Overview
- A range‑proof verification and cache flaw in Elements allowed attackers to mint unbacked L‑BTC and withdraw roughly 3,996–4,000 BTC through SideSwap, draining most of Liquid’s federation reserve.
- After nodes were patched the pseudonymous actors returned about 3,400 BTC but retained roughly 598.5 BTC in a linked address and published plaintext messages demanding a 10% bounty.
- Liquid released Elements v23.3.4 to harden cache keys used for confidential transaction proofs and functionary nodes received the update before resuming block signing.
- Block production has restarted but regular transactions and BTC peg‑out operations remain suspended while operators verify network stability and rebuild the peg reserve.
- SideSwap admitted operational choices—keeping its peg‑out key online, automatic same‑block payouts, and no size or velocity checks—helped convert the software fault into a mainchain loss, raising custody and governance concerns for federated sidechains and users who cannot currently redeem L‑BTC.