GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Liquid hacker may receive a bounty if remaining stolen funds are returned

Bitcoin News posted on X platform stating that Samson Mow said Blockstream refuses to pay a ransom and does not rule out offering a bounty if the hacker returns the remaining stolen funds. Mow stated that the stolen funds belong to Liquid users, and Blockstream cannot negotiate over these funds; any bounty would need to be an independent and reasonable arrangement.

Liquid Network hit by major exploit, Bitcoin News publishes security incident newsletter

Odaily News: According to Bitcoin News monitoring, its latest newsletter reviewed multiple security incidents over the past eight weeks involving projects that Bitcoin users rely on in their daily activities, with a focus on the latest major exploit targeting Liquid Network.

Hacker Exploits Symbiosis Bitcoin Bridge Vulnerability to Mint ~$46.1 Billion in Face Value syBTC, Cashes Out Only $336,000

Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)

SlowMist Discloses Liquid Vulnerability Details: Attacker Minted 3,998.5 L-BTC Without Collateral, Approximately 598.5 BTC Still Not Returned

SlowMist has disclosed that the Liquid Network was attacked on September 6 via a Rangeproof verification cache key collision vulnerability. The attacker minted approximately 3,998.5 L-BTC without collateral — with no corresponding BTC peg-in — and then within minutes converted them to BTC on the Bitcoin mainnet via peg-out. After the incident, approximately 3,400 BTC was returned to the Liquid Federation peg wallet, but approximately 598.5 BTC remains under the attacker's control.SlowMist noted that the root cause of the vulnerability lies in the fact that the Rangeproof verification cache key in Elements did not include length prefixes when concatenating multiple variable-length fields, allowing different parameter combinations to potentially generate the same cache key. The attacker triggered a cache collision by constructing transactions, causing nodes to hit a "verification passed" cached result, thereby bypassing secp256k1_rangeproof_verify and the minimum amount check, ultimately accepting outputs not backed by real assets and completing the L-BTC minting. SlowMist stated that it has traced the fund flows on the Bitcoin side and completed its analysis of the incident.

Blockstream Refuses to Pay Ransom, Vows to Recover Stolen Bitcoin from Liquid Network

Blockstream officially announced on the X platform that Liquid Network has suffered a Bitcoin theft incident. The company explicitly stated its refusal to pay any ransom and characterized the act as a crime rather than a white-hat disclosure. Blockstream has collaborated with law enforcement agencies, exchanges, forensic experts, and other parties to trace the stolen assets through on-chain tracking and other means. It also called on current holders to voluntarily return the Bitcoin, warning that they will face full legal action otherwise.

Liquid Network Vulnerability Disclosure Handling Sparks Public Dispute Between Samson Mow and Bitcoin Red Team

Bitcoin News posted on X stating that Samson Mow and Bitcoin Red Team researcher Calle are engaged in a public dispute over whether security warnings related to a Liquid Network exploit were properly handled. Calle claims that Blockstream did not act on the Red Team's email, ultimately resulting in a loss of 600 BTC; Mow responded by saying "no email was ignored." Calle stated that once Blockstream restores normal Liquid operations and publishes a post-mortem report, the Red Team will release a full account of the disclosure process. Mow separately warned against blindly trusting AI-generated security reports, saying that unverified fixes could introduce new vulnerabilities, and criticized researchers who prioritize pursuing "clout" over protecting Bitcoin.

Liquid Network resumes block production after a $320 million exploit

Liquid Network resumed empty block production after deploying an emergency patch, following a core software vulnerability that resulted in nearly $320 million in assets being withdrawn. Asset recovery and system stability monitoring are currently ongoing.

$50 Million in Liquid Assets Must Be Fully Returned, Samson Mow Warns Alleged White Hat Hacker Attacker Leaves More Clues

according to Bitcoin News monitoring, Samson Mow has warned the alleged white hat hacker behind the Liquid attack that they may have left behind more clues than they realize. Mow stated, "The net of justice is wide and inescapable; no one will be spared." Mow also questioned the attacker's demand to return Bitcoin in exchange for a bounty, asking whether it is wise to publicly admit to taking Bitcoin and demand a bounty in return. Mow pointed out that Liquid's approximately $5 billion in assets, including L-BTC, Tether, and real-world assets, all belong to their respective issuers and holders, and cannot be used as a basis for calculating a bounty. Regardless of how other matters are negotiated, all user assets must be fully returned.

Liquid Network Releases Emergency Fix: Elements v23.3.4 Patches Proof Validation Cache Vulnerability

Odaily News: Liquid Network announced that the emergency release Elements v23.3.4 is now live, with Functionary nodes having immediately begun upgrades. All Liquid node operators are advised to update accordingly. This release addresses a previously identified Proof validation cache vulnerability by strengthening the cache keys used for Range Proofs.Regarding network recovery, Blockstream stated that a recovery plan is still being formulated, expected to proceed in three phases: **resume block production while continuing to pause Peg operations; replay verified valid transactions; restore Peg operations after the network state is fully recovered and fund returns are confirmed.** Currently, the first two phases are being tested in parallel, and any phase will only advance once confirmed secure.Liquid Network stated that Elements v23.3.4 has undergone multiple rounds of internal and external reviews, with participants including the Bitcoin Red Team, Alpen Labs, and other teams. Meanwhile, Liquid Network reminds users to be wary of fake upgrade websites exploiting this incident for scams. Information should only be obtained through official Liquid Network and Blockstream channels, and users should never send funds to strangers or disclose private keys or seed phrases.

Liquid white hat hacker group demands Blockstream pay 10% bug bounty for $5 billion in assets

According to Odaily Planet Daily, as monitored by Bitcoin News, the white hat hacker group behind the Liquid exploit has accused Blockstream of spending only $1.5 million—or possibly nothing at all—to secure $5 billion in assets. In a new on-chain message, the group demanded that Blockstream allocate its own funds to pay a bug bounty equivalent to 10% of the associated assets, warning that refusal to pay would result in a 15% loss for holders. The group also stated it would release the private keys used to decrypt previous communications with Blockstream. Earlier, the group had returned 3,400 BTC to the Liquid Federation, with approximately 600 BTC still unrepaid.

Liquid Network: In discussions with white hat to recover remaining 598.5 BTC, network restoration efforts also underway

Liquid Network's official security incident report: On September 6, a vulnerability related to the range proof verification method in Liquid node caching within the open-source software Elements was exploited, resulting in the creation of approximately 4,000 LBTC tokens not backed by bitcoin reserves. The exploiter subsequently exchanged them for approximately 4,000 BTC via SideSwap and the Liquid standard Peg-out mechanism. Prior to the incident, Liquid's reserves stood at approximately 4,205 BTC. After the relevant Peg-out and other withdrawals completed before the network halt, reserves fell to 197 BTC.According to the official statement, the incident did not involve the compromise of Functionary nodes or private keys, and other issued assets on Liquid such as USDT were also unaffected by the vulnerability. The exploiter claimed to be a white hat security researcher and returned 3,400 BTC to the Liquid Federation Peg wallet on September 7. Approximately 598.5 BTC (about 15% of the funds involved) remain unrecovered, and Blockstream is in communication to recover the remaining assets.At present, the top priority is to recover the remaining funds and restore Liquid Network to normal operation as quickly and safely as possible. A fix for the vulnerability has been developed and is currently undergoing multiple rounds of internal and external review. Blockstream is preparing to urgently release Elements v23.3.4, which is expected to be rolled out as soon as preparations are complete, with a target launch within approximately 48 hours. Following the software update, Liquid Network Functionary operators will make further adjustments to restore full network functionality and resume a corrected network state, including rejecting previously invalid Peg-outs.

Liquid Network preparing to restart, Blockstream has deployed updated software

Odaily News, according to Bitcoin News, Blockstream stated that Liquid Federation members are preparing to coordinate a network restart, with the updated software already deployed. Previously, a security incident occurred on the Liquid Network, resulting in fund transfers. Blockstream noted that its team remains focused on further strengthening the network and ensuring asset restitution. Blockstream thanked the Bitcoin community for its patience, support, suggestions, and assistance, and stated that more updates will be released in the future.

Liquid Network white hat hacker returns 3,400 BTC, keeps about 598 BTC as bounty

According to on-chain monitoring by analyst PeckShield (@PeckShieldAlert), the Liquid Network was targeted by white-hat hackers. Approximately 4,000 BTC (roughly $320 million) were transferred from a Liquid Federation wallet. The funds were consolidated into address bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte, accompanied by an on-chain message: "We are white hats, please contact us on-chain." Subsequently, the hackers completed on-chain negotiations with Blockstream, returning 3,400 BTC (approximately $315 million, or 85% of the total) while retaining around 598.5 BTC (about $47.38 million) as a bug bounty.

Blockstream notifies white hat hackers that vulnerability has been fixed, approximately 4,000 BTC pending return

Odaily News: Blockstream has notified white hat hackers that the vulnerability fix is complete and the approximately 4,000 BTC can be safely returned. The hacker who previously withdrew funds from the Liquid network expressed willingness to return them, but requested that the vulnerability be fixed first. Both parties have been negotiating publicly through Bitcoin OP_RETURN messages.The hacker initially proposed returning "most" of the BTC, but later changed their stance, demanding that the vulnerability be fixed first: "Ensure every node has been patched, and once the fix is confirmed, we will securely return the funds." The hacker also sent encrypted vulnerability details to Blockstream. About two hours ago, Blockstream responded via a PGP-signed OP_RETURN message stating that nodes have been patched. Currently, 3,998.5 BTC remain under the hacker's control.

After fixing the vulnerability, Liquid's white hat hacker said they would return most of the 4,000 BTC

According to Odaily, monitoring by Galaxy's Head of Research revealed that Liquid's white hat hacker stated they would return most of the 4,000 BTC after the Liquid Network vulnerability is patched. The hacker communicated with Blockstream through OP_RETURN messages and PGP-encrypted text: In block 965,822, a Blockstream address sent 1,000 satoshis with the message "Please contact the security team via the Blockstream website"; in block 965,865, the hacker sent an encrypted message to their own key, accompanied by a detached PGP signature that can be verified using the key published by Blockstream; in block 965,869, the hacker sent 1,000 satoshis to the Liquid federation peg-in wallet via a self-spend transaction with the message "Can we return the majority of the funds to the federation address?"; in block 965,875, the hacker conducted another self-spend transaction, sending 1,000 satoshis to the federation peg-in wallet and leaving an OP_RETURN message: "Please fix the vulnerability first. As of the latest commit, there is risk on-chain. Please ensure every node completes the patch update. Once the fix is confirmed, we will securely transfer the funds back." Relevant technical details were encrypted via PGP messages to the key published by Blockstream, readable only by Blockstream.

White-Hat Hacker Withdraws Approximately 4,000 BTC from Liquid Network; Side Chain Suspends Operations

According to an announcement from the official Liquid Network X account (@Liquid_BTC), a suspected whitehat hacker withdrew approximately 4,000 BTC worth around $320 million from a Liquid Federation wallet using a SideSwap PAK (Peg-out Authorization Key). The official statement indicated that the key itself was not leaked, and the Blockstream team is attempting to contact the party through on-chain signed messages. Following the incident, exchanges have paused or are about to pause LBTC deposit and withdrawal services. Bridge nodes have been temporarily shut down, and the Liquid sidechain is currently suspended, unable to submit new transactions. Officials emphasized that other Liquid assets such as USDT, DePix, and RWA remain unaffected by this incident, while Federation members are actively working to resolve the issue to restore normal network operations as soon as possible.

Approximately 4,000 BTC transferred in a single transaction linked to Liquid Network, with an on-chain message calling it a "white hat" operation

Odaily News: According to Bitcoin News monitoring, out of 4,200 BTC associated with a peg-out transaction on the Liquid Network, approximately 4,000 BTC appear to have been moved simultaneously. A subsequent transaction included an OP_RETURN message stating: "We are white hats, please contact us on-chain." It remains unclear what the nature of this transaction is, and whether the funds were moved through an exploit.

ether.fi selects Nexus Mutual to provide slashing coverage for up to 15,000 ETH

: On-chain digital asset management neobank ether.fi has selected Nexus Mutual to provide ETH slashing coverage, covering slashing penalties for its validators up to 15,000 ETH. ether.fi stated that it operates a large-scale validator set on Ethereum, and slashing is a tail risk. This coverage is used to cover validator losses, with a scale exceeding the total historical ETH slashing losses. ether.fi currently manages over $6 billion in assets across products such as Cash, Stake, and Liquid. Since 2019, Nexus Mutual has provided over $7 billion in coverage for smart contract attacks, slashing, and other digital asset risks. (Decrypt)

Yi Lihua: In a bear market, preserving principal should be the top priority; take-profit and stop-loss orders must be strictly enforced.

Liquid Capital founder Yi Lihua posted on X, stating that preserving principal is crucial during bear markets. He pointed out that on-chain theft incidents occur frequently, and ignoring risks solely to chase a few percentage points of returns could result in principal loss. JackYi emphasized that all investments carry risk—including holding funds on exchanges or participating in wealth management products and mining. He stressed that the top priority right now is setting take-profit and stop-loss levels, and proactively planning contingency measures for worst-case scenarios to avoid losing principal before the bull market arrives.