News linked to both this project and an event.
Odaily News: Liquid Network announced that the emergency release Elements v23.3.4 is now live, with Functionary nodes having immediately begun upgrades. All Liquid node operators are advised to update accordingly. This release addresses a previously identified Proof validation cache vulnerability by strengthening the cache keys used for Range Proofs.Regarding network recovery, Blockstream stated that a recovery plan is still being formulated, expected to proceed in three phases: **resume block production while continuing to pause Peg operations; replay verified valid transactions; restore Peg operations after the network state is fully recovered and fund returns are confirmed.** Currently, the first two phases are being tested in parallel, and any phase will only advance once confirmed secure.Liquid Network stated that Elements v23.3.4 has undergone multiple rounds of internal and external reviews, with participants including the Bitcoin Red Team, Alpen Labs, and other teams. Meanwhile, Liquid Network reminds users to be wary of fake upgrade websites exploiting this incident for scams. Information should only be obtained through official Liquid Network and Blockstream channels, and users should never send funds to strangers or disclose private keys or seed phrases.
According to BlockSec Phalcon, the HandlerV1 contract managed by Hyperbridge on the Ethereum network was found to contain a Merkle Mountain Range (MMR) proof replay vulnerability, resulting in approximately $242,000 in losses. The vulnerability stems from the lack of binding between proofs and requests, enabling attackers to replay historical valid proofs alongside newly forged requests to perform malicious actions—such as altering administrator privileges. In the specific incident, the attacker changed the Polkadot (DOT) token administrator and then exploited those privileges to mint additional DOT tokens for profit. Observed attack transactions include: changing the DOT token administrator and minting new tokens (losses of ~$237,400), changing the ARGN token administrator and minting new tokens (losses of ~$3,800), and host withdrawal operations. The vulnerability was discovered by PhalconSecurity and analyzed via PhalconExplorer. Previously, the Hyperbridge gateway contract was attacked, leading to the unauthorized minting and subsequent dumping of 1 billion DOT tokens on Ethereum.