Researchers Identify Cache-Key Collision in Liquid Network Incident
A validation flaw in the Liquid Network's transaction-validation cache reportedly allowed unbacked L-BTC to be redeemed for approximately 3,996 BTC. Researchers suggest a cache-key collision bypassed range-proof checks, while a potential node split may explain why some systems accepted the invalid transactions.

Researchers have identified a potential failure in the software transaction-validation cache of the Liquid Network, which may have enabled the redemption of unbacked tokens for Bitcoin. The incident involved the release of approximately 3,996 BTC following the submission of 4,000 L-BTC through the SideSwap peg-out service on Sept. 6.
The technical explanation centers on how confidential transactions are verified. Liquid uses range proofs to ensure transaction amounts remain within allowed parameters without revealing the values. Because these checks are computationally intensive, nodes cache verification results. According to researchers Calle and Charles Guillemet, an attacker may have constructed an invalid output and proof that matched a cache key from a previously valid check, causing nodes to skip necessary verification.
A separate analysis by Stu identified an allegedly invalid transaction at Liquid block 4,050,336, which reportedly created approximately 3,996.0183 L-BTC. This transaction preceded the withdrawal through SideSwap. Liquid has stated that neither the SideSwap peg-out authorization key nor other federation keys were compromised.
A reported node split may account for why some systems accepted the exploit while others rejected it. Mononaut suggested that federation functionaries may have been running code from the Elements master development branch that had not yet appeared in a tagged release. While other nodes rejected the invalid transactions, those running the unreleased code reportedly accepted them and continued building blocks.
This deployment account remains unconfirmed by Blockstream. If verified, it would indicate that the software rollout is central to the incident, as valid signing credentials authorized the release of Bitcoin against L-BTC created by the alleged bug.
The actors currently holding the withdrawn Bitcoin have identified themselves as whitehats and have conditioned the return of the funds on the implementation of a fix across affected nodes. As of the current reporting, a completed return of funds or a full patch rollout has not been established.
Stay ahead
Join our Telegram Channel
Free real-time crypto news and price alerts, the moment they break.
- Breaking News
- Price Alerts
- Market Insights



