Critical Security Update Deployed

On September 10, Liquid Network rolled out an emergency software release, Elements v23.3.4. This update addresses a critical vulnerability identified in the proof verification cache, marking a necessary step to safeguard network integrity. All node operators are urged to upgrade their software without delay.

Vulnerability Details and Mitigation

The patch specifically strengthens the cache key mechanism used during range proof verification, enhancing security in this critical process. Prior to release, the fix underwent rigorous internal and external scrutiny, including audits from independent security teams such as Bitcoin Red Team and Alpen Labs, to validate its effectiveness and robustness.

The Network Recovery Roadmap

Alongside the security patch, Liquid Network shared a preliminary plan to restore full network functionality in a controlled, phased manner.

  • Phase One: Resume Block Production. The network will restart producing blocks while temporarily keeping peg-in and peg-out operations paused.
  • Phase Two: Process Valid Transactions. Transactions that have already been verified as valid will be reprocessed to ensure user actions are honored.
  • Phase Three: Full Restoration. Peg operations will only be reinstated after the network is fully stabilized and all user fund return processes are confirmed complete.

Development teams are currently conducting parallel tests on the first two phases. The final implementation order and technical specifics may be adjusted based on test outcomes.

Essential Security Advisory

It is crucial to note that security incidents often attract malicious actors. Liquid Network has issued a specific warning about phishing attempts related to this update, with scammers already creating fake websites impersonating official update channels.

Users must obtain update information and software packages exclusively from the official Liquid Network or Blockstream websites, GitHub repositories, or verified social media accounts. Under no circumstances should you transfer funds to unknown entities or disclose sensitive information like private keys or seed phrases.