The report assesses a security incident involving the Liquid Network that occurred on September 6, 2026. An attacker exploited a vulnerability in Elements' rangeproof verification cache, enabling a transaction to pass validation without proper backing. This led to an inflation of the LBTC supply by approximately 4,000 LBTC, resulting in a withdrawal of around 4,000 BTC. The attacker returned 3,400 BTC after negotiations, leaving approximately 602 BTC outstanding.
Blockstream coordinated a halt of the Liquid bridge nodes shortly after the attack and deployed an emergency patch. The report outlines the incident timeline, vulnerability analysis, and corrective actions taken. It details the architecture of Liquid, emphasizing the importance of consensus validation and the role of Peg-out Authorization Keys (PAK).
Two main issues enabled the attack: vulnerabilities in Elements and a gap in the PAK signing process. Bug A, identified in 2018, allowed a node to reuse cached results incorrectly, leading to consensus mismatches. Bug B involved a defect in how fields were combined in the cache key, which was not identified during reviews. The report emphasizes the importance of ongoing security reviews and the integration of AI-assisted analysis tools in future assessments.