Binance Square
#liquid

liquid

18,365 views
106 Discussing
SQUILL
·
--
Article
Blockstream’s Liquid Sidechain Heist: Hackers Demand a Bitcoin “Tip Jar”Blockstream just dropped a bombshell that the same hackers who raided their Liquid sidechain are now demanding a “tip jar” for the 4,000+ $BTC they swiped. The white‑hat crew that swooped in to recover the coins has turned the tables, insisting they keep a slice of the loot as a reward for their “heroic” intervention. Blockstream, obviously not thrilled, is calling out the thieves to return the remaining stash or face the full fury of the crypto community. The Alpha Liquid, Blockstream’s lightning‑fast sidechain, has been a favorite for traders looking to move $BTC off‑chain with near‑instant settlement. When a group of hackers hijacked the network and stole over 4,000 $BTC, the crypto world watched as white‑hat hackers swooped in to recover the coins. Now, the same white‑hat team is asking for a cut of the recovered funds, claiming it’s a fair reward for their “heroic” work. Blockstream’s response? A stern warning that the remaining stolen coins must be returned or they’ll be “pushed to the next level” of enforcement. #Liquid #BTC #CryptoDrama The Punchline Insight If you thought the only thing that could go wrong in crypto is a rug pull, think again. Even the saviors can be greedy. This saga shows that in the wild west of blockchain, heroes can become opportunists, and the line between “white‑hat” and “black‑hat” can blur faster than a meme goes viral. The takeaway? Always double‑check who’s actually pulling the strings before you hand over your digital gold. Engagement Bait So, would you trust a white‑hat hacker who wants a cut of your recovered coins? Drop your thoughts below and let’s see if the community sides with Blockstream or the “heroic” thieves.

Blockstream’s Liquid Sidechain Heist: Hackers Demand a Bitcoin “Tip Jar”

Blockstream just dropped a bombshell that the same hackers who raided their Liquid sidechain are now demanding a “tip jar” for the 4,000+ $BTC they swiped. The white‑hat crew that swooped in to recover the coins has turned the tables, insisting they keep a slice of the loot as a reward for their “heroic” intervention. Blockstream, obviously not thrilled, is calling out the thieves to return the remaining stash or face the full fury of the crypto community.
The Alpha
Liquid, Blockstream’s lightning‑fast sidechain, has been a favorite for traders looking to move $BTC off‑chain with near‑instant settlement. When a group of hackers hijacked the network and stole over 4,000 $BTC , the crypto world watched as white‑hat hackers swooped in to recover the coins. Now, the same white‑hat team is asking for a cut of the recovered funds, claiming it’s a fair reward for their “heroic” work. Blockstream’s response? A stern warning that the remaining stolen coins must be returned or they’ll be “pushed to the next level” of enforcement. #Liquid #BTC #CryptoDrama
The Punchline Insight
If you thought the only thing that could go wrong in crypto is a rug pull, think again. Even the saviors can be greedy. This saga shows that in the wild west of blockchain, heroes can become opportunists, and the line between “white‑hat” and “black‑hat” can blur faster than a meme goes viral. The takeaway? Always double‑check who’s actually pulling the strings before you hand over your digital gold.
Engagement Bait
So, would you trust a white‑hat hacker who wants a cut of your recovered coins? Drop your thoughts below and let’s see if the community sides with Blockstream or the “heroic” thieves.
Liquid returned 85%, leaving 47 million dollars as a bounty—does that count as a white hat? Over the past couple of days, the community has been arguing about this, and I’ll share my take. First, let’s lay out the facts clearly: the attacker created 4,000 LBTC that were fabricated out of thin air, then followed the normal process to withdraw 3,996 real BTC. After Blockstream fixed the nodes, the attacker returned 3,400 more, leaving about 598.5 LBTC, which—at current prices—amounts to roughly 47 million USD. The attacker claims to be a “white hat”: “I’m not here to steal money. I’m here to remind you there are vulnerabilities.” But there’s a logic problem here. What’s the standard process for responsible disclosure? Discover a vulnerability → report it to the project → wait for a fix → collect the bounty. And this time it’s: drain 95% first → wait for the project to fix it → refund 85% → keep 15% as the bounty. The order is reversed, and so is the nature of it. Once Blockstream confirms on-chain that the nodes are fixed and refunds are possible, this also makes things more complicated—in the attacker’s eyes, it effectively confirms a “pay back money equals a settlement” pathway. Ledger’s CTO put it even more directly: this isn’t a white hat—it’s kidnapping first, then negotiating. As the founder of FuturaKey—someone who also builds on-chain products—I understand why the community is split into two camps. One side argues: most of the money came back, so it turned out fine. The other side argues: if this kind of behavior is encouraged, next time attackers will be emboldened—empty the reserves first, and if they refund part later, they can wash themselves as “white hats.” My position is the latter. The reason is simple: if “strike first, then refund” can still be called “white hat,” then the hacking industry has no failure cost—keep a portion when the attack succeeds, call yourself a white hat and ask for mercy when it fails. That is extremely unfair to researchers who do responsible security disclosure the right way. What’s even more concerning is the industry signal: this month Liquid saw 320 million, and Cronos had a rollback—so the density of security incidents is rising. In bear markets, hackers are more active than in bull markets. Project defense budgets are being cut, but the returns from attacks haven’t changed. For ordinary users, I have just one suggestion: anchor the security level of your assets and sidechain assets—always keep it lower than mainnet. Don’t put large positions there just because the yield is a bit higher. Do you think “drain first, then refund 85%” counts as a white hat? Let’s discuss in the comments. The above is only my personal observation and does not constitute investment advice. #Liquid #BTC #Web3 #链上安全 #FuturaKey
Liquid returned 85%, leaving 47 million dollars as a bounty—does that count as a white hat?

Over the past couple of days, the community has been arguing about this, and I’ll share my take.

First, let’s lay out the facts clearly: the attacker created 4,000 LBTC that were fabricated out of thin air, then followed the normal process to withdraw 3,996 real BTC. After Blockstream fixed the nodes, the attacker returned 3,400 more, leaving about 598.5 LBTC, which—at current prices—amounts to roughly 47 million USD.

The attacker claims to be a “white hat”: “I’m not here to steal money. I’m here to remind you there are vulnerabilities.”

But there’s a logic problem here. What’s the standard process for responsible disclosure? Discover a vulnerability → report it to the project → wait for a fix → collect the bounty. And this time it’s: drain 95% first → wait for the project to fix it → refund 85% → keep 15% as the bounty.

The order is reversed, and so is the nature of it. Once Blockstream confirms on-chain that the nodes are fixed and refunds are possible, this also makes things more complicated—in the attacker’s eyes, it effectively confirms a “pay back money equals a settlement” pathway.

Ledger’s CTO put it even more directly: this isn’t a white hat—it’s kidnapping first, then negotiating.

As the founder of FuturaKey—someone who also builds on-chain products—I understand why the community is split into two camps. One side argues: most of the money came back, so it turned out fine. The other side argues: if this kind of behavior is encouraged, next time attackers will be emboldened—empty the reserves first, and if they refund part later, they can wash themselves as “white hats.”

My position is the latter. The reason is simple: if “strike first, then refund” can still be called “white hat,” then the hacking industry has no failure cost—keep a portion when the attack succeeds, call yourself a white hat and ask for mercy when it fails. That is extremely unfair to researchers who do responsible security disclosure the right way.

What’s even more concerning is the industry signal: this month Liquid saw 320 million, and Cronos had a rollback—so the density of security incidents is rising. In bear markets, hackers are more active than in bull markets. Project defense budgets are being cut, but the returns from attacks haven’t changed.

For ordinary users, I have just one suggestion: anchor the security level of your assets and sidechain assets—always keep it lower than mainnet. Don’t put large positions there just because the yield is a bit higher.

Do you think “drain first, then refund 85%” counts as a white hat? Let’s discuss in the comments.

The above is only my personal observation and does not constitute investment advice.

#Liquid #BTC #Web3 #链上安全 #FuturaKey
Mellissa Prach:
Good point $BTC there is always a fake out before a break out..
Trading resumes, but that doesn’t mean risk has been fully cleared. After Liquid reopens trading, what matters more are the reserve data: currently the L-BTC reserve coverage is about 85%, meaning there’s still a gap of roughly 15%. While reopening trading may improve short-term liquidity and market sentiment, it won’t automatically replenish reserves, nor does it imply that redemption pressure has disappeared. Next, focus on three things: whether the official side provides a clear plan to make up the shortfall, whether the reserve address continues to see net inflows, and whether payouts after trading resumes are smooth. If these indicators don’t improve, a price rebound is more likely to be sentiment recovery rather than a fundamental recovery. Before participating in the rebound, be sure to control your position size and wait for verifiable reserve or audit data—don’t let your risk awareness down just because “trading has resumed.”$BTC #Liquid #LBTC #加密市场
Trading resumes, but that doesn’t mean risk has been fully cleared.

After Liquid reopens trading, what matters more are the reserve data: currently the L-BTC reserve coverage is about 85%, meaning there’s still a gap of roughly 15%. While reopening trading may improve short-term liquidity and market sentiment, it won’t automatically replenish reserves, nor does it imply that redemption pressure has disappeared.

Next, focus on three things: whether the official side provides a clear plan to make up the shortfall, whether the reserve address continues to see net inflows, and whether payouts after trading resumes are smooth. If these indicators don’t improve, a price rebound is more likely to be sentiment recovery rather than a fundamental recovery.

Before participating in the rebound, be sure to control your position size and wait for verifiable reserve or audit data—don’t let your risk awareness down just because “trading has resumed.”$BTC

#Liquid #LBTC #加密市场
Liquid resumes trading, but what’s more worth watching is this: the L-BTC reserve coverage ratio is only 85%. This means that, based on current data estimates, for every 100 L-BTC there are roughly only 85 BTC reserves backing it—there is an approximately 15% coverage gap. Trading resumption only indicates that the market has started repricing again; it does not mean the pegged-risk has been fully eliminated. $BTC Going forward, focus on three things: whether the reserves can be replenished back to 100% as quickly as possible, whether the team discloses verifiable reserve addresses, and whether the L-BTC price and redemption depth continue to deviate. Until coverage is fully repaired, it’s not advisable to simply treat it as risk-free equivalent Bitcoin—be sure to manage position sizing and slippage. #Liquid #比特币 #加密安全
Liquid resumes trading, but what’s more worth watching is this: the L-BTC reserve coverage ratio is only 85%.

This means that, based on current data estimates, for every 100 L-BTC there are roughly only 85 BTC reserves backing it—there is an approximately 15% coverage gap. Trading resumption only indicates that the market has started repricing again; it does not mean the pegged-risk has been fully eliminated. $BTC

Going forward, focus on three things: whether the reserves can be replenished back to 100% as quickly as possible, whether the team discloses verifiable reserve addresses, and whether the L-BTC price and redemption depth continue to deviate. Until coverage is fully repaired, it’s not advisable to simply treat it as risk-free equivalent Bitcoin—be sure to manage position sizing and slippage.

#Liquid #比特币 #加密安全
Liquid resumes trading, but this does not mean that the risks have been fully eliminated. Data shows that L-BTC’s reserve coverage is only about 85%, meaning that some L-BTC currently in circulation is not yet supported by BTC reserves on a 1:1 basis, leaving an approximate 15% coverage gap. “Can trade” and “fully backed” are two different things. After trading resumes, the price may rebound—or it may swing sharply due to insufficient reserves, redemption expectations, or changes in market confidence. If the coverage ratio cannot be restored in time, risks such as discounting, tight liquidity, and delayed redemptions still need to be watched. It is advisable to stay cautious, manage position sizes, and focus on official updates on reserves, audit progress, and redemption arrangements. Don’t blindly chase in just because trading has resumed. #Bitcoin #Liquid
Liquid resumes trading, but this does not mean that the risks have been fully eliminated. Data shows that L-BTC’s reserve coverage is only about 85%, meaning that some L-BTC currently in circulation is not yet supported by BTC reserves on a 1:1 basis, leaving an approximate 15% coverage gap.

“Can trade” and “fully backed” are two different things. After trading resumes, the price may rebound—or it may swing sharply due to insufficient reserves, redemption expectations, or changes in market confidence. If the coverage ratio cannot be restored in time, risks such as discounting, tight liquidity, and delayed redemptions still need to be watched.

It is advisable to stay cautious, manage position sizes, and focus on official updates on reserves, audit progress, and redemption arrangements. Don’t blindly chase in just because trading has resumed.

#Bitcoin #Liquid
·
--
Bullish
🚨⚠️🚨 LIQUID VOLUME CREATED A PRODUCER BLOCKS AFTER EXPLOIT THAT TOOK 4.000 BTC FROM THE FEDERATION WALLET $BTC ⋙ 𝗠𝗔𝗦𝗦 𝗖𝗥𝗜𝗦𝗘 𝗔𝗜𝗡𝗗𝗔 𝗡𝗔̃𝗢 𝗔𝗖𝗔𝗕𝗢𝗨⛔ ˗ˋˏ🔔ˎˊ˗ A Liquid Network, a Bitcoin sidechain created by Blockstream, began a controlled resumption after an exploit that removed 4,000 BTC from the federation wallet » About US$ 309 million based on the exchange rate quoted in the report. 🔥 The network started producing blocks again on September 10, four days after the incident. But pay attention: This doesn’t mean normal operation. Common transactions are still frozen, and the peg-in and peg-out mechanisms between BTC and L-BTC remain suspended while the reserve is rebuilt. For now, blocks are being produced without transactions, with monitoring for stability. The Person Responsible for the Attack Presented Himself as a White-Hat and has already returned approximately: 4,000 BTC taken → 3,400 BTC returned → almost 600 BTC still held Now, he is pressuring Blockstream for a 10% bug bounty. 👀 And another explosive point has emerged. In a message from the attacker himself, Blockstream is said to have allocated around US$ 1.5 million for security for an infrastructure with approximately US$ 5 billion in assets. This is the attacker’s claim, not an independent audit. Adam Back stated that L-BTC will continue to be backed 1:1 with Bitcoin, ensuring that users will be able to redeem their assets when the mechanisms are restored. {spot}(DOTUSDT) ⚠️ However, he still hasn’t publicly explained how the near-600 BTC shortfall will be covered if those funds are not returned, nor has he announced a timeline to reopen the pegs. 🔥 The case raises an uncomfortable question: in an infrastructure with billions of dollars, can it rely on security that is too small for the size of the risk? 👇 Does the return of 3,400 $BTC restore your confidence in Liquid? #bitcoin #liquid #CryptoNews
🚨⚠️🚨 LIQUID VOLUME CREATED A PRODUCER BLOCKS AFTER EXPLOIT THAT TOOK 4.000 BTC FROM THE FEDERATION WALLET $BTC ⋙ 𝗠𝗔𝗦𝗦 𝗖𝗥𝗜𝗦𝗘 𝗔𝗜𝗡𝗗𝗔 𝗡𝗔̃𝗢 𝗔𝗖𝗔𝗕𝗢𝗨⛔

˗ˋˏ🔔ˎˊ˗ A Liquid Network, a Bitcoin sidechain created by Blockstream, began a controlled resumption after an exploit that removed 4,000 BTC from the federation wallet » About US$ 309 million based on the exchange rate quoted in the report.
🔥 The network started producing blocks again on September 10, four days after the incident.
But pay attention: This doesn’t mean normal operation.
Common transactions are still frozen, and the peg-in and peg-out mechanisms between BTC and L-BTC remain suspended while the reserve is rebuilt. For now, blocks are being produced without transactions, with monitoring for stability.

The Person Responsible for the Attack Presented Himself as a White-Hat and has already returned approximately:
4,000 BTC taken
→ 3,400 BTC returned
→ almost 600 BTC still held
Now, he is pressuring Blockstream for a 10% bug bounty.

👀 And another explosive point has emerged.
In a message from the attacker himself, Blockstream is said to have allocated around US$ 1.5 million for security for an infrastructure with approximately US$ 5 billion in assets. This is the attacker’s claim, not an independent audit.
Adam Back stated that L-BTC will continue to be backed 1:1 with Bitcoin, ensuring that users will be able to redeem their assets when the mechanisms are restored.
⚠️ However, he still hasn’t publicly explained how the near-600 BTC shortfall will be covered if those funds are not returned, nor has he announced a timeline to reopen the pegs.
🔥 The case raises an uncomfortable question:
in an infrastructure with billions of dollars, can it rely on security that is too small for the size of the risk?

👇 Does the return of 3,400 $BTC restore your confidence in Liquid?

#bitcoin #liquid #CryptoNews
A Serious Blow to the Liquid Network In early September, around 4,000 $BTC left the Liquid federation (Blockstream’s Bitcoin sidechain)—about $320 million. Imagine the scale: hundreds of millions of dollars simply vanished from reserves. Later, most of it—around 3,400 BTC—was returned. It was returned by people who called themselves white-hat hackers. But approximately 600 BTC still remain unrecovered. For a time, the network halted operations; exchanges began limiting deposits and withdrawals of L-BTC. It’s important to understand: this was not a hack of Bitcoin itself. The issue occurred specifically at the Liquid federation level—within reserve management and multi-signature controls. Stories like this once again show how fragile even vetted solutions can be when it comes to custody and trust. What do you think about sidechains after news like this? Did you become more cautious? $BTC {future}(BTCUSDT) #liquid
A Serious Blow to the Liquid Network
In early September, around 4,000 $BTC left the Liquid federation (Blockstream’s Bitcoin sidechain)—about $320 million.
Imagine the scale: hundreds of millions of dollars simply vanished from reserves.
Later, most of it—around 3,400 BTC—was returned. It was returned by people who called themselves white-hat hackers. But approximately 600 BTC still remain unrecovered.
For a time, the network halted operations; exchanges began limiting deposits and withdrawals of L-BTC.
It’s important to understand: this was not a hack of Bitcoin itself. The issue occurred specifically at the Liquid federation level—within reserve management and multi-signature controls.
Stories like this once again show how fragile even vetted solutions can be when it comes to custody and trust.
What do you think about sidechains after news like this? Did you become more cautious? $BTC
#liquid
598.5 BTC is still out there; block production is back, but the peg is still stalled This is the Liquid federated sidechain. Block production has resumed, but transactions and the peg (including PAK withdrawals) are still stuck; Adam Back publicly said that LBTC is backed 1:1, and that the restoration of reserves is still ongoing. About 598.5 BTC remains outside. My position: treat it as sidechain/federation custody risk—don’t mix it up with the Bitcoin main chain. Block production resuming does not mean withdrawals are restored; until the peg is officially announced as restored, don’t treat the story as closed. Do you trust the “1:1 backing, all the way through” claim, or should we wait for an official peg announcement before drawing conclusions? Personal observations only; not investment advice. $BTC #安全 #Liquid
598.5 BTC is still out there; block production is back, but the peg is still stalled

This is the Liquid federated sidechain. Block production has resumed, but transactions and the peg (including PAK withdrawals) are still stuck; Adam Back publicly said that LBTC is backed 1:1, and that the restoration of reserves is still ongoing. About 598.5 BTC remains outside.

My position: treat it as sidechain/federation custody risk—don’t mix it up with the Bitcoin main chain. Block production resuming does not mean withdrawals are restored; until the peg is officially announced as restored, don’t treat the story as closed.

Do you trust the “1:1 backing, all the way through” claim, or should we wait for an official peg announcement before drawing conclusions?
Personal observations only; not investment advice.

$BTC #安全 #Liquid
Liquid resumes transfers; LBTC cross-chain redemption still not open LBTC’s in-chain transfers have resumed, but you still can’t treat it as restored BTC redemption. For anyone who needs to move funds back to the Bitcoin mainnet, the most important question now isn’t the four words “network restart,” but when the cross-chain redemption channel will truly be opened. On September 10, Liquid first announced a resumption of block production without “trading.” Then the latest announcement clarified that in-chain trading has been restored, but cross-chain outbound BTC is still closed. Today, when you read a block explorer, you can also see that transactions are already included in new blocks. If you only look at the previous announcement, you would carry forward the old status that “trading is still paused” into today. The difference is this: moving LBTC from one Liquid address to another transfers in-chain assets. Redeeming BTC back to the Bitcoin mainnet through the federation channel requires a separate set of actions to release reserves. The former being restored does not automatically open the latter, and it doesn’t guarantee that exchanges synchronize their deposits/withdrawals at the same time. On September 8, what we followed up on was partial BTC return. Now we should update the progress to “in-chain trading restored,” and stop broadly saying “preparing to restart.” But the judgment about whether redemption is available must remain unchanged for now. Repairing and restoring operations is real progress—shouldn’t be ignored—yet it also shouldn’t be expanded into a claim that funds can already move in and out freely. According to the latest official announcement, ordinary users currently do not need to take any action; only those running a Liquid node need to update to Elements v23.3.4. Don’t use so-called “unlock” websites to transfer assets or submit seed phrases because of an “urgent recovery” email. Over the next 24–48 hours, I will verify the cross-chain outbound resumption announcements, the reserve restoration notes, and actual redemption records. If these pieces of evidence mutually confirm, I will further lower redemption risk. If redemption still can’t be completed after opening is announced, or if a new abnormal outflow appears, I will raise the alert level. If you need mainnet BTC funds in the short term, you should avoid adding new deposits into Liquid until the channel’s usability is confirmed. #Liquid #LBTC #资产安全
Liquid resumes transfers; LBTC cross-chain redemption still not open

LBTC’s in-chain transfers have resumed, but you still can’t treat it as restored BTC redemption. For anyone who needs to move funds back to the Bitcoin mainnet, the most important question now isn’t the four words “network restart,” but when the cross-chain redemption channel will truly be opened.

On September 10, Liquid first announced a resumption of block production without “trading.” Then the latest announcement clarified that in-chain trading has been restored, but cross-chain outbound BTC is still closed. Today, when you read a block explorer, you can also see that transactions are already included in new blocks. If you only look at the previous announcement, you would carry forward the old status that “trading is still paused” into today.

The difference is this: moving LBTC from one Liquid address to another transfers in-chain assets. Redeeming BTC back to the Bitcoin mainnet through the federation channel requires a separate set of actions to release reserves. The former being restored does not automatically open the latter, and it doesn’t guarantee that exchanges synchronize their deposits/withdrawals at the same time.

On September 8, what we followed up on was partial BTC return. Now we should update the progress to “in-chain trading restored,” and stop broadly saying “preparing to restart.” But the judgment about whether redemption is available must remain unchanged for now. Repairing and restoring operations is real progress—shouldn’t be ignored—yet it also shouldn’t be expanded into a claim that funds can already move in and out freely.

According to the latest official announcement, ordinary users currently do not need to take any action; only those running a Liquid node need to update to Elements v23.3.4. Don’t use so-called “unlock” websites to transfer assets or submit seed phrases because of an “urgent recovery” email.

Over the next 24–48 hours, I will verify the cross-chain outbound resumption announcements, the reserve restoration notes, and actual redemption records. If these pieces of evidence mutually confirm, I will further lower redemption risk. If redemption still can’t be completed after opening is announced, or if a new abnormal outflow appears, I will raise the alert level. If you need mainnet BTC funds in the short term, you should avoid adding new deposits into Liquid until the channel’s usability is confirmed.

#Liquid #LBTC #资产安全
Liquid Network reserves shortfall confirmed. Audit panel shows 3,626.8 BTC supporting 4,229 LBTC, with a solvency ratio of only 85.75%. The missing 602.5 BTC matches almost exactly the amount the attacker walked off with. Don’t panic—this isn’t insolvency; it’s a missing hole that wasn’t plugged after the theft. LBTC is basically an IOU note now; whoever holds it knows what’s going on. The bridge’s trust costs ultimately end up on the holders. $BTC #Liquid
Liquid Network reserves shortfall confirmed. Audit panel shows 3,626.8 BTC supporting 4,229 LBTC, with a solvency ratio of only 85.75%. The missing 602.5 BTC matches almost exactly the amount the attacker walked off with.

Don’t panic—this isn’t insolvency; it’s a missing hole that wasn’t plugged after the theft. LBTC is basically an IOU note now; whoever holds it knows what’s going on. The bridge’s trust costs ultimately end up on the holders.

$BTC #Liquid
Liquid Network restores block production after $320 million exploit - Liquid Network has restarted block production after deploying an emergency software update. - However, transactions and peg-related activity remain temporarily suspended while recovery efforts continue. - Damage from the exploit is estimated at $320 million. #BinanceSquare #CryptoNews #Liquid #BTC $btc #vlikevn Titanbot Source: CoinTelegraph
Liquid Network restores block production after $320 million exploit

- Liquid Network has restarted block production after deploying an emergency software update.
- However, transactions and peg-related activity remain temporarily suspended while recovery efforts continue.
- Damage from the exploit is estimated at $320 million.
#BinanceSquare #CryptoNews #Liquid #BTC

$btc

#vlikevn Titanbot

Source: CoinTelegraph
Liquid 被抽走近 4000 枚 BTC——但链上的"不对劲",比新闻早 On September 6, the Bitcoin sidechain Liquid had nearly 4,000 BTC (about $320 million) withdrawn; at one point, its reserves dropped to just 5%. Many people’s first reaction was, "Hackers are dumping the market." In fact, the chain had already been flashing red long before the news. What you really should watch isn’t "how much was stolen," but on-chain indicators such as the reserve balance, abnormal minting, and large withdrawals. The root cause this time was a verification vulnerability in Elements (range proof caching reuse), which allowed L-BTC without real BTC backing to be minted out of thin air, then transferred through the normal withdrawal flow to be exchanged for real coins. The money followed a "compliant" path, but the on-chain data—reserve plummeting, abnormal mints, and large-scale movements—was already visible at the front end. I built this kind of monitoring into a system before (balance/abnormal transactions/threshold-based automatic alerts), aiming to surface "anomalies" to people before they hit the trending headlines. My assessment: this has no material impact on the BTC mainnet. The risk is concentrated in the redemption of L-BTC and the trust assumptions for the sidechain. So in the short term it’s just an emotional disturbance—don’t panic. The real focus is these three signals: "reserves recovering + patch deployment + where the remaining 598 BTC goes." Until things are clear, I won’t touch L-BTC. Do you normally watch for on-chain anomalies? Let’s discuss in the comments. #Liquid #链上监控 #数据 #量化 #数据控
Liquid 被抽走近 4000 枚 BTC——但链上的"不对劲",比新闻早

On September 6, the Bitcoin sidechain Liquid had nearly 4,000 BTC (about $320 million) withdrawn; at one point, its reserves dropped to just 5%. Many people’s first reaction was, "Hackers are dumping the market." In fact, the chain had already been flashing red long before the news.

What you really should watch isn’t "how much was stolen," but on-chain indicators such as the reserve balance, abnormal minting, and large withdrawals. The root cause this time was a verification vulnerability in Elements (range proof caching reuse), which allowed L-BTC without real BTC backing to be minted out of thin air, then transferred through the normal withdrawal flow to be exchanged for real coins. The money followed a "compliant" path, but the on-chain data—reserve plummeting, abnormal mints, and large-scale movements—was already visible at the front end.

I built this kind of monitoring into a system before (balance/abnormal transactions/threshold-based automatic alerts), aiming to surface "anomalies" to people before they hit the trending headlines.

My assessment: this has no material impact on the BTC mainnet. The risk is concentrated in the redemption of L-BTC and the trust assumptions for the sidechain. So in the short term it’s just an emotional disturbance—don’t panic. The real focus is these three signals: "reserves recovering + patch deployment + where the remaining 598 BTC goes." Until things are clear, I won’t touch L-BTC.

Do you normally watch for on-chain anomalies? Let’s discuss in the comments.
#Liquid #链上监控 #数据 #量化 #数据控
Liquid was hacked, with about 4,000 BTC stolen. Of this, 3,400 has been returned, but 600 BTC (about $47 million) is still unaccounted for. The hackers claim they are "white hats," but the claim is doubtful, and Blockstream is negotiating. In the short term, the BTC price may face downward pressure, but most of the BTC has been recovered or has helped reduce market panic. As a Bitcoin sidechain, this incident with Liquid could affect users’ trust in sidechains, and in the future funds may be more inclined toward the main chain. #Bitcoin #Liquid
Liquid was hacked, with about 4,000 BTC stolen. Of this, 3,400 has been returned, but 600 BTC (about $47 million) is still unaccounted for. The hackers claim they are "white hats," but the claim is doubtful, and Blockstream is negotiating. In the short term, the BTC price may face downward pressure, but most of the BTC has been recovered or has helped reduce market panic. As a Bitcoin sidechain, this incident with Liquid could affect users’ trust in sidechains, and in the future funds may be more inclined toward the main chain. #Bitcoin #Liquid
Liquid was torn open with a huge hole—almost 4,000 BTC are gone Over the weekend, the Liquid network was breached; 4,000 BTC—about $320 million—were basically wiped out. This is roughly 95% of their household savings. They claim it was a white-hat hacker, specifically naming Blockstream and demanding they patch the issue. After the patch was applied, they did manage to return 85%, with 3,400 BTC taken into safekeeping. The remaining 598 BTC is still being held by the other party, and the bridge has been frozen. Now the most panicked thing is L-BTC. It relies on a 1:1 peg to Bitcoin to make a living. If the hole can’t be patched, it will have to break the peg. This is another domino effect of Bitcoin L2s: just as Bitcoin L2s keep exploding, Coldcard has barely finished blowing up, Liquid exploded too—security is really paper-thin. #比特币 #Liquid #安全漏洞
Liquid was torn open with a huge hole—almost 4,000 BTC are gone

Over the weekend, the Liquid network was breached; 4,000 BTC—about $320 million—were basically wiped out. This is roughly 95% of their household savings. They claim it was a white-hat hacker, specifically naming Blockstream and demanding they patch the issue. After the patch was applied, they did manage to return 85%, with 3,400 BTC taken into safekeeping. The remaining 598 BTC is still being held by the other party, and the bridge has been frozen.

Now the most panicked thing is L-BTC. It relies on a 1:1 peg to Bitcoin to make a living. If the hole can’t be patched, it will have to break the peg. This is another domino effect of Bitcoin L2s: just as Bitcoin L2s keep exploding, Coldcard has barely finished blowing up, Liquid exploded too—security is really paper-thin.

#比特币 #Liquid #安全漏洞
🚨BREAKING🚨 White-hat hackers have returned 3,400 BTC to Liquid Network after draining 4,000 BTC worth around $320 million in Sunday's exploit. 💰 Around 598 BTC, worth approximately $47 million, remains outstanding as Blockstream continues talks with the hackers. ⚠️ Liquid Network remains paused while operators implement security fixes, resolve a chain split, and ensure L-BTC is fully backed before restarting. 🔒 Exchanges were asked to freeze L-BTC deposits and withdrawals, while other Liquid assets, including USDT, were not affected. $BTC {future}(BTCUSDT) #BTC☀ #liquid
🚨BREAKING🚨

White-hat hackers have returned 3,400 BTC to Liquid Network after draining 4,000 BTC worth around $320 million in Sunday's exploit.

💰 Around 598 BTC, worth approximately $47 million, remains outstanding as Blockstream continues talks with the hackers.

⚠️ Liquid Network remains paused while operators implement security fixes, resolve a chain split, and ensure L-BTC is fully backed before restarting.

🔒 Exchanges were asked to freeze L-BTC deposits and withdrawals, while other Liquid assets, including USDT, were not affected.

$BTC

#BTC☀ #liquid
Liquid hackers paid back 3,400 BTC—returned to the original address 😳 On Sunday, nearly 4,000 BTC were siphoned from Liquid’s sidechain. Now they’ve recovered 85%. Based on current prices, this repayment is worth about $270 million. Let’s recap: on Sunday, the hacker pulled roughly 4,000 BTC from the Liquid Federation wallet. Liquid had only about 4,200 BTC in reserve—almost completely drained, and the network effectively shut down on the spot. At the time, the other party claimed to be a white-hat, saying that once the vulnerability was fixed, they would return the funds. Turns out it wasn’t just talk. Blockstream first patched the vulnerability on the affected nodes, then used a Bitcoin on-chain signed message to reach out and address the attacker. On-chain records show the full 3,400 BTC were transferred back to the Federation wallet without a single coin missing. There are still 598 BTC left to be repaid—about $47 million—so both sides are still at odds. Here’s the interesting part: Ledger’s CTO, the head of the hardware wallet giant, directly fired back. He said they kept nearly 600 BTC as a “compensation for the trouble.” That move doesn’t really look like a white-hat—more like coercive extortion. White-hat or gray-hat—on-chain, it’s just one thin sheet of paper. As for Liquid: the network remains paused. The official advisory says not to send funds to the deposit addresses yet. Wait until the restart is confirmed before doing anything—don’t be the one who ends up holding the bag. This incident is a pretty solid reminder for us. Sidechains and cross-chain bridges—these “high-end” channels. When something goes wrong, it can become a massive hole. Big players’ assets can be siphoned—what about ordinary users’ wallets? Don’t put all your eggs in one basket. That old saying still applies on-chain. Every day I bring you the latest BTC headlines—not just what happened, but also the logic and opportunities behind it 👀🚀 Click the link below to follow me 👇🏻 [👉 加入小恐龙粉丝群](https://app.binance.com/uni-qr/DXaccF5q) #比特币 #Liquid #安全 #Hacker
Liquid hackers paid back 3,400 BTC—returned to the original address 😳
On Sunday, nearly 4,000 BTC were siphoned from Liquid’s sidechain. Now they’ve recovered 85%.
Based on current prices, this repayment is worth about $270 million.

Let’s recap: on Sunday, the hacker pulled roughly 4,000 BTC from the Liquid Federation wallet.
Liquid had only about 4,200 BTC in reserve—almost completely drained, and the network effectively shut down on the spot.
At the time, the other party claimed to be a white-hat, saying that once the vulnerability was fixed, they would return the funds.

Turns out it wasn’t just talk.
Blockstream first patched the vulnerability on the affected nodes, then used a Bitcoin on-chain signed message to reach out and address the attacker.
On-chain records show the full 3,400 BTC were transferred back to the Federation wallet without a single coin missing.
There are still 598 BTC left to be repaid—about $47 million—so both sides are still at odds.

Here’s the interesting part: Ledger’s CTO, the head of the hardware wallet giant, directly fired back.
He said they kept nearly 600 BTC as a “compensation for the trouble.” That move doesn’t really look like a white-hat—more like coercive extortion.
White-hat or gray-hat—on-chain, it’s just one thin sheet of paper.

As for Liquid: the network remains paused. The official advisory says not to send funds to the deposit addresses yet.
Wait until the restart is confirmed before doing anything—don’t be the one who ends up holding the bag.

This incident is a pretty solid reminder for us.
Sidechains and cross-chain bridges—these “high-end” channels. When something goes wrong, it can become a massive hole.
Big players’ assets can be siphoned—what about ordinary users’ wallets?
Don’t put all your eggs in one basket. That old saying still applies on-chain.

Every day I bring you the latest BTC headlines—not just what happened, but also the logic and opportunities behind it 👀🚀
Click the link below to follow me 👇🏻
👉 加入小恐龙粉丝群
#比特币 #Liquid #安全 #Hacker
瑞见未来:
退回3400枚BTC这剧情太魔幻了,侧链漏洞我是真看不懂,现在大头放冷钱包小头交给托管代跑,闲下来可以看看 他的帖子
4000 BTC withdrawn, 3400 returned The incident occurred on Liquid’s sidechain. After about 4000 BTC was withdrawn, the “white hat” returned roughly 3400 BTC (news reports put it at about $270 million), but is still owed about 598 BTC; the network is preparing to restart. Cointelegraph 9/8: Samson Mow’s retelling is that it was returned only after a patch was applied. Ledger CTO and others have questioned the white-hat narrative, suggesting it sounds more like a bounty discussion. My stance: treat sidechain/federated custody risk as its own matter—don’t mix it up with the Bitcoin main chain. Until the outstanding balance is settled and the patch can be verified, don’t let this story become the “closing statement”; if the debt remains outstanding, consider it under unresolved/unfinished conditions and the associated risks. Sidechain risk is sidechain risk; main-chain risk is separate. Which do you believe more: “white hat returns after the patch,” or “talking about a bounty and only then returning coins”? Personal observation only; not investment advice. $BTC #安全 #Liquid Draft reviewed: passed
4000 BTC withdrawn, 3400 returned

The incident occurred on Liquid’s sidechain. After about 4000 BTC was withdrawn, the “white hat” returned roughly 3400 BTC (news reports put it at about $270 million), but is still owed about 598 BTC; the network is preparing to restart.

Cointelegraph 9/8: Samson Mow’s retelling is that it was returned only after a patch was applied. Ledger CTO and others have questioned the white-hat narrative, suggesting it sounds more like a bounty discussion.

My stance: treat sidechain/federated custody risk as its own matter—don’t mix it up with the Bitcoin main chain. Until the outstanding balance is settled and the patch can be verified, don’t let this story become the “closing statement”; if the debt remains outstanding, consider it under unresolved/unfinished conditions and the associated risks. Sidechain risk is sidechain risk; main-chain risk is separate.

Which do you believe more: “white hat returns after the patch,” or “talking about a bounty and only then returning coins”?

Personal observation only; not investment advice.

$BTC #安全 #Liquid

Draft reviewed: passed
A key turning point has emerged in the Bitcoin sidechain Liquid Network fund incident. After about 4,000 units of $BTC reportedly flowed abnormally out of a federation wallet earlier, the self-claimed white-hat party has returned 3,400 $BTC to the Liquid Federation—about 85% of the amount involved. The main funds have already been returned to the federation address. Only after Blockstream confirmed via an on-chain signed message that the bridge node had completed repairs did the other party complete this repayment. There are still about 598.5 units of $BTC left at the relevant address. Many external interpretations view this as a self-assigned “bounty,” but there is no publicly visible agreement between the two parties, and no official final position has been issued yet regarding how the remaining gap will be handled. At present, Liquid bridge connectivity and L-BTC deposits/withdrawals remain paused, and the timeline for a full resumption has not been announced. Whether the sidechain reserves will be realigned, how the remaining funds will be handled, and when exchanges will reopen the relevant channels are the key points to watch over the coming days. #比特币 #Liquid #区块链安全 This does not constitute investment advice
A key turning point has emerged in the Bitcoin sidechain Liquid Network fund incident. After about 4,000 units of $BTC reportedly flowed abnormally out of a federation wallet earlier, the self-claimed white-hat party has returned 3,400 $BTC to the Liquid Federation—about 85% of the amount involved. The main funds have already been returned to the federation address.

Only after Blockstream confirmed via an on-chain signed message that the bridge node had completed repairs did the other party complete this repayment. There are still about 598.5 units of $BTC left at the relevant address. Many external interpretations view this as a self-assigned “bounty,” but there is no publicly visible agreement between the two parties, and no official final position has been issued yet regarding how the remaining gap will be handled.

At present, Liquid bridge connectivity and L-BTC deposits/withdrawals remain paused, and the timeline for a full resumption has not been announced. Whether the sidechain reserves will be realigned, how the remaining funds will be handled, and when exchanges will reopen the relevant channels are the key points to watch over the coming days.

#比特币 #Liquid #区块链安全
This does not constitute investment advice
Liquid drained of 95% reserves; the hacker only agreed to return 85% On September 6, the Liquid network disclosed an Elements consensus and asset verification vulnerability. The attacker minted about 4,000 L-BTC tokens with no real underlying assets, then went through SideSwap’s normal redemption process to swap these “air L-BTC” into 3,996.01834922 genuine BTC, taking them directly from the Liquid Federation. At the time, the value was about $320 million; the reserve balance dropped from roughly 4,207 BTC to around 197 BTC—draining 95%. The Bitcoin mainnet itself was not compromised. Of the Federation’s 11/15 signing members, those who were supposed to sign did sign—so the signature mechanism was functioning normally. The issue was entirely in Liquid’s sidechain Elements validation logic. SideSwap also stated that its PAK system was not breached; it was only used as a normal redemption channel. Other assets such as USDT were unaffected because they are never backed by that peg wallet. However, the network’s pause mechanism still froze the entire transfer and liquidity. As for what happened next: the attacker used an on-chain OP_RETURN message to claim they were a white-hat, demanding that the vulnerability be fixed before returning the funds. The two sides negotiated across the blockchain for several rounds. On September 7, the attacker returned 3,400 BTC, keeping 598.5 BTC—worth about $47 million at the time—as an effective “finder’s fee.” That ratio was no longer up for discussion; in the end, the attacker only returned a sad emoji. This kind of “hack you, then voluntarily negotiate part of the return” is no longer new in DeFi and cross-chain over the past couple of years. But the larger the amounts involved each time, the weaker the deterrent effect of this “post-hack protection fee” approach on the whole industry becomes—if the cost of a vulnerability is always “return the bulk, keep a substantial split,” does that count as effectively encouraging more people to go looking for bugs? #Liquid #Blockstream #BTC #侧链安全 #白帽黑客
Liquid drained of 95% reserves; the hacker only agreed to return 85%

On September 6, the Liquid network disclosed an Elements consensus and asset verification vulnerability. The attacker minted about 4,000 L-BTC tokens with no real underlying assets, then went through SideSwap’s normal redemption process to swap these “air L-BTC” into 3,996.01834922 genuine BTC, taking them directly from the Liquid Federation. At the time, the value was about $320 million; the reserve balance dropped from roughly 4,207 BTC to around 197 BTC—draining 95%.

The Bitcoin mainnet itself was not compromised. Of the Federation’s 11/15 signing members, those who were supposed to sign did sign—so the signature mechanism was functioning normally. The issue was entirely in Liquid’s sidechain Elements validation logic. SideSwap also stated that its PAK system was not breached; it was only used as a normal redemption channel. Other assets such as USDT were unaffected because they are never backed by that peg wallet. However, the network’s pause mechanism still froze the entire transfer and liquidity.

As for what happened next: the attacker used an on-chain OP_RETURN message to claim they were a white-hat, demanding that the vulnerability be fixed before returning the funds. The two sides negotiated across the blockchain for several rounds. On September 7, the attacker returned 3,400 BTC, keeping 598.5 BTC—worth about $47 million at the time—as an effective “finder’s fee.” That ratio was no longer up for discussion; in the end, the attacker only returned a sad emoji.

This kind of “hack you, then voluntarily negotiate part of the return” is no longer new in DeFi and cross-chain over the past couple of years. But the larger the amounts involved each time, the weaker the deterrent effect of this “post-hack protection fee” approach on the whole industry becomes—if the cost of a vulnerability is always “return the bulk, keep a substantial split,” does that count as effectively encouraging more people to go looking for bugs?

#Liquid #Blockstream #BTC #侧链安全 #白帽黑客
·
--
🎯 A bombshell worth $320 million in chain exploits—institutions moved in and stepped on another landmine 📰 Liquid network shocks with a staggering new vulnerability report. Even though it’s supposedly tied to Bitcoin, it still got hacked—$320 million is simply gone. Just when institutions were about to nod in approval, they were hit with a bucket of cold water 💬 In the end, the heavier the on-chain footprint, the more it tests security. What we fear most is a “looks reliable” custodial loophole. Don’t overthink short-term market jitters into a systemic collapse; in the long run, stay clear-headed and watch risk controls 🏷️ #比特币安全 #Liquid #黑客 #托管风险 #institutional entry
🎯 A bombshell worth $320 million in chain exploits—institutions moved in and stepped on another landmine

📰 Liquid network shocks with a staggering new vulnerability report. Even though it’s supposedly tied to Bitcoin, it still got hacked—$320 million is simply gone. Just when institutions were about to nod in approval, they were hit with a bucket of cold water

💬 In the end, the heavier the on-chain footprint, the more it tests security. What we fear most is a “looks reliable” custodial loophole. Don’t overthink short-term market jitters into a systemic collapse; in the long run, stay clear-headed and watch risk controls

🏷️ #比特币安全 #Liquid #黑客 #托管风险 #institutional entry
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number