Liquid Federation said an attacker exploited a cache vulnerability in Elements range proof verification to mint about 4,000 unbacked L-BTC and then redeemed them for real BTC through SideSwap's authorized exit peg path. According to Odaily, the federation treated the related transactions as valid and released about 4,000 BTC from its reserves.
Before the incident, Liquid held about 4,205 BTC, and reserves fell to a low of 197 BTC before operations were suspended. The self-described white hat attacker has since returned 3,400 BTC, while about 598.5 BTC remain unreturned. No private keys were exposed, and the exit peg mechanism operated as designed. Liquid remains offline, and Blockstream is preparing an emergency release of Elements v23.3.4 while working to restore the network with 1:1 Bitcoin reserve backing.