Overview
- The exploit on Sunday, Sept. 6 let attackers mint unbacked L-BTC by abusing a cache key flaw in Elements’ range-proof verification, which allowed about 3,996 BTC to be withdrawn from Liquid’s federation reserve.
- Operators patched nodes and, after Blockstream confirmed the fixes, the actors returned roughly 3,400 BTC but kept about 598–598.5 BTC in addresses they control.
- Liquid released Elements v23.3.4 to harden proof-verification cache keys, and functionary nodes have resumed producing blocks while transactions and peg-out services remain suspended for further checks.
- The actors publicly demanded a 10% bounty and used on-chain OP_RETURN and PGP-signed messages to negotiate, a move Blockstream called theft and refused to treat as responsible disclosure.
- Blockstream said it will not pay the demanded bounty and will work with exchanges, forensic firms and law enforcement to trace and seek recovery of the remaining coins, a stance that frames future responses to similar exploits.