Wu said he learned from SlowMist that SlowMist disclosed that Liquid Network was hit on September 6 by a Rangeproof verification cache-key collision vulnerability attack. The attacker, without any corresponding BTC inflow (peg-in), minted about 3,998.5 L-BTC in an uncollateralized manner, and then within minutes exchanged it via peg-out for BTC on the Bitcoin mainnet. After that, about 3,400 BTC was returned to the Liquid federation-linked wallet, and roughly 598.5 BTC remains under the attacker’s control. SlowMist said the vulnerability stemmed from Elements failing to include a length prefix when concatenating multiple variable-length fields to form the Rangeproof verification cache key, allowing different parameter combinations to generate the same cache key. By crafting transactions to trigger a cache collision, the attacker caused nodes to hit the cached result marked as “verification passed,” skipping secp256k1_rangeproof_verify and the minimum-amount check. This enabled the acceptance of outputs not backed by real assets and the completion of L-BTC minting. SlowMist has tracked the flow of funds on the Bitcoin side and completed an event analysis.