🚨 THE MOST EXPENSIVE "WHITE HAT" BOUNTY IN HISTORY? 🚨
Liquid Network just got drained of $320 MILLION. And the attacker walked away with $47M for free. 💀
Here's what actually happened — and why this should scare every single person holding wrapped or bridged assets right now. 👇
🔓 The Scariest Part: No private keys were stolen. No multisig was bypassed. The attacker exploited a bug in the Elements software to MINT ~4,000 FAKE L-BTC out of thin air — then cashed them out for REAL Bitcoin through the normal peg-out system .
The federation wallet went from 4,205 $BTC to 197 BTC in 23 minutes. That's 95% of the reserve — GONE .
📅 The Timeline That Should Terrify You:
• Sept 6, 13:53 UTC — Attacker mints 4,000 unbacked L-BTC
• Sept 6, 14:28 UTC — Federation releases 3,996 REAL BTC
• Total elapsed: 35 minutes
The software told every validator the transaction was clean. Every signature was valid. The system worked exactly as designed — except it was designed to be fooled.
💬 Then things got WEIRD:
The attacker left an on-chain message: "we are whitehats. contact us on chain." They demanded Blockstream patch the bug FIRST, then they'd return the funds .
They returned 3,400 BTC — and kept 598.5 BTC (~$47M) for themselves .
🔴 Blockstream's response: "We will not pay a ransom. Taking assets without authorization and withholding their return is a crime, not white-hat activity."
🔴 Ledger CTO's take: "White hats don't drain a bridge and then solicit an 'on-chain' contact." Called it closer to extortion .
⚡ THE REAL LESSON: Bitcoin itself was never hacked. The base layer stayed perfect. The exploit happened in the layer built on top of it — the sidechain, the bridge, the "wrapped" asset .
Every bridge. Every sidechain. Every wrapped token. New functionality = new attack surface.
And this time, someone minted $320 million from nothing— and walked away with $47 million as a "tip."
DYOR. Understand what you're actually trusting. 🎯
#LiquidNetwork #Bitcoin #Blockstream #CryptoSecurity
Liquid Network just got drained of $320 MILLION. And the attacker walked away with $47M for free. 💀
Here's what actually happened — and why this should scare every single person holding wrapped or bridged assets right now. 👇
🔓 The Scariest Part: No private keys were stolen. No multisig was bypassed. The attacker exploited a bug in the Elements software to MINT ~4,000 FAKE L-BTC out of thin air — then cashed them out for REAL Bitcoin through the normal peg-out system .
The federation wallet went from 4,205 $BTC to 197 BTC in 23 minutes. That's 95% of the reserve — GONE .
📅 The Timeline That Should Terrify You:
• Sept 6, 13:53 UTC — Attacker mints 4,000 unbacked L-BTC
• Sept 6, 14:28 UTC — Federation releases 3,996 REAL BTC
• Total elapsed: 35 minutes
The software told every validator the transaction was clean. Every signature was valid. The system worked exactly as designed — except it was designed to be fooled.
💬 Then things got WEIRD:
The attacker left an on-chain message: "we are whitehats. contact us on chain." They demanded Blockstream patch the bug FIRST, then they'd return the funds .
They returned 3,400 BTC — and kept 598.5 BTC (~$47M) for themselves .
🔴 Blockstream's response: "We will not pay a ransom. Taking assets without authorization and withholding their return is a crime, not white-hat activity."
🔴 Ledger CTO's take: "White hats don't drain a bridge and then solicit an 'on-chain' contact." Called it closer to extortion .
⚡ THE REAL LESSON: Bitcoin itself was never hacked. The base layer stayed perfect. The exploit happened in the layer built on top of it — the sidechain, the bridge, the "wrapped" asset .
Every bridge. Every sidechain. Every wrapped token. New functionality = new attack surface.
And this time, someone minted $320 million from nothing— and walked away with $47 million as a "tip."
DYOR. Understand what you're actually trusting. 🎯
#LiquidNetwork #Bitcoin #Blockstream #CryptoSecurity