Odaily Planet Daily report: According to the security incident report released by the Liquid Network official, on September 6, a vulnerability in the open-source software Elements related to the range proof verification method for Liquid node caching was exploited, resulting in the creation of approximately 4,000 LBTC without corresponding Bitcoin reserves. The attacker subsequently exchanged these tokens for approximately 4,000 BTC via SideSwap and the Liquid standard peg-out mechanism. Prior to the incident, Liquid’s reserves stood at around 4,205 BTC; after the affected peg-outs and other withdrawals were completed before the network was halted, reserves dropped to as low as 197 BTC.
The Liquid Network stated that the incident did not involve any compromise of Functionary nodes or private keys, and other assets issued on Liquid, such as USDT, were not affected by the vulnerability. The attacker, who identified themselves as a white-hat security researcher, returned 3,400 BTC to the Liquid Federation Peg wallet on September 7. Approximately 598.5 BTC (about 15% of the involved funds) remains unreturned, and Blockstream is currently in communication with the individual to recover the remaining assets.
The Liquid Network also stated that the current priority is to recover the remaining funds and restore normal operations on the Liquid Network as quickly and securely as possible. A fix for the vulnerability has been developed and is currently undergoing multiple rounds of internal and external review. Blockstream is preparing to urgently release Elements v23.3.4, which is expected to be published as soon as preparations are complete, with a planned rollout within approximately 48 hours. After the software update, Liquid Network Functionary operators will perform additional adjustments to restore the network’s full functionality and return it to a corrected state, including rejecting previously invalid peg-outs.

