I think the problem here, and imho this is really nasty, is:
The problem was spotted a while ago and it was fixed, but not treated as a security incident.
The fix commit was sitting in a release candidate
The attacker raced the release / deployment of the fix
So that is a nightmare scenario for open collaboration on FOSS, which is something we have to think about how to counter. I might make a post about it, because this is pretty bad.
Or is it able to be cancelled
No. The swap already paid on L1 in BTC.
So whose buckets do these 4 hunny billy sats get taken from?
It's 95% of all sats on Liquid - basically the backing of that entire network.
I think the problem here, and imho this is really nasty, is:
So that is a nightmare scenario for open collaboration on FOSS, which is something we have to think about how to counter. I might make a post about it, because this is pretty bad.
No. The swap already paid on L1 in BTC.
It's 95% of all sats on Liquid - basically the backing of that entire network.