Researchers examining the roughly $320 million Liquid Network incident are testing an explanation involving a flaw in transaction validation that may have allowed allegedly bug-created L-BTC to be redeemed for real Bitcoin. The incident began when a SideSwap customer submitted 4,000 L-BTC on Sept. 6, leading to the release of approximately 3,996 BTC. A transaction reconstruction cited by Stu reportedly showed approximately 3,996.0183 L-BTC created in Liquid block 4,050,336 before the withdrawal.
Why it matters
The proposed mechanism centers on Liquid’s confidential transactions and range proofs, which are designed to verify that hidden amounts remain within permitted limits without revealing them. Researcher Calle described a cache-key collision that could let an invalid proof reuse a successful verification result. Charles Guillemet endorsed the broad explanation, although Calle cautioned that his simplified account could contain errors.
The software trail may be as important as the alleged bug. Mononaut said the code had entered Elements’ master development branch the previous week but had not appeared in a tagged release, while Liquid federation functionaries apparently ran it. Other nodes reportedly rejected the affected transactions or block. Blockstream has not confirmed that deployment account in the available statements, making the postmortem important for identifying the affected versions and failure path.
Market impact
The immediate issue is Bitcoin reserves versus L-BTC liabilities. Liquid says federation signing keys were not compromised, and the actors holding the withdrawn Bitcoin have described themselves as whitehats while conditioning most returns on a fix across affected nodes. No completed return or patch rollout has been established. Investors will be watching for a reproducible postmortem, software updates across federation and non-federation nodes, and evidence that the corrected validation process rejects the invalid transaction.
Frequently asked questions
-
How could allegedly unbacked L-BTC be used to withdraw real BTC?
Researchers say a cache-key collision may have bypassed a range-proof check, allowing a hidden invalid output. Those L-BTC then reportedly entered a 4,000 L-BTC peg-out request that released approximately 3,996 BTC.
-
What is the role of range proofs in Liquid transactions?
Range proofs let nodes verify that confidential transaction amounts fall within allowed limits without revealing the amounts. A failure in that check could allow a negative hidden output to offset a larger positive output.
-
Did the transaction-validation bug enter a released Liquid version?
Mononaut said the code entered Elements’ master development branch but never appeared in a tagged release, while federation functionaries apparently ran it. Blockstream has not confirmed that deployment account.
-
Were Liquid federation signing keys compromised?
Liquid said neither SideSwap’s peg-out authorization key nor other federation keys had been compromised. The emerging accounts instead focus on how invalid L-BTC reached the withdrawal process.
-
What is needed to resolve the $320M Liquid incident?
Investigators need a postmortem identifying the affected code, why federation nodes accepted the transactions, and whether corrected software rejects them. Recovery of the withdrawn Bitcoin would also address the reported reserve shortfall.
CryptoSlate