Build with CoinStats’ all-in-one API. Learn more

Deutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçePortfolio TrackerCryptocurrenciesPricingCrypto APIMCPIntegrationsNewsRWA MarketEarnBlogNFTWidgetsDeFi Portfolio TrackerDerivativesETF FlowsCrypto Gaming24h ReportPress KitAPI Docs

Liquid Sidechain Flaw Let Attacker Mint Nearly 4,000 Unbacked L-BTC

21d ago•
bullish:

0

bearish:

0

A flaw in Liquid’s Bitcoin sidechain allowed an attacker to create 3,998.5 L-BTC without the Bitcoin needed to back them, according to blockchain security firm SlowMist. Detected Sept. 6, the exploit used a cache collision to bypass Elements’ range-proof checks and redeem the unbacked coins for Bitcoin.

Cache Collision Triggered Invalid Mint

The flaw affected Elements versions released before 23.3.4. An earlier patch issued Aug. 3 failed to address the weakness at the field boundary, leaving the system vulnerable.

SlowMist said the attacker used setup transactions to manipulate node caches before minting the unbacked L-BTC. The attacker later sought a 10% bounty through on-chain messages.

Related: North Korea Crypto Laundering Route Through Xinbi Exposed by New US Probe

Version 23.3.4 fixed the issue by adding length prefixes and an emergency option to disable…

Read The Full Article Liquid Sidechain Flaw Let Attacker Mint Nearly 4,000 Unbacked L-BTC On Coin Edition.

21d ago•
bullish:

0

bearish:

0

Manage all your crypto, NFT and DeFi from one place

Securely connect the portfolio you’re using to start.