• Sources: Elements commit c26d719, HN discussion
  • Summary: The Elements commit c26d719, titled as a fix binding the range proof cache to asset and scriptpubkey, was authored by delta1. That commit is the only part of this story confirmed against a primary source, and the Elements releases that carry the range proof cache bug are not yet known. The reported theft from the Liquid Federation wallet, the sidechain pause, and the on-chain OP_RETURN negotiation could not be checked against any primary source from this run.
  • Comments: HN commenters, including the account nullc, who states he wrote the original range proofs at Blockstream, argue the fix introduced an undelimited hash field collision worse than the cache bug it closed. The roughly 4,000 BTC figure and the sidechain pause rest on that thread alone. The submission points at a Liquid_BTC post on X that was not readable, because X is unreachable and xcancel.com serves a browser verification challenge, and mempool.space transaction pages render empty.
  • Why it matters: If the thread is right, a security fix that shipped as an ordinary public commit introduced a worse bug than the one it closed, which is the failure mode any project that patches in the open has to plan for.
  • Follow-up: A Blockstream or Liquid Federation statement, the amount and the sidechain status confirmed on chain, and whether a second fix lands for the collision the thread describes.

send feedback on this story