Liquid bug let unbacked L‑BTC pass verification; 3,996 BTC exited via authorized peg‑out

security⚖️ Neutral$BTC

⏱ 2 min read

Alpen Labs traced a cache‑collision flaw in Elements that let an invalid proof skate past verification once the cache was primed; Elements patched days later, but federation‑level peg‑out limits remain the key missing control.


On September 6, Liquid’s federation released roughly 3,996 BTC after the network accepted L‑BTC that lacked Bitcoin backing. A validly authorized withdrawal turned the invalid sidechain state into a real Bitcoin payment—about $320 million at the time. A payout limit before federation signing might have interrupted that exit.

The mechanism

Elements, the software underlying Liquid, caches successful checks of the cryptographic proofs attached to confidential transactions. A September 1 code change attempted to make each cached result depend on all relevant context, including the asset generator and output script. According to Alpen Labs, the change concatenated those fields as raw bytes without encoding their boundaries. That made it possible for a valid “seed” proof and a different, invalid target to produce identical cache inputs.

In Alpen’s local replay, fresh verification rejected the target, while the affected cache wrapper accepted it after the seed had populated the cache. A successful cache lookup bypassed the proof check that should have rejected the target—locally reproducing the suspected consensus failure. Alpen notes that exact production validator binaries and historical cache contents were unavailable, leaving the deployed path inferred from source code and chain evidence.

$BTC
▼ 0.15%
$84,381

Deployment and fixes

SideSwap says a private security build installed on its own node in August accepted the attack transaction—narrowing the deployment question for one operator but not identifying every federation functionary’s build. On September 8, an Elements repair changed cache keys to encode field lengths, added collision‑focused tests, and introduced an option to bypass the range‑proof cache. Version 23.3.4 followed on September 9, addressing the validation gate before invalid L‑BTC can become accepted state.

The peg‑out path

Per SideSwap’s account, the attacker sent 4,000 L‑BTC to its peg‑out service at 14:05 UTC on September 6, and SideSwap burned the tokens with valid authorization at 14:06. The authorized exit required a separate check; once the sidechain had accepted the unbacked L‑BTC as valid state, a routine authorization allowed the federation to release native BTC.

Limitations

Two uncertainties remain material: which federation functionaries were running vulnerable binaries, and whether any real‑time monitoring could have produced an actionable warning. Alpen’s rapid post‑incident reproduction does not, by itself, establish that a standing AI monitor would have blocked the attack.

What to watch

Look for federation disclosures on version pinning and upgrade attestations, adoption status of Elements v23.3.4 (or cache‑bypass), and concrete peg‑out controls such as pre‑sign payout limits. Those operational measures would determine whether a similar consensus‑edge bug can again translate into an on‑chain BTC outflow.


This content is for informational purposes only and does not constitute financial advice.

🧠 HafidWatch Take

The failure stemmed from consensus-critical code combined with an unsafe cache key, allowing a valid proof to prime the cache and let an invalid request bypass verification. This led to the sidechain accepting invalid state, resulting in a 3,996 BTC main-chain payout after a routine authorization. While the code fix addresses the vulnerability, the root issue was operational: the absence of pre-sign peg-out limits to block large withdrawals during the incident. Future risk mitigation depends on the federation’s disclosure of version pinning, upgrade attestations, and implementing strict payout controls. Without greater build transparency, Liquid’s security relies more on operational coordination than cryptographic guarantees.

Daily crypto intelligence. Before the market opens.

Including the Divergence Index — the sentiment gap no other newsletter tracks. Free, every morning at 7:30am ET.

✓ Free forever  ·  ✓ No spam  ·  ✓ 50+ sources monitored

Want it faster? Join the community:

Type above and press Enter to search. Press Esc to cancel.