Alleged Cache Flaw May Explain $320M Loss from Liquid Network

iconNS3
Share
AI summary iconSummary
Network activity on Liquid spiked after researchers uncovered an alleged flaw in the transaction-validation cache, potentially explaining the $320M Bitcoin outflow. On Sept. 6, a customer sent 4,000 L-BTC through SideSwap’s peg-out service, with nearly 3,996 BTC released. The flaw involved range proofs, allowing attackers to craft invalid outputs that matched valid cache keys, bypassing checks. Charles Guillemet confirmed a cache-key collision let the transaction skip verification. Stu linked the exploit to a pre-transaction setup in block 4,050,336. The vulnerability entered Elements’ development branch but hadn’t been officially released. Nodes varied in responses, with some rejecting the exploit. Whitehats reportedly withdrew funds and demanded a network-wide fix. No official patch or fund return has been confirmed. Network metrics showed a sharp drop in validation efficiency post-incident.

Researchers identified an alleged failure in Liquid's transaction-validation cache that may explain how roughly $320 million in Bitcoin left the network. Liquid's L-BTC tokens are intended to be backed one-for-one by BTC held by its federation. SideSwap said a customer submitted 4,000 L-BTC through its peg-out service on Sept. 6. The service released approximately 3,996 BTC. Liquid said no SideSwap peg-out authorization key or other federation key had been compromised. Calle described a flaw involving range proofs. Range proofs let nodes verify that hidden transaction amounts fall within an allowed range. A hidden negative output could otherwise offset a larger positive output. Nodes cache successful range-proof checks because verification is computationally expensive. According to Calle, an attacker could create an invalid output and proof that matched a cache key from a valid check. A node using that cached result would skip the verification that should have rejected the output. Charles Guillemet endorsed the explanation. Guillemet described a crafted cache-key collision that allowed an invalid confidential transaction to bypass a range check. Calle cautioned that his account simplified the mechanism and could contain errors. Stu's separate transaction reconstruction identified setup transactions before an allegedly invalid transaction at Liquid block 4,050,336. Stu said the transaction created approximately 3,996.0183 L-BTC before the withdrawal through SideSwap. Mononaut said the exploited bug entered Elements' master development branch the previous week. Mononaut said the bug had not appeared in a tagged release. Mononaut said Liquid's federation functionaries apparently ran that code. Other nodes rejected the invalid transactions. Mononaut said federation functionaries accepted the exploit transactions. Mononaut said the functionaries approved withdrawals. Mononaut said the functionaries continued building blocks. Other nodes, including nodes powering Liquid's mempool explorer, rejected the affected block. The node split could explain why that explorer omitted transactions visible elsewhere. Blockstream had not confirmed the deployment account in the available statements. If established, the account would place the software rollout at the center of the incident. The actors controlling the withdrawn Bitcoin described themselves as whitehats. They conditioned the return of most funds on fixing the bug across affected nodes. The available reporting did not establish a completed return or patch rollout.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.