95% of Reserves Gone in 23 Minutes
The exploit targeted a software bug in Elements, the open-source codebase underlying Liquid. Preliminary analysis suggests the vulnerability enabled the unauthorized minting of L-BTC, which then passed through SideSwap’s peg-out service as though it were legitimate. SideSwap’s authorization system could not distinguish between real and exploit-created coins, and Liquid’s federation of 15 rotating signers approved the withdrawal through its standard 11-of-15 multisig threshold. Bitcoin’s base layer was never compromised. BTC price held steady around $80,000 throughout the incident.