SideSwap Recap: Automated peg-out, swapping 4000 L-BTC for real funds

SideSwap’s own recap lays it out clearly: on September 6, an Elements consensus flaw minted roughly 4,000 uninsured L-BTC out of thin air. The other party then carried out a peg-out, and the Federation released about 3,996 BTC.

The wallet’s private keys weren’t lost—rather, they were exposed by the operational design: the peg-out authorization key stayed online for the long term, payments were automatically pushed outward, and there were almost no restrictions on large amounts, frequency, or sources. The same recap also mentioned something even more striking: the vulnerability patch was written as early as August, but it only made it into the public repository on September 1—leaving enough of a window for people to rehearse more than 70 “dress rehearsal” transactions.

Don’t interpret “non-custodial wallet is fine” as “the bridge can still routinely move in and out.” Liquid is still down; before peg is enabled, don’t assume redemption is available by default.

Automated large-amount peg-outs are more jarring than even the vulnerability’s headline.