Liquid Sidechain Hack Allows Attacker to Mint Nearly 4000 Unbacked L-BTC
A vulnerability in the Liquid sidechain allowed an attacker to mint nearly 4,000 unbacked L-BTC. The flaw was detected on September 6 by blockchain security firm SlowMist and was caused by a cache collision that bypassed Elements' range-proof checks. This allowed the attacker to redeem the unbacked coins for Bitcoin.
The issue affected versions of Elements released before 23.3.4, which failed to address the weakness at the field boundary. The earlier patch issued on August 3 was insufficient to prevent the attack. SlowMist stated that the attacker used setup transactions to manipulate node caches before minting the unbacked L-BTC.
The incident did not involve compromised private keys or smart contracts, but it did affect the trust in the Liquid sidechain. The attacker later sought a 10% bounty through on-chain messages. To address the issue, Version 23.3.4 added length prefixes and an emergency option to disable caching.