GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Marketing/Whale

News linked to both this project and an event.

SlowMist Discloses Liquid Vulnerability Details: Attacker Minted 3,998.5 L-BTC Without Collateral, Approximately 598.5 BTC Still Not Returned

SlowMist has disclosed that the Liquid Network was attacked on September 6 via a Rangeproof verification cache key collision vulnerability. The attacker minted approximately 3,998.5 L-BTC without collateral — with no corresponding BTC peg-in — and then within minutes converted them to BTC on the Bitcoin mainnet via peg-out. After the incident, approximately 3,400 BTC was returned to the Liquid Federation peg wallet, but approximately 598.5 BTC remains under the attacker's control.SlowMist noted that the root cause of the vulnerability lies in the fact that the Rangeproof verification cache key in Elements did not include length prefixes when concatenating multiple variable-length fields, allowing different parameter combinations to potentially generate the same cache key. The attacker triggered a cache collision by constructing transactions, causing nodes to hit a "verification passed" cached result, thereby bypassing secp256k1_rangeproof_verify and the minimum amount check, ultimately accepting outputs not backed by real assets and completing the L-BTC minting. SlowMist stated that it has traced the fund flows on the Bitcoin side and completed its analysis of the incident.

Liquid Network white hat hacker returns 3,400 BTC, keeps about 598 BTC as bounty

According to on-chain monitoring by analyst PeckShield (@PeckShieldAlert), the Liquid Network was targeted by white-hat hackers. Approximately 4,000 BTC (roughly $320 million) were transferred from a Liquid Federation wallet. The funds were consolidated into address bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte, accompanied by an on-chain message: "We are white hats, please contact us on-chain." Subsequently, the hackers completed on-chain negotiations with Blockstream, returning 3,400 BTC (approximately $315 million, or 85% of the total) while retaining around 598.5 BTC (about $47.38 million) as a bug bounty.