Liquid Federation has just been hacked. The attackers exploited an Elements cache vulnerability to mint roughly 4,000 unsupported L-BTC, then exited the side swap channel and swapped them for real BTC. Liquid’s original BTC reserves of 4,205 have been drained down to just 197. White hats have already returned 3,400, but nearly 600 BTC are still unaccounted for and falling off the radar.

This is a protocol-layer vulnerability, not a private-key leak. Blockstream has been pushing Elements as a Bitcoin sidechain security solution, yet the cached data used for range proof verification can be bypassed. Consensus security for $BTC is fine, but every project that relies on BTC as a bridge must re-examine its security model. And to make matters worse, today Iran carried out a second attack on U.S. Navy vessels within two days. Brent crude surged to $97.69—geopolitical risk layered on top of a protocol-level black-swan event means market risk-aversion sentiment isn’t baseless. So who exactly holds those 598.5 BTC, and do you think they’ll be returned?