SlowMist said Liquid Network was attacked on September 6 through a Rangeproof verification cache key collision vulnerability. The attacker minted about 3,998.5 L-BTC without a corresponding BTC peg-in and converted it to Bitcoin mainnet BTC through peg-out within minutes. According to Odaily, about 3,400 BTC has been returned to Liquid's federated peg wallet, while roughly 598.5 BTC remains under the attacker's control.
SlowMist said the flaw stemmed from Elements' Rangeproof verification cache key, which did not add length prefixes when concatenating multiple variable-length fields, allowing different parameter combinations to produce the same cache key. By constructing transactions that triggered the cache collision, the attacker caused nodes to hit a cached verification result marked as passed, bypassing secp256k1_rangeproof_verify and the minimum amount check. SlowMist said it tracked the Bitcoin-side funds and completed its analysis of the incident.