The keys worked. The signatures were valid. So what actually failed in the ~4,000 BTC Liquid incident?
I've spent the week trying to understand the Liquid incident beyond the "$320M hack" headline.
The part I find most interesting is that this apparently wasn't a federation key compromise.
The federation keys weren't reported stolen. SideSwap says its PAK wasn't compromised. Yet roughly 4,000 unbacked L-BTC were created and eventually resulted in real BTC leaving the federation wallet through a valid peg-out path.
That changes the security question completely.
A multisig can protect against unauthorized signing.
But what happens when authorized signers are operating on state that the software incorrectly considers valid?
I dug into the Elements 23.3.4 changes, range-proof verification caching, SideSwap's role in the peg-out, the federation model and the distinction between Bitcoin consensus and Liquid's additional assumptions.
I also tried to separate what Liquid has officially confirmed from what independent researchers have reconstructed so far.
Full analysis:
Bitcoin Didn't Break. Everything Around It Keeps Reminding Us Why Bitcoin Exists
I'm particularly interested in technical criticism of the analysis.
If you've been following the Elements commits or have a better understanding of the cache failure, I'd like to hear it.
[link] [comments]