A $320M exploit, a 24/7 agentic red team & the future ecosystem security
After hearing about the near 4000 BTC (~$320M) Liquid exploit on September 6, I pointed MASH, @AlpenLabs’ internal Multi-Agent Security Harness, at the Elements codebase. We’ve been working on an agentic red team to continuously secure our own ecosystem, so I was curious to see what these tools could do.
In about an hour, the agents had traced the root cause, written a post-incident report with a local reproduction of the exploit.
But its finding did not match the speculations circulating at the time. The speculation circulating online was that a public commit had exposed an existing vulnerability before nodes could upgrade. Our agents pointed to a different explanation: a change intended to fix an older bug had introduced a new flaw in the cache key.
That surprised me, but after reviewing the findings closely, including the local reproduction of the exploit, I promptly shared our reports with @adam3us and the team.
The @Blockstream team confirmed that the root cause matched their internal findings. That night, I used MASH to support their head of engineering with further investigation, fix development and validation. The subsequent remediation report documents that work .
Code Review & Audits → Continuous Monitoring & Pentesting
Much of the conversation around cyber-capable AI focuses on how fast attackers can find and exploit weaknesses. We don’t have evidence that AI was used in the Liquid attack, but we saw firsthand what it could do for defense.
A blockchain is a state machine. Every transaction changes its state; upgrades can change the rules, and new applications and integrations change how those rules are exercised. Security assumptions need to keep holding as the system evolves.
Audits and code review provide essential checkpoints. But to secure live blockchain systems in this new AI-Cyber age, we must go beyond static checkpoints. Teams of agents coordinating in harnesses like MASH can be deployed for ongoing defense: monitor the live ecosystem, reproduce suspicious behavior in controlled environments, and surface these findings before a bug turns into an exploit.
How we’re applying MASH at Alpen
With Alpen approaching mainnet, we’re working towards a 24/7 MASH red team on our continuously evolving ecosystem.
Agents test the live bridge, proof system, consensus and access controls in parallel in staging. They share findings and triage results using independent models providing additional validation & local reproductions. Eventually, we’d like to extend coverage across the ecosystem.
Agents continuously surface potential attack paths and evidence, while Alpen contributors take accountability over fixes & decisions.
We built MASH through our partnerships with @OpenAI and @v12sec. It combines publicly available frontier and open-weight models, restricted cyber models through OpenAI’s Trusted Access for Cyber program, and specialized models like Zellic’s v12.
Designing Fault-Tolerant Systems
When designing a secure system, we should not expect MASH to find every bug before an attacker does at all times. On Alpen, finding a bug should still leave an attacker facing challenge periods, withdrawal velocity checks, and further validation and authorization before any BTC deposited into our system can be withdrawn. If one defense fails, other independent defensive layers still have to hold.
Those protections, however, also need to let valid withdrawals complete and state finality to continue. An attacker shouldn’t be able to turn a safety check into an indefinite freeze. Safety and liveness both matter, especially when finality is immutable and we can’t rely on rolling a transfer back. We've built our bridge peg mechanism exactly around these principles.
I want MASH testing that fault tolerance as Alpen evolves. I think the same work should become routine across Bitcoin and other ecosystems.
----
The incident report was prepared on September 6, within hours of the exploit. I’m sharing it now, alongside the subsequent remediation report, after delaying public release for security reasons.
[1] Post-incident report: alpen.org/files/liquid-incident.pdf
[2] Remediation report: alpen.org/files/elements-remediation.pdf

