Hackers have withdrawn ~4k BTC (~$320M) from the Liquid Federation wallet
Posted by felipelalli 1 day ago
Comments
Comment by cypherpunks01 1 day ago
Sort of self-fulfilling prophecy if true, that's a leading theory anyhow.
fix: range proof cache bind to asset and scriptpubkey
https://github.com/ElementsProject/elements/commit/c26d719c2...
Comment by greyface- 13 hours ago
The mechanism reminds me of this classic AWS request signature forgery bug from 2008: https://news.ycombinator.com/item?id=401876
Comment by solenoid0937 1 day ago
> Fixes a number of small issues picked up during LLM scans
Comment by rgbrgb 1 day ago
Comment by teravor 1 day ago
Comment by alex_duf 1 day ago
This shortens the exploit window
Comment by ranger_danger 1 day ago
Comment by pingupongu 1 day ago
How many forks and psyops until people realize?
Comment by embedding-shape 1 day ago
And given the world will never run out of fools, you're actually saying cryptocurrencies will continue working forever?
Comment by pingupongu 23 hours ago
Comment by mhitza 21 hours ago
Some of these people with the moral integrity of "quick buck at everyone else's expense" maybe won't stop until they go bankrupt or severly in debt. Might be a self-selective environment at this point.
Comment by pingupongu 7 hours ago
People need to call them for what they are.
Comment by shuwix 1 day ago
Comment by silveradogomez9 5 hours ago
Comment by skinfaxi 1 day ago
Comment by greyface- 1 day ago
Comment by greyface- 1 day ago
https://mempool.space/tx/91271efcbb5ab29abfc38ae635f0644e3ba... "Please contact security@blockstream.com"
https://mempool.space/tx/bd81219691eb1e22475c5985d847fa888c3... from Blockstream, unknown PGP message
https://mempool.space/tx/3a3eac4a26395b8c2563aaf1eb8b1b77798... from attackers, "sending most back to bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr, is that ok"
https://mempool.space/tx/8a444eed65c4584f138e08ee138f61490ef... from Blockstream, PGP-signed "Yes, thank you."
https://mempool.space/tx/83825b2135dd0abac12c9dfe17f29ab81b3... from attackers, "Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix. The detail is as follows (encrypted using https://blockstream.com/pgp.txt)." with unknown PGP-encrypted payload
As of writing, no response from Blockstream, and funds are still controlled by the attackers.
Comment by tom_ 1 day ago
Comment by kennywinker 1 day ago
Comment by cyanydeez 1 day ago
Comment by wjnc 1 day ago
Where I live it's only theft if there is an intention to unlawfully take ownership of the good. As an example, forgetting to pay in a supermarket lies exactly on that boundary. Take a cart or hide a product and you won't get away. Try to pay, payment fails and you don't notice, walk away and get apprehended and you might convince the judge that you had no intention to unlawfully take ownership.
Comment by embedding-shape 1 day ago
Kind of in-between I'd say. You find a wallet, on a bench, next to sleeping person, and you see lots of other people eying the wallet to take for themselves. You take the wallet to prevent others from taking it essentially.
Not saying these people for sure are whitehats/grayhats, who knows until the funds are returned, but that's basically how grayhatters see themselves.
Comment by enoint 1 day ago
Comment by faitswulff 1 day ago
Comment by simonw 1 day ago
Comment by jeremyjh 1 day ago
Comment by thephyber 1 day ago
Comment by pingupongu 1 day ago
Comment by mvdtnz 1 day ago
Comment by cool_dude85 1 day ago
Comment by Kranar 1 day ago
Comment by esseph 1 day ago
Comment by thephyber 1 day ago
Every time there was a new token that was 80% reminded or was governed by a central company, the original cryptocurrency enthusiasts cried fowl.
Most people don't read the fine print, don't read the founding white papers, and don't care about the differences between the protocols and the networks when they should.
Comment by vkou 1 day ago
It's 2026. Show of hands, who here actually uses any of this, and why?
Comment by nullc 1 day ago
But I gave this issue a quick look based on the transactions and github history.
Underlying issue was related to validation caching. Signatures and proofs are expensive to validate, to improve performance and prevent certain DOS attacks their validation is cached. It's important that the key used in the cache capture everything that goes into the validation decision (though to prevent some attacks its important not too much goes into the key, or an attacker can flood with valid proof attacked to insignificantly different transactions).
It appears to me that there was a longstanding vulnerability-- stemming back to the introduction of multiple-asset-support-- which could cause a consensus split/ddos. But on a lazy review I can't come up with any way of translating it into theft. I see how someone could make an invalid transaction that would be falsely accepted by nodes that have cache state from a constructed prior transaction, but the ways I can come up with results in the invalid transaction just burning assets--- not directly very useful. [Big asterisks on the non obviously exploitable here, I've only thought about it for a minute or two and I really know fairly little about assets support in Liquid-- but exploiting it would require being able to create a fake 'shadow' asset with the a generator that is the negation of a real asset.]
In any case: This was recently fixed, but the "fix" introduced a hash collision vulnerability: The new fields added to the hash were not delimited. Failing to include type information like lengths in hashes is a perennial problem in cryptographic protocols.
Imagine you have a protocol where you sign a {comment, command} tuple, each a string. If the protocol computes the hash by just concating the command and comment and they're variable length fields, then you could get a signature of {"boring comment containing dangerous command", "boring command"} but then present it to someone as {"boring comment containing ","dangerous command boring command"} and have the signature pass. That sort of thing.
This new vulnerability has a somewhat straight forward path to exploitation and prints funds out of thin air.
Based on some of the public comments about nodes rejecting the attack transaction, I'm guessing they rolled out the "fix" to the federation in advance of publishing the changes because they seem to have accepted an attack that everyone else was still rejecting.
Advanced private deployment of a 'fix' might have gave them the confidence to drop the fix on github with little fanfare as it was "already fixed", but doing so painted a target on the issue that remained. Interestingly, off the shelf open weight AI like Kimi K3 immediately identify the new vulnerability without any particularly artful prompting. Makes me wonder if "safe" AI played a role in the introduction of the new, more serious, vulnerability.
Interestingly, it looks like the funds are being returned: https://mempool.space/tx/3a3eac4a26395b8c2563aaf1eb8b1b77798...
I'm going to guess that anyone who actually knows more has their hands busy dealing with the return of the funds. I'm not sure if anyone has ever taken and then returned 1/3rd of a billion dollars worth of assets before.
Comment by nullc 1 day ago
Comment by aizk 1 day ago
Comment by killingtime74 1 day ago
Comment by enoint 1 day ago
Comment by Daviey 1 day ago
Comment by mitxela 1 day ago
Comment by embedding-shape 1 day ago
Comment by recursivecaveat 21 hours ago
Comment by etothepii 1 day ago
Comment by the_real_cher 1 day ago
Comment by kennywinker 1 day ago
Comment by etothepii 1 day ago
Comment by TZubiri 1 day ago
Comment by lmz 1 day ago
Comment by peab 1 day ago
Comment by dotancohen 1 day ago
The coin fanboys will argue that the bankers and government were criminals as well.
Comment by thephyber 1 day ago
Comment by dotancohen 1 day ago
Comment by knorker 1 day ago
Comment by groundzeros2015 1 day ago
Comment by georgemcbay 1 day ago
More than enough to buy yourself a pardon if you get caught.
Comment by thephyber 1 day ago
Comment by pingupongu 1 day ago
Get rid of it.
Comment by MaxikCZ 1 day ago
Comment by pingupongu 7 hours ago
Comment by harrouet 1 day ago
Comment by embedding-shape 1 day ago
Comment by harrouet 1 day ago
But I see how polarized you are about the topic.
Comment by tancop 3 hours ago
Of course you need to use a well designed network like Ethereum or Solana for that, not a random Bitcoin sidechain controlled by a committee of BTC miners and shady VCs. This is a problem with Liquid not DeFi.
Comment by embedding-shape 1 day ago
Ok, but who were you quoting before? I too see how polarized your view seems to be, given you started this conversation with arguing against yourself for some reason.
Comment by harrouet 1 day ago
How so ?
Meanwhile, what you qualified as blog spam is actually proving to be written by a human spending too much time answering your rant.
Comment by embedding-shape 1 day ago
Who said any of the parts you quoted in https://news.ycombinator.com/item?id=49594757?
It looks like you made up all of those lines.
Comment by harrouet 1 day ago
Comment by embedding-shape 1 day ago
Generally, we use quotes here for actual quotes, not quoting stuff we've read in other newspapers or on reddit or whatever, but real verbatim quotes.
I think it used to be a proper guidelines back in the day, or at least people got really up in their arms if you used quote syntax for things that weren't actually verbatim quotes.
But besides that, what's the point? Why share other's viewpoints you don't even agree with, so you can argue against them yourself? Why not wait until someone who actually has those viewpoints, share them? Or even better, why not just say nothing at all?
Comment by toasty228 1 day ago
Comment by shuwix 1 day ago
Comment by iwontberude 1 day ago
Comment by walrus01 1 day ago
Comment by atian 1 day ago
Comment by xyst 1 day ago
Comment by fxwin 1 day ago
Comment by knorker 1 day ago
Comment by fxwin 1 day ago
Comment by bagels 1 day ago
Comment by s1artibartfast 1 day ago
Comment by antonvs 1 day ago
Theft doesn’t have to involve any convincing.
This is a pretty basic distinction. Perhaps you were thinking of “fraud”?
Comment by brador 1 day ago
Comment by Incipient 1 day ago
Comment by jeremyjh 1 day ago
Comment by atian 1 day ago
Comment by mvdtnz 1 day ago
Comment by pingupongu 1 day ago
Comment by galkk 1 day ago
Comment by gruez 1 day ago
Comment by galkk 1 day ago
Comment by medellin 1 day ago