Liquid Network Bug Let Attacker Mint Fake Bitcoin Without a Single Stolen Key
Security firm SlowMist has revealed the root cause of a September 6 incident on the Liquid Network, a Bitcoin sidechain, that resulted in roughly 3,998.5 L-BTC being created out of thin air with no matching Bitcoin deposit. The problem traced back to a performance shortcut in Blockstream's Elements code, where a caching system meant to speed up cryptographic checks accidentally let two different, specially crafted transactions share the same cache key. When that happened, nodes skipped proper verification and treated fabricated value as legitimate.
Notably, the attacker did not need to steal any private keys or compromise the network's peg-out authorisation system. Instead, they built a sequence of transactions designed to trigger the cache collision, then quickly consolidated and redeemed the counterfeit L-BTC for real Bitcoin through Liquid's federated peg-out process. The underlying flaw dated back to a 2016 design decision and had persisted even through an August patch that failed to fully close the gap.
Blockstream released Elements version 23.3.4 on September 8 to fix the issue, adding stronger safeguards and an option to disable the vulnerable caching feature entirely. Liquid Network operators restarted block production on September 10 in a controlled manner, initially blocking user transactions while federation members updated their systems before normal service resumed.
Key Takeaway: Businesses using blockchain or sidechain infrastructure should ensure all node software is kept current, since even long-standing, seemingly minor performance optimisations can hide serious security flaws.