Analysis of the Liquid Network Cache Key Collision Vulnerability: Nearly 4,000 L-BTC Minted Out of…
Analysis of the Liquid Network Cache Key Collision Vulnerability: Nearly 4,000 L-BTC Minted Out of Thin Air
On the Bitcoin mainnet, roughly 3,998.5 BTC in peg-out funds finally flowed into the deal with bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte. MistTrack assigned the deal with a danger rating of 100/100, with a ranking of Severe. Its labels embrace Malicious Address / Involved Theft Activity, and it has a direct one-hop connection to a bootleg exercise entity categorized as Theft, with a 100% affiliation.
From the perspective of the supply of funds, the BTC obtained by this deal with didn’t correspond to any professional underlying principal. Its supply will be traced again to the aforementioned L-BTC minting and subsequent peg-out, with the attacker’s precise value consisting primarily of the related transaction charges.
The funds had been then break up into two elements. Of these, 3,400 BTC was transferred to the federation’s peg pockets bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr the following day. Verification via MistTrack’s transaction investigation confirmed that this deal with was additionally the largest recipient by quantity amongst the outgoing transfers from bc1ql4mfu…, receiving 3,400 BTC, per the on-chain information.
The remaining roughly 598.5 BTC remained below the attacker’s management. From September 8 to 10, these funds had been repeatedly self-transferred between Bitcoin blocks 966,052 and 966,199, with the attacker publicly negotiating with the federation via OP_RETURN messages. One of the messages learn, “You SHALL pay 10% utilizing your personal cash as bug bounty,” and included the Telegram account @MRBOND_1. The negotiations can nonetheless be noticed on-chain.
Based on the on-chain information presently accessible, the attacker returned 3,400 BTC out of the roughly 3,998.5 BTC in peg-out funds, whereas the remaining roughly 598.5 BTC stays below the attacker’s management, accounting for about 15% of the whole peg-out quantity. We will proceed to watch the related addresses and fund actions.
Conclusion
This code had been sitting in the repository for ten years, run numerous instances by numerous nodes. It was patched as soon as on August 3, but the assault nonetheless occurred on September 6. The first patch added the lacking fields to the hash however ignored subject boundaries; 5 weeks later, these boundaries had been exactly exploited. Elements 23.3.4, launched on September 8, not solely added size prefixes to the key, but additionally launched the -norangeproofcache emergency cease change, permitting operators to forestall any cached outcomes from being accepted and instantly disable this cache.
The lesson from this incident will be acknowledged very briefly. For positive-result caches in cryptographic verification paths, the place a cache hit means skipping verification, the key have to be handled based on the requirements of the cryptographic primitive itself. Every subject learn by the verification perform, together with the boundary of each subject, have to be unambiguously included into the hash. Length prefixes exist exactly for this goal. Performance optimizations resembling caching, memoization, and parallelization ought to obtain the similar stage of scrutiny throughout audits as the cryptographic primitives they optimize every time they lie on the verification path.
The SlowMist safety workforce recommends that tasks conduct a complete exterior safety audit earlier than deployment. In consensus-layer audit checklists, the integrity of verification cache keys ought to be listed as a compulsory merchandise for evaluate.
About SlowMist
SlowMist is a risk intelligence agency centered on blockchain safety, established in January 2018. The agency was began by a workforce with over ten years of community safety expertise to turn out to be a worldwide pressure. Our purpose is to make the blockchain ecosystem as safe as attainable for everybody. We are actually a famend worldwide blockchain safety agency that has labored on varied well-known tasks resembling HashKey Exchange, OSL, MEEX, BGE, BTCBOX, Bitget, BHEX.SG, OKX, Binance, HTX, Amber Group, Crypto.com, and many others.
SlowMist presents a range of companies that embrace however aren’t restricted to safety audits, risk data, protection deployment, safety consultants, and different security-related companies. We additionally provide AML (Anti-money laundering) software program, MistEye (Security Monitoring), SlowMist Hacked (Crypto hack archives), FireWall.x (Smart contract firewall) and different SaaS merchandise. We have partnerships with home and worldwide corporations resembling Akamai, BitDefender, RC², TianJi Partners, IPIP, and many others. Our in depth work in cryptocurrency crime investigations has been cited by worldwide organizations and authorities our bodies, together with the United Nations Security Council and the United Nations Office on Drugs and Crime.
By delivering a complete safety answer custom-made to particular person tasks, we are able to determine dangers and forestall them from occurring. Our workforce was capable of finding and publish a number of high-risk blockchain safety flaws. By doing so, we may unfold consciousness and lift the safety requirements in the blockchain ecosystem.
