Binance Square
John_BNB
972 Posts

John_BNB

I’m John, Binance Angel from Cambodia 🇰🇭 Active in trading, P2P, Web3 farming & community building.
Binance Square Angels
Binance Square Angels
Open Trade
Frequent Trader
8.8 Years
233 Following
4.4K+ Followers
4.0K+ Liked
1 Badges
Posts
Portfolio
🎙️ 📖 Day 2 is calling. Yesterday: 21 pages down. Tonight: we continue..
cover
End
43 m 36 s
180
0
0
🎙️ Monthly Market Update AMA
avatar
End
01 h 02 m 56 s
693
3
0
·
--
Binance Square Official
·
--
Share & Win Traffic Reward in our Trending Hashtag Campaign

✨Topic: Will CPI Trigger Rate Hike?

👉How to Join:
Publish a short post or article with hashtag #CPIWatch
Create content based on the below two angles:
- Nonfarm payrolls beat expectations and CPI is around the corner, do you think the Fed will hike or hold the rate?
- Bullish or bearish? Share your take and showcase your stocks or gold trade/holdings with our trade sharing widget.

🚀Campaign Period:
- 2026-09-11 3:00 - 2026-09-12 9:00 UTC

🎁Reward:
- Qualified posts that comply with the above guidelines and contain more than 100 words will be reviewed and may receive a random traffic boost of 500 to 3,000 views. You will receive a notification from your feed secretary if your post is selected. 
- Get a chance to have your article featured on Binance Square Official

Need ideas for your post? Visit the topic page #CPIWatch or the Square Guide on How to Post for Better Reach.
·
--
Bullish
7 8 9 @Binance_Square_Official 2022 joined Binance meet up as users, hiding my tittle. Joined local group and help countless users to avoid scam in p2p and various phishing. 2024 in loved with Binance angels and applied. And selected, start my 1st support Binance event, travelling with personal budget. 2024 Jul be selected to exclusive SEA angels in Danang, Vietnam 2025 Jun, Aug, Dec be selected again SEA angels TB Hanoi, Coinfest 2025 Bali, and #BBW2025 Dubai. 2026 Aug #BinanceClubhouse Coinfest 2026 Journey begins with #Community #Binance @CZ knows #Binance @Binance_Angels $BNB {spot}(BNBUSDT)
7 8 9 @Binance Square Official

2022 joined Binance meet up as users, hiding my tittle. Joined local group and help countless users to avoid scam in p2p and various phishing.

2024 in loved with Binance angels and applied. And selected, start my 1st support Binance event, travelling with personal budget.

2024 Jul be selected to exclusive SEA angels in Danang, Vietnam

2025 Jun, Aug, Dec be selected again SEA angels TB Hanoi,
Coinfest 2025 Bali, and #BBW2025
Dubai.

2026 Aug
#BinanceClubhouse Coinfest 2026

Journey begins with
#Community #Binance

@CZ knows

#Binance @Binance Angels $BNB
🎙️ 1 Hour with @CZ DAY 1 Freedom of Money
cover
End
44 m 43 s
576
6
0
Imagine the 3B users look like on Binance. Not only crypto, web3 but TradeFi merch to blockchain, Defi, RWA....and much more. Esp payment rail. Thinking of global payment for the whole humanity, which support even $5 US dollar without any fee or delay. It will be huge. Are you ready to welcome them? $BTC $BNB $NVDAB {spot}(NVDABUSDT) {spot}(BNBUSDT) {spot}(BTCUSDT)
Imagine the 3B users look like on Binance.

Not only crypto, web3 but TradeFi merch to blockchain, Defi, RWA....and much more. Esp payment rail. Thinking of global payment for the whole humanity, which support even $5 US dollar without any fee or delay.

It will be huge. Are you ready to welcome them?

$BTC $BNB $NVDAB
2mn to go
2mn to go
Binance Square Official
·
--
[Replay] Tradfi Essential: Gaetano of Crux Capital
50 m 05 s · 5.5k views
Interesting Strategy of Michael Saylor stay at 1st public company of Bitcoin treasuries. And most important is avg price is $75.47K which means he have profit around 4k per coin. $BTC {spot}(BTCUSDT)
Interesting Strategy of Michael Saylor stay at 1st public company of Bitcoin treasuries. And most important is avg price is $75.47K which means he have profit around 4k per coin.

$BTC
Can't imagine $ZEC reach this level. There is always possible in #crypto {spot}(ZECUSDT)
Can't imagine $ZEC reach this level.

There is always possible in #crypto
Binance News
·
--
Bitcoin Recovers to Nearly $78,900 as Grayscale’s Zcash ETF Tops $500 Million
Bitcoin recovered to nearly $78,900 after briefly falling below $78,000, with the asset touching $77,666 during the move. According to NS3.AI, Grayscale said its Zcash ETF has surpassed $500 million in assets two weeks after listing on NYSE Arca.

The fund has also recorded more than $70 million in cumulative inflows since its Aug. 25 debut.
September 2026 Monthly User Survey - Win a share of the total $1,300 USDC We highly value your feedback and opinions, which are essential for helping us improve and develop our money transfer services. Please complete this survey to have a chance to win a share of the total rewards of 1,300 USDC. 🎁 Reward details The first 500 users who complete the form will share a total reward pool of 1,000 USDC. The selected Top 3 users will receive a total of 300 USDC each, with 100 USDC per person. 🗓️ Survey period: 9 September 2026 – 30 September 2026 🔗 Survey link: [ចូលរួមនៅទីនេះ](https://app.binance.com/uni-qr/user-survey/08abcf8b74704455977149d629c24f02) Thank you sincerely for your continued participation and support. $BNB {spot}(BNBUSDT)
September 2026 Monthly User Survey - Win a share of the total $1,300 USDC

We highly value your feedback and opinions, which are essential for helping us improve and develop our money transfer services. Please complete this survey to have a chance to win a share of the total rewards of 1,300 USDC.

🎁 Reward details

The first 500 users who complete the form will share a total reward pool of 1,000 USDC.
The selected Top 3 users will receive a total of 300 USDC each, with 100 USDC per person.

🗓️ Survey period: 9 September 2026 – 30 September 2026
🔗 Survey link: ចូលរួមនៅទីនេះ

Thank you sincerely for your continued participation and support.

$BNB
·
--
Bullish
Article
The $320M Liquid Hack: How a Software Bug Let 4,000 BTC Walk OutNearly 4,000 BTC worth roughly $320 million was drained from Bitcoin sidechain Liquid. But this wasn't a simple private-key hack — and the people holding the Bitcoin now say they want to give most of it back. On September 6, the Liquid Network suffered one of the largest crypto security incidents of 2026. Approximately 4,000 BTC was withdrawn from the Liquid Federation's Bitcoin reserve wallet, worth around $320 million at the time. Liquid subsequently paused bridge activity, while exchanges suspended or prepared to suspend L-BTC deposits and withdrawals. Then the story took an unexpected turn. The attackers identified themselves on-chain as "whitehats" and told Blockstream they would return most of the Bitcoin — but only after the underlying vulnerability was fixed and the network's nodes were patched. At the time of writing, the roughly 4,000 BTC remained under the attackers' control. So what actually happened? This Wasn't a Bitcoin Hack The first important distinction: Bitcoin itself was not hacked. The incident happened on Liquid, a Bitcoin sidechain operated through the Liquid Federation. Liquid's model is built around a two-way peg. Users move BTC into the federation's Bitcoin reserve and receive an equivalent amount of Liquid Bitcoin, or LBTC, on the sidechain. In normal operation: BTC → Liquid Federation → LBTC And when users want to leave Liquid: LBTC → burned → BTC released Liquid's own documentation describes LBTC as being backed 1:1 by Bitcoin held in the Federation's multisignature wallet. The security model is deliberately designed so that the federation doesn't depend on a single private key. The Federation uses an 11-of-15 multisig structure, with keys held by separate functionaries. Peg-outs also use a Peg-out Authorization Key, or PAK, to restrict where Bitcoin can be sent. And yet, approximately 4,000 BTC left the reserve. That is what makes this incident so interesting. The Keys Apparently Weren't Stolen According to Liquid and reporting from SideSwap, the incident did not involve the theft of the federation's signing credentials. Instead, the transaction went through the normal peg-out mechanism. The problem appears to have been somewhere deeper in the software stack. SideSwap said the L-BTC involved in the transaction was created through a bug in Elements, the open-source blockchain software underlying Liquid. In other words, the attacker appears to have exploited a flaw that allowed roughly 4,000 LBTC to exist even though the corresponding Bitcoin had never been deposited into the federation. Those tokens were then presented for redemption. The federation's infrastructure effectively processed the request as a valid peg-out and released real Bitcoin. The result was an extraordinary conversion: Fake/illegitimate LBTC → legitimate peg-out → real BTC The attackers ended up with approximately 3,996 BTC in a Bitcoin address after the transaction. The $320 Million Problem This exposes a fundamental risk in any bridged or wrapped asset system. The security of the bridge is not determined only by how well the underlying Bitcoin is protected. It also depends on whether the system can correctly answer a much simpler question: "Does this token actually exist legitimately?" Liquid's entire peg relies on a 1:1 relationship between LBTC circulating on the sidechain and BTC held by the federation. If software allows an attacker to manufacture LBTC outside that accounting model, the attacker may be able to redeem those artificial tokens for real Bitcoin. The vault can remain secure. The private keys can remain secure. The multisig can remain intact. And the system can still lose hundreds of millions of dollars. That is the critical lesson from this incident. Why Didn't the 11-of-15 Multisig Stop It? At first glance, this seems like exactly the kind of attack that an 11-of-15 multisig should prevent. But multisig protects against unauthorized spending. It does not automatically protect against a transaction that the system itself considers valid. Liquid's documented peg-out process requires the federation's functionaries to verify the peg-out request and then sign the corresponding Bitcoin transaction. If the underlying software incorrectly determines that an LBTC redemption is legitimate, the multisig participants can end up doing precisely what they were designed to do: sign a valid transaction. That distinction is crucial. This wasn't necessarily: "The attacker stole 11 private keys." It was closer to: "The attacker found a way to make the system believe the withdrawal was legitimate." That's a fundamentally different class of vulnerability. Then the Hackers Did Something Strange After moving the Bitcoin, the attackers didn't immediately disappear. Instead, they left an on-chain message identifying themselves as "whitehats" and asking Blockstream to contact them. Blockstream subsequently responded through Bitcoin transactions and encrypted communication. The attackers then reportedly offered to return most of the Bitcoin — with one major condition: Fix the bug first. They wanted confirmation that the vulnerability had been patched across the relevant nodes before returning the funds. Blockstream later sent a signed on-chain message indicating that the bridge nodes had been patched and that the funds could be returned. But the Bitcoin had not yet moved at the time of reporting. So the biggest crypto theft story of the day has, unusually, turned into a negotiation between the protocol developers and the people who exploited it. Liquid Paused the Bridge Following the incident, Liquid disabled bridge nodes and exchanges moved to suspend L-BTC deposits and withdrawals. That makes sense: if the underlying accounting vulnerability isn't fixed, simply returning the stolen BTC doesn't solve the problem. The network needs to establish that the same exploit cannot be repeated. Liquid can continue to exist as a blockchain, but the bridge between Liquid and Bitcoin is the critical point being protected. This distinction matters because Liquid is not Bitcoin. Blockstream's own documentation describes Liquid as a Bitcoin sidechain that operates independently from Bitcoin's base layer. Bitcoin does not depend on Liquid to function. So there is no indication that Bitcoin's consensus mechanism or Bitcoin's underlying proof-of-work was compromised. The failure occurred at the sidechain and peg layer. The Bigger Lesson for Crypto This incident is bigger than Liquid. It is another reminder that crypto infrastructure has multiple layers of security — and protecting one layer doesn't automatically protect the others. You can have: Hardware-secured private keysMultisignature walletsGeographically distributed validatorsWhitelisted withdrawal addressesTimelocks and emergency recovery procedures …and still have a catastrophic failure if the software validating the assets contains a consensus bug. Liquid's architecture actually includes multiple additional safeguards. Its documentation describes an emergency recovery mechanism and timelocks designed to protect federation funds during prolonged network failure. But those protections are primarily designed around different failure scenarios. The lesson is not that multisig doesn't work. The lesson is that multisig cannot compensate for broken validation logic. The Most Interesting Part May Be What Happens Next The Bitcoin is still the central piece of the puzzle. If the attackers genuinely return most of the ~4,000 BTC after the patch, the incident could become an unusual example of a massive white-hat intervention: a vulnerability was exploited for real money, the funds were temporarily secured by the researchers, and the protocol was forced to fix the underlying weakness. But until the Bitcoin actually moves back, it remains a claim — not a completed recovery. And there are still major questions to answer: Exactly which Elements bug enabled the unauthorized LBTC creation? How did the attacker discover it? Why did the federation's validation process accept the resulting peg-out? Could the vulnerability have been exploited earlier? How many nodes and systems were affected? And perhaps most importantly: How much confidence should users place in a bridged asset whose security ultimately depends on software validating a 1:1 backing relationship? The Liquid incident is therefore not simply a story about $320 million being stolen. It is a case study in the difference between protecting keys and protecting the rules those keys are programmed to enforce. And in crypto, sometimes the second problem is the bigger one. #bitcoin #liquidnetwork #CryptoSecurity #BTC $BTC $BNB $ETH {spot}(ETHUSDT) {spot}(BNBUSDT) {spot}(BTCUSDT)

The $320M Liquid Hack: How a Software Bug Let 4,000 BTC Walk Out

Nearly 4,000 BTC worth roughly $320 million was drained from Bitcoin sidechain Liquid. But this wasn't a simple private-key hack — and the people holding the Bitcoin now say they want to give most of it back.
On September 6, the Liquid Network suffered one of the largest crypto security incidents of 2026.
Approximately 4,000 BTC was withdrawn from the Liquid Federation's Bitcoin reserve wallet, worth around $320 million at the time. Liquid subsequently paused bridge activity, while exchanges suspended or prepared to suspend L-BTC deposits and withdrawals.
Then the story took an unexpected turn.
The attackers identified themselves on-chain as "whitehats" and told Blockstream they would return most of the Bitcoin — but only after the underlying vulnerability was fixed and the network's nodes were patched.
At the time of writing, the roughly 4,000 BTC remained under the attackers' control.
So what actually happened?
This Wasn't a Bitcoin Hack
The first important distinction: Bitcoin itself was not hacked.
The incident happened on Liquid, a Bitcoin sidechain operated through the Liquid Federation.
Liquid's model is built around a two-way peg. Users move BTC into the federation's Bitcoin reserve and receive an equivalent amount of Liquid Bitcoin, or LBTC, on the sidechain.
In normal operation:
BTC → Liquid Federation → LBTC
And when users want to leave Liquid:
LBTC → burned → BTC released
Liquid's own documentation describes LBTC as being backed 1:1 by Bitcoin held in the Federation's multisignature wallet.
The security model is deliberately designed so that the federation doesn't depend on a single private key.
The Federation uses an 11-of-15 multisig structure, with keys held by separate functionaries. Peg-outs also use a Peg-out Authorization Key, or PAK, to restrict where Bitcoin can be sent.
And yet, approximately 4,000 BTC left the reserve.
That is what makes this incident so interesting.
The Keys Apparently Weren't Stolen
According to Liquid and reporting from SideSwap, the incident did not involve the theft of the federation's signing credentials.
Instead, the transaction went through the normal peg-out mechanism.
The problem appears to have been somewhere deeper in the software stack.
SideSwap said the L-BTC involved in the transaction was created through a bug in Elements, the open-source blockchain software underlying Liquid.
In other words, the attacker appears to have exploited a flaw that allowed roughly 4,000 LBTC to exist even though the corresponding Bitcoin had never been deposited into the federation.
Those tokens were then presented for redemption.
The federation's infrastructure effectively processed the request as a valid peg-out and released real Bitcoin.
The result was an extraordinary conversion:
Fake/illegitimate LBTC → legitimate peg-out → real BTC
The attackers ended up with approximately 3,996 BTC in a Bitcoin address after the transaction.
The $320 Million Problem
This exposes a fundamental risk in any bridged or wrapped asset system.
The security of the bridge is not determined only by how well the underlying Bitcoin is protected.
It also depends on whether the system can correctly answer a much simpler question:
"Does this token actually exist legitimately?"
Liquid's entire peg relies on a 1:1 relationship between LBTC circulating on the sidechain and BTC held by the federation.
If software allows an attacker to manufacture LBTC outside that accounting model, the attacker may be able to redeem those artificial tokens for real Bitcoin.
The vault can remain secure.
The private keys can remain secure.
The multisig can remain intact.
And the system can still lose hundreds of millions of dollars.
That is the critical lesson from this incident.
Why Didn't the 11-of-15 Multisig Stop It?
At first glance, this seems like exactly the kind of attack that an 11-of-15 multisig should prevent.
But multisig protects against unauthorized spending.
It does not automatically protect against a transaction that the system itself considers valid.
Liquid's documented peg-out process requires the federation's functionaries to verify the peg-out request and then sign the corresponding Bitcoin transaction.
If the underlying software incorrectly determines that an LBTC redemption is legitimate, the multisig participants can end up doing precisely what they were designed to do:
sign a valid transaction.
That distinction is crucial.
This wasn't necessarily:
"The attacker stole 11 private keys."
It was closer to:
"The attacker found a way to make the system believe the withdrawal was legitimate."
That's a fundamentally different class of vulnerability.
Then the Hackers Did Something Strange
After moving the Bitcoin, the attackers didn't immediately disappear.
Instead, they left an on-chain message identifying themselves as "whitehats" and asking Blockstream to contact them.
Blockstream subsequently responded through Bitcoin transactions and encrypted communication.
The attackers then reportedly offered to return most of the Bitcoin — with one major condition:
Fix the bug first.
They wanted confirmation that the vulnerability had been patched across the relevant nodes before returning the funds.
Blockstream later sent a signed on-chain message indicating that the bridge nodes had been patched and that the funds could be returned.
But the Bitcoin had not yet moved at the time of reporting.
So the biggest crypto theft story of the day has, unusually, turned into a negotiation between the protocol developers and the people who exploited it.
Liquid Paused the Bridge
Following the incident, Liquid disabled bridge nodes and exchanges moved to suspend L-BTC deposits and withdrawals.
That makes sense: if the underlying accounting vulnerability isn't fixed, simply returning the stolen BTC doesn't solve the problem.
The network needs to establish that the same exploit cannot be repeated.
Liquid can continue to exist as a blockchain, but the bridge between Liquid and Bitcoin is the critical point being protected.
This distinction matters because Liquid is not Bitcoin.
Blockstream's own documentation describes Liquid as a Bitcoin sidechain that operates independently from Bitcoin's base layer. Bitcoin does not depend on Liquid to function.
So there is no indication that Bitcoin's consensus mechanism or Bitcoin's underlying proof-of-work was compromised.
The failure occurred at the sidechain and peg layer.
The Bigger Lesson for Crypto
This incident is bigger than Liquid.
It is another reminder that crypto infrastructure has multiple layers of security — and protecting one layer doesn't automatically protect the others.
You can have:
Hardware-secured private keysMultisignature walletsGeographically distributed validatorsWhitelisted withdrawal addressesTimelocks and emergency recovery procedures
…and still have a catastrophic failure if the software validating the assets contains a consensus bug.
Liquid's architecture actually includes multiple additional safeguards. Its documentation describes an emergency recovery mechanism and timelocks designed to protect federation funds during prolonged network failure.
But those protections are primarily designed around different failure scenarios.
The lesson is not that multisig doesn't work.
The lesson is that multisig cannot compensate for broken validation logic.
The Most Interesting Part May Be What Happens Next
The Bitcoin is still the central piece of the puzzle.
If the attackers genuinely return most of the ~4,000 BTC after the patch, the incident could become an unusual example of a massive white-hat intervention: a vulnerability was exploited for real money, the funds were temporarily secured by the researchers, and the protocol was forced to fix the underlying weakness.
But until the Bitcoin actually moves back, it remains a claim — not a completed recovery.
And there are still major questions to answer:
Exactly which Elements bug enabled the unauthorized LBTC creation?
How did the attacker discover it?
Why did the federation's validation process accept the resulting peg-out?
Could the vulnerability have been exploited earlier?
How many nodes and systems were affected?
And perhaps most importantly:
How much confidence should users place in a bridged asset whose security ultimately depends on software validating a 1:1 backing relationship?
The Liquid incident is therefore not simply a story about $320 million being stolen.
It is a case study in the difference between protecting keys and protecting the rules those keys are programmed to enforce.
And in crypto, sometimes the second problem is the bigger one.
#bitcoin #liquidnetwork #CryptoSecurity #BTC
$BTC $BNB $ETH
M I dreaming? $ZEC hit 1200 dollar? anyone can tell what's going on? is it a lead of new super cycle? #crypto
M I dreaming? $ZEC hit 1200 dollar?

anyone can tell what's going on?

is it a lead of new super cycle?

#crypto
John_BNB
·
--
Go $ASTER go

@Aster DEX
44 people. One room. So many conversations about the future. ☕️🟡Today, I had the pleasure of hosting a BNB Chain Coffee Chat in Siem Reap, and honestly, this is the kind of community moment I love most. We had 44 solid attendees who stayed engaged and curious throughout the session. What really impressed me was the attention and questions around AI, U.S. stocks, bStocks, and Binance Academy. We talked about how AI is already becoming useful in our daily lives and workloads — not just something we hear about in the news. We also explored how the financial world is changing. A few years ago, owning U.S. stocks from this part of the world could feel complicated. Today, Binance is bringing crypto and traditional financial products closer together, with access to thousands of U.S. stocks and tokenized assets. And education matters just as much. Binance Academy gives people a free online place to learn, earn and build knowledge across different areas of Web3 and finance. For me, this is what community is about. Not just talking about the future online — but sitting together, learning together, asking questions, and helping each other understand it. Big thanks to everyone who joined us in Siem Reap. ❤️ 44 attendees today. Hopefully, many more conversations tomorrow. 🚀 #BNBChainsiemreap #Binance #BinanceAngels #BinanceAcademy #Siemreap @Binance_Square_Official @Binance_Angels
44 people. One room. So many conversations about the future.

☕️🟡Today, I had the pleasure of hosting a BNB Chain Coffee Chat in Siem Reap, and honestly, this is the kind of community moment I love most.

We had 44 solid attendees who stayed engaged and curious throughout the session. What really impressed me was the attention and questions around AI, U.S. stocks, bStocks, and Binance Academy.

We talked about how AI is already becoming useful in our daily lives and workloads — not just something we hear about in the news.
We also explored how the financial world is changing. A few years ago, owning U.S. stocks from this part of the world could feel complicated. Today, Binance is bringing crypto and traditional financial products closer together, with access to thousands of U.S. stocks and tokenized assets.

And education matters just as much.
Binance Academy gives people a free online place to learn, earn and build knowledge across different areas of Web3 and finance.
For me, this is what community is about.
Not just talking about the future online — but sitting together, learning together, asking questions, and helping each other understand it.

Big thanks to everyone who joined us in Siem Reap. ❤️
44 attendees today. Hopefully, many more conversations tomorrow. 🚀
#BNBChainsiemreap #Binance #BinanceAngels #BinanceAcademy #Siemreap
@Binance Square Official @Binance Angels
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number
Sitemap
Cookie Preferences
Platform T&Cs