Cache Bug in Blockstream's Elements Software Leads to $320M Bitcoin Sidechain Hack
Security firm SlowMist has published an analysis of a major exploit against Blockstream's Liquid Network, a Bitcoin sidechain, that resulted in the loss of roughly $320 million in Bitcoin. The attacker minted approximately 3,998.5 L-BTC without any backing and quickly converted them into real Bitcoin, draining the Liquid Federation's reserve wallet from over 4,200 BTC to about 197 BTC.
The root cause was a cache key collision bug in the Elements software's range-proof verification process. Range proofs are used to confirm that transaction amounts are valid without revealing their exact figures, a core part of Liquid's confidential transaction system. Because the software's cache keys were generated without proper length prefixes prior to version v23.3.4, two different inputs could produce the same cache key, tricking the system into treating an invalid proof as already verified. This allowed the attacker to mint tokens with no real Bitcoin backing and cash them out before the issue was caught.
Blockstream responded by suspending peg operations and pausing block production on the network until September 10, when a patched version of the software was deployed. The company confirmed the incident stemmed from a software flaw rather than any compromise of the federation's signing keys.