SideSwap Client Exploits Elements Vulnerability to Mint Counterfeit L-BTC
A client of SideSwap took advantage of a vulnerability in the Elements software to mint 4000 L-BTC, worth $80,375.00 at current prices. The client then used the peg-out service offered by SideSwap to exchange this L-BTC for BTC on Liquid.
The transaction was processed normally by SideSwap's services, and the 3996 BTC was paid out to the client's Bitcoin address at 14:28 UTC. However, it was later confirmed by Blockstream that the L-BTC in question were indeed minted using a vulnerability in the Elements software.
SideSwap clarified that their peg-out service authorization key and system were not compromised, but rather they were unable to distinguish between legitimate and counterfeit L-BTC. The company emphasized that their service is non-custodial, meaning users retain control of their assets through their own private keys.
Liquid has been temporarily paused by the Liquid Federation, and SideSwap's exchange, peg-in, and peg-out services will also be suspended until the network is restored. However, completed peg-outs on Bitcoin are unaffected, and any uncompleted peg-ins or peg-outs can be sent to a special email address for individual handling.