Crypto news report · source clearly identified

Alpen Labs AI Reproduces Liquid’s $320M BTC Exploit in One Hour

Alpen Labs’ AI agents traced the cache flaw that let Liquid’s sidechain release roughly 3,996 BTC on September 6, 2026, and reproduced the exploit locally in about an hour.

On September 6, 2026, the Liquid federation released roughly 3,996 BTC after its sidechain accepted L‑BTC that lacked Bitcoin backing. A validly authorized withdrawal turned an invalid sidechain state into a real Bitcoin payment worth about $320 million.

Technical cause of the exploit

The Elements software that powers Liquid caches successful cryptographic proof checks. A code change on September 1 attempted to make each cache entry depend on all verification context, but concatenated fields as raw bytes without encoding their boundaries. This allowed a valid “seed” proof and an invalid target to produce identical cache inputs. When the cache returned a hit, the proof check was bypassed, letting the invalid L‑BTC be accepted.

Alpen Labs’ investigation

Alpen Labs CEO Simanta Gautam says AI agents began analyzing the attack after hearing about it and, within an hour, reproduced the flaw in a local environment. The replay showed fresh verification rejecting the target while the cached wrapper accepted it, confirming the cache‑collision hypothesis. Production validator binaries and historic cache contents were not available, so the analysis relied on source code and chain evidence.

SideSwap’s role in the payout

According to SideSwap, the attacker sent a 4,000 L‑BTC peg‑out request at 14:05 UTC on September 6. The service burned the tokens with valid authorization at 14:06, but the order exceeded its wallet funds, causing two payout attempts to fail. The federation then signed an exceptional request and released 3,996 BTC at 14:28, which SideSwap forwarded in the same Bitcoin block.

Potential safeguards

  • A payout limit or other independent hold applied before federation signing could have stopped the large payout even after the invalid L‑BTC was accepted.
  • An offline authorization key or manual review would have introduced a pause before the peg‑out was approved.
  • Elements updates on September 8‑9 changed cache key handling, added collision tests, and introduced an option to bypass the range‑proof cache, addressing the validation gate.

Current status

Liquid announced on September 17 that ordinary transactions had resumed while peg‑outs remained paused. Withdrawals will restart only after full one‑to‑one BTC backing is confirmed and software updates, testing, and independent reviews are completed.

Source & attribution

News Source

Publisher
CryptoSlate
Original date
September 24, 2026, 12:20 PM
Original headline
Alpen says AI identified Liquid’s $320M BTC exploit in an hour. Could a payout limit have stopped it?
View original report ↗