GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Liquid hacker may receive a bounty if remaining stolen funds are returned

Bitcoin News posted on X platform stating that Samson Mow said Blockstream refuses to pay a ransom and does not rule out offering a bounty if the hacker returns the remaining stolen funds. Mow stated that the stolen funds belong to Liquid users, and Blockstream cannot negotiate over these funds; any bounty would need to be an independent and reasonable arrangement.

Blockstream Refuses to Pay Ransom, Vows to Recover Stolen Bitcoin from Liquid Network

Blockstream officially announced on the X platform that Liquid Network has suffered a Bitcoin theft incident. The company explicitly stated its refusal to pay any ransom and characterized the act as a crime rather than a white-hat disclosure. Blockstream has collaborated with law enforcement agencies, exchanges, forensic experts, and other parties to trace the stolen assets through on-chain tracking and other means. It also called on current holders to voluntarily return the Bitcoin, warning that they will face full legal action otherwise.

Liquid Network Vulnerability Disclosure Handling Sparks Public Dispute Between Samson Mow and Bitcoin Red Team

Bitcoin News posted on X stating that Samson Mow and Bitcoin Red Team researcher Calle are engaged in a public dispute over whether security warnings related to a Liquid Network exploit were properly handled. Calle claims that Blockstream did not act on the Red Team's email, ultimately resulting in a loss of 600 BTC; Mow responded by saying "no email was ignored." Calle stated that once Blockstream restores normal Liquid operations and publishes a post-mortem report, the Red Team will release a full account of the disclosure process. Mow separately warned against blindly trusting AI-generated security reports, saying that unverified fixes could introduce new vulnerabilities, and criticized researchers who prioritize pursuing "clout" over protecting Bitcoin.

Liquid Network Releases Emergency Fix: Elements v23.3.4 Patches Proof Validation Cache Vulnerability

Odaily News: Liquid Network announced that the emergency release Elements v23.3.4 is now live, with Functionary nodes having immediately begun upgrades. All Liquid node operators are advised to update accordingly. This release addresses a previously identified Proof validation cache vulnerability by strengthening the cache keys used for Range Proofs.Regarding network recovery, Blockstream stated that a recovery plan is still being formulated, expected to proceed in three phases: **resume block production while continuing to pause Peg operations; replay verified valid transactions; restore Peg operations after the network state is fully recovered and fund returns are confirmed.** Currently, the first two phases are being tested in parallel, and any phase will only advance once confirmed secure.Liquid Network stated that Elements v23.3.4 has undergone multiple rounds of internal and external reviews, with participants including the Bitcoin Red Team, Alpen Labs, and other teams. Meanwhile, Liquid Network reminds users to be wary of fake upgrade websites exploiting this incident for scams. Information should only be obtained through official Liquid Network and Blockstream channels, and users should never send funds to strangers or disclose private keys or seed phrases.

Liquid white hat hacker group demands Blockstream pay 10% bug bounty for $5 billion in assets

According to Odaily Planet Daily, as monitored by Bitcoin News, the white hat hacker group behind the Liquid exploit has accused Blockstream of spending only $1.5 million—or possibly nothing at all—to secure $5 billion in assets. In a new on-chain message, the group demanded that Blockstream allocate its own funds to pay a bug bounty equivalent to 10% of the associated assets, warning that refusal to pay would result in a 15% loss for holders. The group also stated it would release the private keys used to decrypt previous communications with Blockstream. Earlier, the group had returned 3,400 BTC to the Liquid Federation, with approximately 600 BTC still unrepaid.

Liquid Network: In discussions with white hat to recover remaining 598.5 BTC, network restoration efforts also underway

Liquid Network's official security incident report: On September 6, a vulnerability related to the range proof verification method in Liquid node caching within the open-source software Elements was exploited, resulting in the creation of approximately 4,000 LBTC tokens not backed by bitcoin reserves. The exploiter subsequently exchanged them for approximately 4,000 BTC via SideSwap and the Liquid standard Peg-out mechanism. Prior to the incident, Liquid's reserves stood at approximately 4,205 BTC. After the relevant Peg-out and other withdrawals completed before the network halt, reserves fell to 197 BTC.According to the official statement, the incident did not involve the compromise of Functionary nodes or private keys, and other issued assets on Liquid such as USDT were also unaffected by the vulnerability. The exploiter claimed to be a white hat security researcher and returned 3,400 BTC to the Liquid Federation Peg wallet on September 7. Approximately 598.5 BTC (about 15% of the funds involved) remain unrecovered, and Blockstream is in communication to recover the remaining assets.At present, the top priority is to recover the remaining funds and restore Liquid Network to normal operation as quickly and safely as possible. A fix for the vulnerability has been developed and is currently undergoing multiple rounds of internal and external review. Blockstream is preparing to urgently release Elements v23.3.4, which is expected to be rolled out as soon as preparations are complete, with a target launch within approximately 48 hours. Following the software update, Liquid Network Functionary operators will make further adjustments to restore full network functionality and resume a corrected network state, including rejecting previously invalid Peg-outs.

Liquid Network preparing to restart, Blockstream has deployed updated software

Odaily News, according to Bitcoin News, Blockstream stated that Liquid Federation members are preparing to coordinate a network restart, with the updated software already deployed. Previously, a security incident occurred on the Liquid Network, resulting in fund transfers. Blockstream noted that its team remains focused on further strengthening the network and ensuring asset restitution. Blockstream thanked the Bitcoin community for its patience, support, suggestions, and assistance, and stated that more updates will be released in the future.

Liquid Network white hat hacker returns 3,400 BTC, keeps about 598 BTC as bounty

According to on-chain monitoring by analyst PeckShield (@PeckShieldAlert), the Liquid Network was targeted by white-hat hackers. Approximately 4,000 BTC (roughly $320 million) were transferred from a Liquid Federation wallet. The funds were consolidated into address bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte, accompanied by an on-chain message: "We are white hats, please contact us on-chain." Subsequently, the hackers completed on-chain negotiations with Blockstream, returning 3,400 BTC (approximately $315 million, or 85% of the total) while retaining around 598.5 BTC (about $47.38 million) as a bug bounty.

Blockstream notifies white hat hackers that vulnerability has been fixed, approximately 4,000 BTC pending return

Odaily News: Blockstream has notified white hat hackers that the vulnerability fix is complete and the approximately 4,000 BTC can be safely returned. The hacker who previously withdrew funds from the Liquid network expressed willingness to return them, but requested that the vulnerability be fixed first. Both parties have been negotiating publicly through Bitcoin OP_RETURN messages.The hacker initially proposed returning "most" of the BTC, but later changed their stance, demanding that the vulnerability be fixed first: "Ensure every node has been patched, and once the fix is confirmed, we will securely return the funds." The hacker also sent encrypted vulnerability details to Blockstream. About two hours ago, Blockstream responded via a PGP-signed OP_RETURN message stating that nodes have been patched. Currently, 3,998.5 BTC remain under the hacker's control.

After fixing the vulnerability, Liquid's white hat hacker said they would return most of the 4,000 BTC

According to Odaily, monitoring by Galaxy's Head of Research revealed that Liquid's white hat hacker stated they would return most of the 4,000 BTC after the Liquid Network vulnerability is patched. The hacker communicated with Blockstream through OP_RETURN messages and PGP-encrypted text: In block 965,822, a Blockstream address sent 1,000 satoshis with the message "Please contact the security team via the Blockstream website"; in block 965,865, the hacker sent an encrypted message to their own key, accompanied by a detached PGP signature that can be verified using the key published by Blockstream; in block 965,869, the hacker sent 1,000 satoshis to the Liquid federation peg-in wallet via a self-spend transaction with the message "Can we return the majority of the funds to the federation address?"; in block 965,875, the hacker conducted another self-spend transaction, sending 1,000 satoshis to the federation peg-in wallet and leaving an OP_RETURN message: "Please fix the vulnerability first. As of the latest commit, there is risk on-chain. Please ensure every node completes the patch update. Once the fix is confirmed, we will securely transfer the funds back." Relevant technical details were encrypted via PGP messages to the key published by Blockstream, readable only by Blockstream.

White-Hat Hacker Withdraws Approximately 4,000 BTC from Liquid Network; Side Chain Suspends Operations

According to an announcement from the official Liquid Network X account (@Liquid_BTC), a suspected whitehat hacker withdrew approximately 4,000 BTC worth around $320 million from a Liquid Federation wallet using a SideSwap PAK (Peg-out Authorization Key). The official statement indicated that the key itself was not leaked, and the Blockstream team is attempting to contact the party through on-chain signed messages. Following the incident, exchanges have paused or are about to pause LBTC deposit and withdrawal services. Bridge nodes have been temporarily shut down, and the Liquid sidechain is currently suspended, unable to submit new transactions. Officials emphasized that other Liquid assets such as USDT, DePix, and RWA remain unaffected by this incident, while Federation members are actively working to resolve the issue to restore normal network operations as soon as possible.

Jade unaffected by Coldcard RNG vulnerability, Blockstream releases firmware 1.0.41

Odaily News: Bitcoin News posted on X platform that Blockstream stated Jade is not affected by the Coldcard random number generator vulnerability, and has released firmware 1.0.41 following a large number of AI-assisted security reviews.Jade stated that it has undergone dozens of automated AI scans and multiple manual reviews, focusing on sensitive areas such as random number generation and transaction signing.The new firmware strengthens stack protection, updates dependencies, audits sensitive memory cleanup processes, and upgrades the Jade runtime environment.Blockstream stated that Jade's random number generation mechanism uses multiple entropy sources, including hardware chip noise, timing data, sensor data, and camera noise, mixed via SHA-512 to prevent a single entropy source failure from affecting seed generation.The team stated that other lower-severity findings are still being addressed, and firmware 1.0.42 is expected to be released within a shorter development cycle.

Coldcard incident boosts BitBox credit card sales by ~10x, while Trezor and OneKey see rising demand

Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)

Crypto Companies Send Joint Letter to AI Labs, Urging Access to Frontier Models for Bitcoin Developers

据 Cointelegraph 报道,比特币政策研究所(BPI)联合 Anchorage Digital、BitGo、Bitwise、Blockstream、Kraken、Ledger、MARA、Trezor 等多家加密机构,发布公开信敦促各大前沿 AI 实验室为比特币及开源软件开发者建立或扩展可信访问计划。 信中指出,Bitcoin Core 等开源维护者目前缺乏对 AI 实验室网络安全程序的访问渠道,被迫依赖能力较弱的开源模型,而比特币网络当前保护着逾 1 万亿美元资产,任何开源基础设施漏洞均可能危及用户毕生积蓄。BPI 同时披露,已收到多份报告显示包括潜在境外势力在内的复杂攻击者正借助先进 AI 能力持续发动攻击。

Bitcoin’s Quantum Security Crisis: 6.9 Million BTC at Risk, Governance Challenges Impede Response

According to CoinDesk, while quantum computers cannot break Bitcoin’s mining mechanism or blockchain ledger, they could potentially crack the elliptic curve cryptography (ECC) that secures wallet ownership—using Shor’s algorithm. Currently, approximately 6.9 million BTC—roughly one-third of the total supply—are at potential risk because their public keys are already visible on-chain; this includes Satoshi Nakamoto’s estimated early holdings of about 1 million BTC. Transactions generated after Ethereum’s 2021 Taproot upgrade are similarly exposed due to public key disclosure. Ethereum has maintained an official post-quantum migration plan since 2018, with four full-time teams and over ten independent development groups, and operates a dedicated progress website at pq.ethereum.org. In contrast, Bitcoin currently lacks a unified roadmap for quantum resistance: existing proposals such as BIP-360 and BitMEX Research’s detection framework have not gained broad support among core developers. Prominent Bitcoin advocate Nic Carter has bluntly labeled Bitcoin’s quantum response “the worst,” while Blockstream CEO Adam Back acknowledges that current quantum systems remain confined to laboratory settings—but still endorses deploying optional upgrade paths in advance. Analysts note that Bitcoin’s decentralized governance culture makes coordinating large-scale security upgrades extremely difficult, and resolving historical issues—such as how to handle Satoshi’s holdings—presents a particularly thorny dilemma. A related Google paper warns that once quantum attacks become feasible, the window for effective response may already have closed.

Adam Back Advocates Optional Quantum-Resistant Upgrades, Diverging from BIP-361’s Mandatory Freeze Proposal

According to Decrypt, Blockstream CEO Adam Back stated at Paris Blockchain Week that he supports advancing Bitcoin’s quantum resistance upgrade on an opt-in basis, opposing proposals to forcibly freeze quantum-vulnerable addresses. He emphasized that “preparation well in advance is far safer than scrambling to respond during a crisis,” and noted that the Bitcoin community possesses strong coordination capabilities to rapidly address critical vulnerabilities. Previously, developer Jameson Lopp and five others proposed BIP-361 (“Post-Quantum Migration and Legacy Signature Sunset”), which advocates phasing out quantum-vulnerable addresses over five years and ultimately freezing coins held in unmigrated addresses—including approximately 1.7 million bitcoins held by Satoshi Nakamoto.

Adam Back advocates for Bitcoin to promptly advance optional post-quantum upgrades and opposes pre-emptively freezing vulnerable addresses.

According to CoinDesk, Adam Back, CEO of Blockstream, stated at Paris Blockchain Week that Bitcoin developers should move forward early with optional post-quantum upgrades—even though practical quantum computers remain far from realization. He noted that Taproot’s flexible design supports integrating new post-quantum signature schemes without affecting existing users. Previously, Jameson Lopp and others proposed BIP-361, aiming to phase out quantum-vulnerable addresses over five years and freeze bitcoins in addresses that fail to complete the migration. Adam Back believes the Bitcoin community can rapidly coordinate a response in an emergency—without needing to predefine freezing arrangements.