploit, Bitcoin News publishes security incident newsletter

Odaily News: According to Bitcoin News monitoring, its latest newsletter reviewed multiple security incidents over the past eight weeks involving projects that Bitcoin users rely on in their daily activities, with a focus on the latest major exploit targeting Liquid Network.

Hacker Exploits Symbiosis Bitcoin Bridge Vulnerability to Mint ~$46.1 Billion in Face Value syBTC, Cashes Out Only $336,000

Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)

SlowMist Discloses Liquid Vulnerability Details: Attacker Minted 3,998.5 L-BTC Without Collateral, Approximately 598.5 BTC Still Not Returned

SlowMist has disclosed that the Liquid Network was attacked on September 6 via a Rangeproof verification cache key collision vulnerability. The attacker minted approximately 3,998.5 L-BTC without collateral — with no corresponding BTC peg-in — and then within minutes converted them to BTC on the Bitcoin mainnet via peg-out. After the incident, approximately 3,400 BTC was returned to the Liquid Federation peg wallet, but approximately 598.5 BTC remains under the attacker's control.SlowMist noted that the root cause of the vulnerability lies in the fact that the Rangeproof verification cache key in Elements did not include length prefixes when concatenating multiple variable-length fields, allowing different parameter combinations to potentially generate the same cache key. The attacker triggered a cache collision by constructing transactions, causing nodes to hit a "verification passed" cached result, thereby bypassing secp256k1_rangeproof_verify and the minimum amount check, ultimately accepting outputs not backed by real assets and completing the L-BTC minting. SlowMist stated that it has traced the fund flows on the Bitcoin side and completed its analysis of the incident.

Blockstream Refuses to Pay Ransom, Vows to Recover Stolen Bitcoin from Liquid Network

Blockstream officially announced on the X platform that Liquid Network has suffered a Bitcoin theft incident. The company explicitly stated its refusal to pay any ransom and characterized the act as a crime rather than a white-hat disclosure. Blockstream has collaborated with law enforcement agencies, exchanges, forensic experts, and other parties to trace the stolen assets through on-chain tracking and other means. It also called on current holders to voluntarily return the Bitcoin, warning that they will face full legal action otherwise.

Liquid Network Vulnerability Disclosure Handling Sparks Public Dispute Between Samson Mow and Bitcoin Red Team

Bitcoin News posted on X stating that Samson Mow and Bitcoin Red Team researcher Calle are engaged in a public dispute over whether security warnings related to a Liquid Network exploit were properly handled. Calle claims that Blockstream did not act on the Red Team's email, ultimately resulting in a loss of 600 BTC; Mow responded by saying "no email was ignored." Calle stated that once Blockstream restores normal Liquid operations and publishes a post-mortem report, the Red Team will release a full account of the disclosure process. Mow separately warned against blindly trusting AI-generated security reports, saying that unverified fixes could introduce new vulnerabilities, and criticized researchers who prioritize pursuing "clout" over protecting Bitcoin.