Overview
- A validation bug in Elements’ range-proof verification cache let nodes accept minted, unbacked L-BTC and triggered a withdrawal that removed roughly 3,996–4,000 BTC from the federation wallet.
- SideSwap says the bug was in Elements but admitted two operational choices — keeping a peg-out authorization key online and allowing automatic same-block payouts with no size or origin checks — that converted the software fault into a Bitcoin loss.
- After emergency fixes in Elements v23.3.4 and node updates, the attackers transferred about 3,400 BTC back to the federation while about 598.5 BTC remains in the attack-linked address.
- Liquid resumed block production without adding transactions so operators can monitor stability, peg-ins and peg-outs remain suspended, and the network has warned users to ignore scam recovery offers.
- The incident highlights a systemic risk in federated custody models because a validation failure, not stolen multisig keys, allowed sidechain tokens to be treated as real assets and will likely trigger deeper audits and procedural changes.