Màn Vũ reveals that Liquid Network has been attacked by a vulnerability; attackers minted 3998.5 l-BTC
2026-09-11 20:15:02
According to CoinMeta, it was reported that on September 6th, Liquid Network suffered from a vulnerability attack involving cache key collisions caused by rangeproof. Without the corresponding BTC transfer (to peg-in), the attacker managed to mint approximately 3998.5 l-BTC without any collateral, and then exchanged these for Bitcoin mainnet BTC through peg-out within a few minutes. Subsequently, about 3400 BTC were returned to the Liquid federated pegged wallet, while around 598.5 BTC remained under the attacker's control. SlowMist stated that the vulnerability stemmed from the fact that Elements did not add a length prefix when concatenating multiple variable-length fields in the rangeproof validation cache keys, allowing different parameter combinations to generate the same cache key. The attacker exploited this by constructing transactions that triggered cache collisions, enabling nodes to receive a "validation passed" result and bypassing the secp256k1_rangeproof_verify check as well as the minimum amount verification, thus accepting outputs not supported by actual assets and completing the minting of l-BTC. SlowMist has traced the flow of funds on the Bitcoin side and completed an analysis of the incident.
Source:X
This content is for market information only and does not constitute investment advice.
Follow CoinMeta official accounts to stay updated

Hot Articles
Refresh

Bitcoin Trading Platforms 2026: Top 3 Exchanges Compared
3h ago

Privacy Coin Sector Outlook Sept 2026: 4 Dark Horses
09-10 18:34

S&P 500 Top 5 Companies: The Leaders Explained at a Glance
09-09 17:57

2026 Crypto Prediction Market: Is Polymarket the Leader or Being Surpassed?
09-08 18:26

SOL Price Prediction September: Can It Break $150?
09-07 17:10



