Almost 4,000 BTC were drained from Liquid.
And the craziest part? The vulnerability appears to have been introduced while fixing another vulnerability. 🧡
Here's what happened, without the cryptography PhD.
Liquid allows transaction amounts to remain private.
But if amounts are hidden, nodes still need to prove nobody is secretly creating money. That's what range proofs help prevent.
Think:
1 BTC in → 1 BTC out versus... 1 BTC in → +4,000 BTC and −3,999 BTC out.
Both mathematically balance.
But the second one effectively creates thousands of BTC from nothing.
Now comes the bug.
Checking these proofs is expensive, so Liquid caches successful checks.
Basically: "I've already checked this. It's valid."
Attackers reportedly managed to create two different transactions with the same cache key.
First, they submitted a legitimate proof.
Liquid checked it and cached: VALID.
Then they crafted an invalid transaction that produced the same cache key.
Instead of checking again, vulnerable nodes essentially said: "Already checked this one." They hadn't.
And suddenly, fake L-BTC could be created and exchanged for real BTC from Liquid's reserves.
Brutal.
But here's the important distinction: Bitcoin wasn't hacked. The infrastructure built around Bitcoin was.
And this comes shortly after the Coldcard vulnerability we discussed recently.
Different systems. Different bugs.
Same reminder: The base protocol can be incredibly robust while wallets, sidechains, bridges, keys and everything built around it remain attack surfaces.
And there's another lesson here.
Some will respond: “See? Stop experimenting.” We'd argue almost the opposite.
Bitcoin needs more brilliant developers building, competing, testing and trying to break assumptions.
Because the answer to bad engineering isn't less engineering. It's better engineering.
Security isn't the absence of innovation. It's what happens when innovation survives adversarial reality. 🧡