On September 6, 2026, Liquid’s federation released roughly 3,996 BTC after its network accepted L-BTC that lacked Bitcoin backing. Liquid is a Bitcoin sidechain whose L-BTC is meant to represent bitcoin held in a federation reserve. A validly authorized withdrawal turned the invalid sidechain state into a real Bitcoin payment worth about $320 million at the time. A payout limit before federation signing might have interrupted that exit.
Alpen Labs CEO Simanta Gautam now says his AI agents traced the flaw and reproduced it locally in about an hour. The work began after he heard of the September 6 attack. His September 22 account and technical report give a detailed explanation of the failed proof check. The demonstration came after the funds left, so its speed says little by itself about whether a standing AI monitor would have raised an actionable warning before the attack.
Elements, the software underlying Liquid, caches successful checks of the cryptographic proofs attached to confidential transactions. A September 1 code change tried to make each cached result depend on all the context that affects verification, including the asset generator and output script. Alpen says the change concatenated those fields as raw bytes without encoding their boundaries. A valid “seed” proof and a different, invalid target could therefore produce identical cache input.
In Alpen’s local replay, fresh verification rejected the target, while the affected cache wrapper accepted it after the seed had populated the cache. A successful cache lookup bypassed the proof check that should have rejected the target.
Source link







