安全客September 8, 2026🇨🇳Translated from Chinese

Liquid Network Federation Wallet Drained of 4000 BTC in Alleged White-Hat Exploit Exposing L-BTC Minting Flaw

On September 7, the Liquid Network Bitcoin sidechain was hit by an attack that drained its Federation wallet of roughly 4000 Bitcoin, valued at approximately $320 million or 2.1 billion RMB, leaving only about 200 BTC in reserves. This represented a 95% loss of the network's backing assets overnight.

The incident was first noticed through an official post on X confirming that the Liquid Federation wallet had been compromised. Funds were transferred out via the authorized SideSwap settlement platform, yet Liquid emphasized that SideSwap keys remained secure and that the PAK (Pegin Authorization Key) itself was not leaked.

Security researchers, including FailSafe CEO Aneirin Flynn, identified preliminary evidence pointing to a vulnerability that permitted unauthorized minting of L-BTC. In the Liquid Network model, L-BTC is issued 1:1 against locked Bitcoin held in the federation wallet; any flaw allowing free minting of L-BTC effectively lets an attacker exchange phantom assets for real Bitcoin.

Officials described the perpetrator as a claimed white-hat hacker who allegedly planned to return the funds in exchange for a fee. This narrative echoes past cases such as the 2021 Poly Network incident, where $610 million was moved and later largely returned, though many similar events end with permanent loss.

The attack has forced Liquid to suspend all new transactions while federation members, including major exchanges BTSE, Bitfinex, and BitMEX, work on remediation. The event highlights a shift in 2026 crypto threats from stealing private keys to compromising asset-issuance and consensus logic, evidenced by the recent Coldcard random-number-generation flaw that enabled theft of over 1755 BTC.

Industry data for the first half of 2026 already records $972 million stolen across 207 incidents, marking a record half-year high. Experts warn that the Liquid case exposes fatal gaps in verification mechanisms and multi-signature federation controls that traditional audits often overlook.

Related articles

安全客Crypto & Financial Crime

1755 Bitcoin Worth $110 Million Stolen from 5000 Hardware Cold Wallets Due to Flawed Random Number Generator

A mainstream hardware cold wallet suffered a systemic defect in its random number generation algorithm, allowing attackers to compromise approximately 5000 wallets and steal 1755 BTC valued at around $110 million. The incident, confirmed on August 4, marks the largest hardware wallet security breach in crypto history because the flaw existed at the foundational level of private key generation rather than in network defenses. Victims had relied on the common assumption that offline cold storage provides ultimate protection, yet the non-random RNG reduced the effective keyspace dramatically, enabling feasible brute-force attacks. Historical precedents show similar RNG weaknesses have repeatedly undermined wallet security across platforms including Android implementations and various hardware chips. The event underscores that cold storage security depends entirely on correct implementation of cryptographic primitives at every layer, from hardware entropy sources to firmware. Experts recommend avoiding blind trust in any single device, verifying third-party audits, and diversifying storage across multiple solutions including open-source options.

HabrCrypto & Financial Crime

COLDCARD Wallets Suffer Mass Crypto Theft After RNG Flaw Allows Seed Reconstruction

A critical implementation error in COLDCARD hardware wallets enabled attackers to reconstruct wallet seeds and steal cryptocurrency from thousands of users. The flaw stemmed from an incorrect switch to the libsecp256k1 library, which inadvertently used the rng_get() function from libNgU for seed generation instead of proper hardware entropy. Depending on the model, seeds for Mk2 and Mk3 devices could be derived solely from UID, timer state, and generator history, while Mk4, Mk5, and Q models added limited extra entropy. On July 30, the attacker drained over 1,367 BTC worth approximately $88 million from 4,585 addresses in just 41 minutes. Coinkite released updated firmware, but affected users must also regenerate new seeds and consider additional protections such as passphrases. Other Coinkite products including TAPSIGNER, OPENDIME, and SATSCARD remain unaffected. The incident highlights how even well-tested cryptographic libraries can fail when integrated incorrectly.

HispasecCrypto & Financial Crime

Coldcard Firmware Flaw Linked to Theft of 1,082 Bitcoin in 41 Minutes

A critical defect in COLDCARD firmware degraded entropy during BIP39 seed generation, enabling offline enumeration of weak seeds and resulting in the theft of 1,082.65 BTC from 1,196 addresses in just 41 minutes on July 30, 2026. The root cause traces to a March 2021 integration error that replaced the STM32 hardware RNG with a deterministic software PRNG initialized only by chip ID and timing registers, yielding roughly 40 bits of effective entropy on Mk3 devices and 72 bits on Mk4, Mk5, and Q models. Coinkite issued emergency firmware updates, yet any seed created on vulnerable versions remains exposed regardless of later updates. Additional sweeps matching the same pattern have raised total observed losses to 1,367.05 BTC across 4,585 addresses. Users must generate fresh seeds on patched firmware and migrate funds immediately; dice-based entropy addition or BIP39 passphrases provide only partial mitigation.