安全客•September 8, 2026•🇨🇳Translated from Chinese

Liquid Network Federation Wallet Drained of 4000 BTC in Alleged White-Hat Exploit Exposing L-BTC Minting Flaw

On September 7, the Liquid Network Bitcoin sidechain was hit by an attack that drained its Federation wallet of roughly 4000 Bitcoin, valued at approximately $320 million or 2.1 billion RMB, leaving only about 200 BTC in reserves. This represented a 95% loss of the network's backing assets overnight.

The incident was first noticed through an official post on X confirming that the Liquid Federation wallet had been compromised. Funds were transferred out via the authorized SideSwap settlement platform, yet Liquid emphasized that SideSwap keys remained secure and that the PAK (Pegin Authorization Key) itself was not leaked.

Security researchers, including FailSafe CEO Aneirin Flynn, identified preliminary evidence pointing to a vulnerability that permitted unauthorized minting of L-BTC. In the Liquid Network model, L-BTC is issued 1:1 against locked Bitcoin held in the federation wallet; any flaw allowing free minting of L-BTC effectively lets an attacker exchange phantom assets for real Bitcoin.

Officials described the perpetrator as a claimed white-hat hacker who allegedly planned to return the funds in exchange for a fee. This narrative echoes past cases such as the 2021 Poly Network incident, where $610 million was moved and later largely returned, though many similar events end with permanent loss.

The attack has forced Liquid to suspend all new transactions while federation members, including major exchanges BTSE, Bitfinex, and BitMEX, work on remediation. The event highlights a shift in 2026 crypto threats from stealing private keys to compromising asset-issuance and consensus logic, evidenced by the recent Coldcard random-number-generation flaw that enabled theft of over 1755 BTC.

Industry data for the first half of 2026 already records $972 million stolen across 207 incidents, marking a record half-year high. Experts warn that the Liquid case exposes fatal gaps in verification mechanisms and multi-signature federation controls that traditional audits often overlook.

Related articles

Habr•Crypto & Financial Crime

Address Substitution Attacks Exploit Partial Address Checks in Crypto Wallets

Address poisoning, clipboard hijackers, and supply-chain malware all rely on users verifying only the first and last few characters of long blockchain addresses. Researchers detail real incidents including a May 2024 theft of 1,155 WBTC worth roughly 68 million dollars where an attacker poisoned transaction history after a test transfer. Studies from Carnegie Mellon University show that even security-conscious users miss mismatches in truncated addresses 21 to 38 percent of the time. Existing identicons such as Jazzicon and Blockies can be matched by attackers because they depend on only the first eight hex characters. The team released the open-source Humanized Hash library that renders any address or hash as a 4x4 grid of colored shapes using PBKDF2 stretching, making forgery computationally expensive. Calculations indicate that matching both the visual pattern and edge characters requires tens to millions of GPU-years on current hardware. The library supports multiple languages with identical output and carries an MIT license with a fixed algorithm.

Habr•Crypto & Financial Crime

Monero Web Wallet Built on Official monero-wallet-rpc Adds Digest Authentication, Two-Phase Transfers and BigInt Precision

A developer created a non-custodial Monero web wallet that runs entirely on the user's machine and communicates only with a personal monero-wallet-rpc instance. The project retained all key-handling logic inside the official RPC daemon while adding a custom backend, frontend and supporting infrastructure. Eight practical challenges were documented, including HTTP Digest authentication that is tightly coupled to TCP connections and the silent loss of monetary precision caused by JSON.stringify on large numbers. The solution introduced two-phase transaction submission to reduce the risk of broadcast errors and replaced floating-point arithmetic with BigInt to guarantee exact handling of Monero amounts. The resulting implementation demonstrates how to expose a convenient web interface without introducing custodial risk or weakening the security model of the Monero wallet RPC.

安全客•Crypto & Financial Crime

1755 Bitcoin Worth $110 Million Stolen from 5000 Hardware Cold Wallets Due to Flawed Random Number Generator

A mainstream hardware cold wallet suffered a systemic defect in its random number generation algorithm, allowing attackers to compromise approximately 5000 wallets and steal 1755 BTC valued at around $110 million. The incident, confirmed on August 4, marks the largest hardware wallet security breach in crypto history because the flaw existed at the foundational level of private key generation rather than in network defenses. Victims had relied on the common assumption that offline cold storage provides ultimate protection, yet the non-random RNG reduced the effective keyspace dramatically, enabling feasible brute-force attacks. Historical precedents show similar RNG weaknesses have repeatedly undermined wallet security across platforms including Android implementations and various hardware chips. The event underscores that cold storage security depends entirely on correct implementation of cryptographic primitives at every layer, from hardware entropy sources to firmware. Experts recommend avoiding blind trust in any single device, verifying third-party audits, and diversifying storage across multiple solutions including open-source options.

Habr•Crypto & Financial Crime

COLDCARD Wallets Suffer Mass Crypto Theft After RNG Flaw Allows Seed Reconstruction

A critical implementation error in COLDCARD hardware wallets enabled attackers to reconstruct wallet seeds and steal cryptocurrency from thousands of users. The flaw stemmed from an incorrect switch to the libsecp256k1 library, which inadvertently used the rng_get() function from libNgU for seed generation instead of proper hardware entropy. Depending on the model, seeds for Mk2 and Mk3 devices could be derived solely from UID, timer state, and generator history, while Mk4, Mk5, and Q models added limited extra entropy. On July 30, the attacker drained over 1,367 BTC worth approximately $88 million from 4,585 addresses in just 41 minutes. Coinkite released updated firmware, but affected users must also regenerate new seeds and consider additional protections such as passphrases. Other Coinkite products including TAPSIGNER, OPENDIME, and SATSCARD remain unaffected. The incident highlights how even well-tested cryptographic libraries can fail when integrated incorrectly.