吴说区块链|9月 11, 2026 12:19
Wu Blockchain has learned that SlowMist disclosed an attack on Liquid Network on September 6 due to a Rangeproof verification cache key collision vulnerability. The attacker minted approximately 3,998.5 L-BTC without the corresponding BTC peg-in, and within minutes exchanged it for Bitcoin mainnet BTC via peg-out. Subsequently, about 3,400 BTC were returned to Liquid's federated peg wallet, while approximately 598.5 BTC remain under the attacker's control.
SlowMist stated that the vulnerability originated from Elements' Rangeproof verification cache key, which failed to include a length prefix when concatenating multiple variable-length fields. This allowed different parameter combinations to generate identical cache keys. The attacker constructed transactions to trigger cache collisions, causing nodes to hit the "verified" cache result and skip `secp256k1_rangeproof_verify` and minimum amount checks. This enabled the acceptance of outputs not backed by real assets, completing the L-BTC minting process. SlowMist has tracked the Bitcoin-side fund flow and completed the incident analysis.
https://www.(wublock123.com)/news/news-68257
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink