I had my clanker implement the Liquid inflation attack as a Python functional test, and then explain it to me with some diagrams. A functional test is a good way to catch hallucinations in the attack scenario. When responsibly disclosed, it also gives maintainers a way to quickly assess if they want to read your slop. This is safe to publish because the attack involves transactions that are consensus invalid for both old nodes and future fixed nodes. No blocks are mined currently, so new attacks won't get mined. Even if they did, they'd get reorged along with the attack block once operations resume.

Replies (2)

Perhaps a failsafe along the lines of: 'Don't spend more than 10% of balance in a single peg-out'... would have been sensible. I'm going to the grocery store after breakfast. Fortunately my method of transport is made by Doppelmayr and not Blockstream.