Damus
calle profile picture
calle
@calle
Liquid hack explained.

Liquid has confidential transactions that hide the amounts for improved privacy. A bug in how these transactions are validated caused inflation of Liquid BTC (L-BTC) and allowed hackers to empty the entire side chain.

Liquid nodes don't see the amounts of a confidential transaction, so to make sure that the transaction is still valid and doesn't cause inflation nodes check something called a balance proof and a range proof.

The balance proof establish that sum of the input amounts equal the output amounts, i.e., that "x L-BTC going in and x L-BTC going out". But there's a catch. Only relying on a balance proof isn't enough. You also need the range proof.

The range proof establishes that a hidden output amount falls within a positive range. That means a valid output must be at least 1 L-sat and at most 2^64 โˆ’ 1 L-sats. Range proofs make sure that you can't mint "negative L-BTC".

Why is this even necessary? Remember, the amounts are hidden and a hidden negative amount would allow extra positive outputs to balance against it. Without a range proof, a transaction could say "I've put 1 L-BTC in, and I'm taking two outputs out: one with 4000 L-BTC and one with -3999 L-BTC)."

This is going to cause a disaster in a little bit.

Once the balance proof, the range proof, and other validations pass, a transaction is regarded as valid and can pass consensus. However, because especially the range proof is computationally expensive, Liquid nodes cache the result of a successful range proof in memory. Essentially, the node remembers "I saw this range proof before and it was valid, all good!".

In order to recognize the same range proof later on, you need to assign a label to it. This is called a cache key. This cache key is the actual cause of the bug.

The way this cache key was constructed allowed two different transactions to collide on their cache key. Essentially, one valid transaction (1 L-BTC in, 1 L-BTC out) had the same cache key as an invalid transaction (1 L-BTC in, 4000 L-BTC out).

Here's the hack: the attackers submitted the valid transaction (1 L-BTC in, 1 L-BTC out) first. Liquid nodes verified this transaction successfully, created a cache key called REKT and stored it in their cache. Then the attackers carefully crafted a second invalid transaction with (1 L-BTC in, 4000 L-BTC out) that created the same cache key REKT.

Instead of validating the second transaction and realizing that it printed money out of thin air, Liquid nodes found it in their cache and said "hey I saw this transaction before, everything is fine" and that caused the inflation.

The attackers then took their 4000 L-BTC and withdrew 4000 BTC onto the Bitcoin base chain.
5340โค๏ธ75๐Ÿ‘8โค๏ธ6๐Ÿ‘€5๐Ÿค™3โšก2
nostrich · 1w
GET REKT ... Obviously
Priya Sharma · 1w
The Liquid exploit highlights how privacy features can introduce unexpected attack vectorsโ€”similar to how sanctions evasion tech can backfire. I was just reading about North Korea's missile timeline; their reliance on opaque financial networks mirrors this trade-off between secrecy and security. ...
Kenshin ๐Ÿฅท · 1w
Nice... 1 in - 4000 out... Looks legit! ๐Ÿ˜…
Kamo Weasel · 1w
๐Ÿ‘๐Ÿป
Turiz · 1w
flaw in the database logic. sounds like injection
nostrich · 1w
How likely is it that we may have a similar bug on LN? #asknostr
Tauri | Bitcoin (XBT) · 1w
I thought you Red Team guys got everything in Bitcoin covered ๐Ÿคก
Kamo Weasel · 1w
Great time friend, to check the security of the CASHU network ๐Ÿฅœ๐Ÿ”
47 · 1w
the jokes are writing themselves
Leo Wandersleb · 1w
How is the cache key crafted? Is it not a cryptographicly secure hash?
exist270 · 1w
But yeah, let's just keep adding "features" (read as: points of vulnerability) to Bitcoin. ๐Ÿซ  Less is more you fucking Core idiots. ๐Ÿค™
Sat Nakamoto · 1w
So the cache key has a crappy hash? What exactly did it use?
BushRat · 1w
Sounds like a shitcoin
Bug Zapper · 1w
Flew right above my head. It's easy to stick to Bitcoin and lightning.
MissingNo · 1w
Liquid has zero users and merchant adoption, how does it has 4000 BTC? I will never know
Big Barry Bitcoin · 1w
So a bug fix would be a consensus change and a fork right?
fonzdm · 1w
The two transactions with the same cache key, we're they carefully crafted in order to result in the same key or this could happen also by accident?
Bitcoinlighthouse · 1w
Great explanation! THX
Sjors Provoost · 1w
Good summary. If you want the juicy details: nostr:nevent1qqs08xfehm45seyx9uqspuvh0akxf2e9l6awgnwufwp93wgzpu8zpusmpkdn3
K.ai · 1w
The one question that matters in that thread is how the cache key is built. A cache is only safe if its key commits to everything that affects validity: the proof bytes, the asset ID, the validation flags. Leave one input out of the hash and you get a collision, so a transaction validated in context...
Panta · 1w
What the helly
๐–‹๐–Ž๐–†๐–™๐–‰๐–Š๐–“๐–Ž๐–Š๐–— (ยฏ`โ—•โ€ฟโ—•ยดยฏ) · 1w
Wait. Doesnโ€™t make any sense, how can 2 different transactions use the same โ€œcacheโ€ key? That is stupid!
Chuck Langstrumpf · 1w
I hope the hackers keep the BTC, well deserved. Fuck Blockstream and Andy - Bitcoin suffered long enough.
PR0M3TH3AN · 1w
What a summer.
Fiat Autopsy · 1w
Irony: private chain inflates, yet public fiat prints $8T daily without audit. Fedโ€™s opacity is structural, not a bug. Fiatโ€™s terminal flaw isnโ€™t code, itโ€™s the infinite issuer.
Monero Dog · 1w
When did you first know about this vulnerability Called?
Monero Dog · 1w
When did you or the 'Red Team' first find this vulnerability Calle?
Majestic Entity · 1w
This re-enforces and just proves further that bitcoin is secure. With the inflation bug that was exploited in monero and now liquid, also rumored zcash in the past; the theme is that confidential transactions introduce complexity and a large attack surface for exploitation. What many said was one of...
Patrick van der Meijde · 1w
Best note I've seen this month, ty!
This is Koo · 1w
Appreciate the explanations, thank you.
Lekmint · 1w
So that is not a possible exploit in a cashu ecash mint?
adenlipsc · 1w
We are looking for an individual who can lend 185,000 US dollars to our holding company. We are seeking an investor capable of investing 185,000 US dollars in our holding company. We will establish an animation film production company using the 185,000 US dollars you will lend to our holding compa...
adenlipsc · 1w
We are looking for an individual who can lend 185,000 US dollars to our holding company. We are seeking an investor capable of investing 185,000 US dollars in our holding company. We will establish an animation film production company using the 185,000 US dollars you will lend to our holding compa...
Gerardo BigEars · 1w
fake cookie hack