Liquid Sidechain Flaw Exposed as Attacker Mints Thousands of Unbacked L-BTC
A recent flaw in Liquid's Bitcoin sidechain allowed an attacker to mint nearly 4,000 unbacked L-BTC without the necessary Bitcoin backing.
The issue was detected on September 6 by blockchain security firm SlowMist and used a cache collision to bypass Elements' range-proof checks.
The flaw affected Elements versions released before 23.3.4 and an earlier patch issued on August 3 failed to address the weakness at the field boundary, leaving the system vulnerable.
The attacker manipulated node caches using setup transactions to mint the unbacked L-BTC and later sought a 10% bounty through on-chain messages.