The Bitcoin network used by the exchange was hit by a $320 million vulnerability, with hackers claiming to be "good people."

CN
1 hour ago
The attacker demanded that the vulnerability be repaired and all nodes patched before returning the funds through on-chain messages. However, as of the time of publication, Liquid has not specified when the network will restart or whether the funds can be returned.

Author: Omkar Godbole (CoinDesk)

Translation: Deep Tide TechFlow

Deep Tide Guide: The Bitcoin sidechain Liquid Network was drained of approximately 4000 BTC (the vast majority of the 4200 BTC in the alliance wallet), worth about $320 million, and trading on the network was immediately halted. Unlike most hacking incidents this year, this was not due to a private key or password leak, but rather a vulnerability in the open-source software Elements that supports Liquid, causing funds to flow out through the legitimate platform SideSwap. The attacker demanded that the vulnerability be fixed, all nodes patched, and then the funds returned. However, as of the time of publication, Liquid has not specified when the network will restart or whether the funds can be returned.

Approximately 4000 BTC Withdrawn, Sidechain Suspends Trading

Liquid Network was launched by Blockstream in 2018, which stated that the so-called "white hat hacker" extracted about 4000 BTC from the alliance wallet of approximately 4200 BTC. The network is governed collectively by an alliance of over 80 exchanges, infrastructure companies, and asset management companies.

"The Liquid wallet will be affected, and we sincerely apologize for the inconvenience this has caused," Liquid Network posted on X, while also suspending all new transactions. "Alliance members are actively addressing this matter to restore the normal functioning of the network."

Why This Matters

The sidechain has halted new transactions and warned that wallets will be affected during the recovery of services by alliance members. This matter is significant because the original intent of Liquid was to solve a real pain point faced by exchanges, primarily the slow transaction speeds on the Bitcoin mainchain. To address this, the network issues L-BTC backed by locked reserve bitcoins, allowing for faster transaction settlements. However, with nearly the entire reserve being drained, doubts have been raised about the safety of this model.

The Vulnerability is in the Software, Not in the Private Keys

This theft was not due to the leakage of passwords or private keys, which is the method used in most crypto hacking incidents this year. Instead, the stolen funds flowed through SideSwap, a legitimate and authorized platform.

Subsequently, Blockstream discovered that a software vulnerability in a system called Elements "created" a portion of the involved bitcoins. SideSwap stated that it could not distinguish between coins sourced from the vulnerability and those that were legitimate funds, thus processing them all in the same manner. Other types of assets on the same network (Liquid) were unaffected.

What is a White Hat Hacker

A white hat hacker refers to a "ethical hacker" who exploits the vulnerabilities of a protected system before malicious attackers do. They typically exploit vulnerabilities, transfer funds, and then demand a fee to return the funds.

The Vulnerability is at the Node Level

According to security experts, the vulnerability in this case is at the node level of the Liquid trading software, rather than a breach of keys or hardware modules.

The Attacker Communicates Through On-Chain Messages, Promising to Return Funds

According to recent reports, the attacker is communicating with network maintainers through Bitcoin on-chain transactions, promising to return the funds after the vulnerability is fixed.

"Please fix the vulnerability first. Currently, this chain remains at risk at least in the latest submission. Ensure every node has been patched. Once confirmed that the fix is applied, we will safely return the money," one message stated.

Recent Series of Security Incidents

Just a week before this theft occurred, a lending platform associated with Crypto.com was drained of $6 million; in August, the Coldcard hardware wallet was also compromised. Liquid has not specified when the network will restart, nor has it confirmed whether these bitcoins can be returned.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink