GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Regulation/Compliance

News linked to both this project and an event.

Liquid Network Releases Emergency Fix: Elements v23.3.4 Patches Proof Validation Cache Vulnerability

Odaily News: Liquid Network announced that the emergency release Elements v23.3.4 is now live, with Functionary nodes having immediately begun upgrades. All Liquid node operators are advised to update accordingly. This release addresses a previously identified Proof validation cache vulnerability by strengthening the cache keys used for Range Proofs.Regarding network recovery, Blockstream stated that a recovery plan is still being formulated, expected to proceed in three phases: **resume block production while continuing to pause Peg operations; replay verified valid transactions; restore Peg operations after the network state is fully recovered and fund returns are confirmed.** Currently, the first two phases are being tested in parallel, and any phase will only advance once confirmed secure.Liquid Network stated that Elements v23.3.4 has undergone multiple rounds of internal and external reviews, with participants including the Bitcoin Red Team, Alpen Labs, and other teams. Meanwhile, Liquid Network reminds users to be wary of fake upgrade websites exploiting this incident for scams. Information should only be obtained through official Liquid Network and Blockstream channels, and users should never send funds to strangers or disclose private keys or seed phrases.

Liquid Network: In discussions with white hat to recover remaining 598.5 BTC, network restoration efforts also underway

Liquid Network's official security incident report: On September 6, a vulnerability related to the range proof verification method in Liquid node caching within the open-source software Elements was exploited, resulting in the creation of approximately 4,000 LBTC tokens not backed by bitcoin reserves. The exploiter subsequently exchanged them for approximately 4,000 BTC via SideSwap and the Liquid standard Peg-out mechanism. Prior to the incident, Liquid's reserves stood at approximately 4,205 BTC. After the relevant Peg-out and other withdrawals completed before the network halt, reserves fell to 197 BTC.According to the official statement, the incident did not involve the compromise of Functionary nodes or private keys, and other issued assets on Liquid such as USDT were also unaffected by the vulnerability. The exploiter claimed to be a white hat security researcher and returned 3,400 BTC to the Liquid Federation Peg wallet on September 7. Approximately 598.5 BTC (about 15% of the funds involved) remain unrecovered, and Blockstream is in communication to recover the remaining assets.At present, the top priority is to recover the remaining funds and restore Liquid Network to normal operation as quickly and safely as possible. A fix for the vulnerability has been developed and is currently undergoing multiple rounds of internal and external review. Blockstream is preparing to urgently release Elements v23.3.4, which is expected to be rolled out as soon as preparations are complete, with a target launch within approximately 48 hours. Following the software update, Liquid Network Functionary operators will make further adjustments to restore full network functionality and resume a corrected network state, including rejecting previously invalid Peg-outs.

Jade unaffected by Coldcard RNG vulnerability, Blockstream releases firmware 1.0.41

Odaily News: Bitcoin News posted on X platform that Blockstream stated Jade is not affected by the Coldcard random number generator vulnerability, and has released firmware 1.0.41 following a large number of AI-assisted security reviews.Jade stated that it has undergone dozens of automated AI scans and multiple manual reviews, focusing on sensitive areas such as random number generation and transaction signing.The new firmware strengthens stack protection, updates dependencies, audits sensitive memory cleanup processes, and upgrades the Jade runtime environment.Blockstream stated that Jade's random number generation mechanism uses multiple entropy sources, including hardware chip noise, timing data, sensor data, and camera noise, mixed via SHA-512 to prevent a single entropy source failure from affecting seed generation.The team stated that other lower-severity findings are still being addressed, and firmware 1.0.42 is expected to be released within a shorter development cycle.

Coldcard incident boosts BitBox credit card sales by ~10x, while Trezor and OneKey see rising demand

Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)

Crypto Companies Send Joint Letter to AI Labs, Urging Access to Frontier Models for Bitcoin Developers

据 Cointelegraph 报道,比特币政策研究所(BPI)联合 Anchorage Digital、BitGo、Bitwise、Blockstream、Kraken、Ledger、MARA、Trezor 等多家加密机构,发布公开信敦促各大前沿 AI 实验室为比特币及开源软件开发者建立或扩展可信访问计划。 信中指出,Bitcoin Core 等开源维护者目前缺乏对 AI 实验室网络安全程序的访问渠道,被迫依赖能力较弱的开源模型,而比特币网络当前保护着逾 1 万亿美元资产,任何开源基础设施漏洞均可能危及用户毕生积蓄。BPI 同时披露,已收到多份报告显示包括潜在境外势力在内的复杂攻击者正借助先进 AI 能力持续发动攻击。

Adam Back Refutes the "Bitcoin Supports Spam Data" Argument: Limiting Spam Cannot Rely on Soft Forks Lacking Consensus

Odaily News BIP-110 has sparked community controversy over its attempt to restrict non-financial data storage on the Bitcoin blockchain. Supporters of this proposal plan to push for the rule change through a User-Activated Soft Fork (UASF), but current miner support is far from meeting the activation requirements. The market is watching whether this controversy will further escalate into a split within Bitcoin's network governance.Blockstream CEO Adam Back criticized the arguments of BIP-110 supporters in a post on the X platform, stating that the claim "Bitcoin supports spam data" is incorrect and noting that all Bitcoin participants dislike network spam. Adam Back pointed out that Bitcoin cannot achieve absolute censorship at the mathematical level, and the BIP-110 proposal itself has numerous flaws that prevent it from functioning effectively, which is why it has not gained network consensus. He emphasized that forcibly pushing rule changes without consensus could ultimately lead to a fork outcome similar to Bitcoin SV (BSV).