An Elements protocol consensus/asset-validation bug let an attacker mint ≈4,000 unbacked L-BTC and drain ≈3,996 BTC via SideSwap's peg-out flow on Sept. 6-7. The attacker claims to be a "whitehat," but funds remain unreturned; Bitcoin mainnet itself was not exploited.
Matters because: this highlights sidechain and bridge security risk rather than BTC L1 risk, and could pressure confidence in Liquid-based products until funds are recovered or clarified.
