
Liquid Network Drained of $320M Through Cache Bug Allowing Unbacked Token Minting
An unknown attacker exploited a range-proof cache bug in the Elements codebase to mint unbacked L-BTC on the Liquid sidechain, draining approximately $320 million from the federation reserve. The network remains frozen while the attacker negotiates the return of drained funds via on-chain messages.
Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work
The Bug and the Drain
Researchers examining the Liquid Network incident have identified a transaction-validation cache failure in the Elements software as the likely vector for the $320 million loss. The bug allowed an unknown actor to mint unbacked L-BTC tokens, which were then exchanged for real Bitcoin through the SideSwap exchange. According to reports, approximately 95% of the federation reserve was drained through this method. The network has remained frozen since the exploit.
Timeline and Code History
The exploited bug had entered the Elements master development branch in the week prior to the attack, according to researcher Mononaut, raising questions about the deployment pipeline and code review practices. The specific failure involved the software's range-proof cache, a component responsible for validating whether transaction proofs meet cryptographic requirements. The presence of this vulnerability in the main codebase prior to its deployment on Liquid suggests a gap between development and production safeguards.
Ongoing Negotiations
The attacker has used on-chain OP_RETURN messages to negotiate the return of the drained funds, indicating some level of dialogue with the Liquid team or federation members. As of the latest reports, 598.5 BTC remains in the attacker's control pending resolution. The network remains non-operational while these discussions continue.
Why It Matters
For Traders
Liquid's frozen state and ongoing negotiations create near-term liquidity uncertainty for L-BTC holders; positions on the sidechain remain locked.
For Investors
The bug reveals a critical gap between Elements development and production deployment; it raises questions about the governance and review processes protecting Bitcoin-backed Layer 2 systems.
For Builders
Any protocol relying on Elements codebase should audit their cache validation logic and deployment procedures to prevent similar unbacked token minting vulnerabilities.
This article is for information only and is not financial advice. Read the full disclaimer.






