# Exploit Articoli collegati

Il Centro Notizie HTX fornisce gli articoli più recenti e le analisi più approfondite su "Exploit", coprendo tendenze di mercato, aggiornamenti sui progetti, sviluppi tecnologici e politiche normative nel settore crypto.

Liquid Attacker Keeps $47 Million for Themselves: Is It a White Hat Bounty or Disguised Extortion?

On September 6th, an attacker exploited a vulnerability in the Elements software, the foundation of Blockstream's Liquid Network, to generate approximately 4,000 fake LBTC tokens. Using the normal withdrawal channels of the SideSwap service, they exchanged these for roughly 3,998.5 real BTC (worth about $320 million) from Liquid's multi-signature wallet. The attacker then left a message in a Bitcoin transaction claiming to be "whitehats" and requested on-chain contact. After Blockstream patched the vulnerability upon contact, the attacker returned 3,400 BTC but kept approximately 598.5 BTC (worth around $47 million) in an address under their control. Blockstream is currently in communication to recover these remaining funds and has not officially recognized them as a bug bounty payment. This incident has sparked debate within the crypto community. Supporters argue the attacker acted as a white hat by exposing a critical flaw, securing the fix, and returning most funds, thus preventing a total loss. Some suggest a 15% retention could set a precedent for incentivizing ethical disclosures in major hacks. Critics, however, contend that exploiting the bug first to extract funds and then unilaterally deciding on a reward resembles extortion rather than standard white-hat procedure, where vulnerabilities are typically reported first for a negotiated bounty. Blockstream's ongoing recovery efforts indicate they view the withheld sum as assets to be retrieved, not an agreed-upon bounty.

marsbitIeri 03:01

Liquid Attacker Keeps $47 Million for Themselves: Is It a White Hat Bounty or Disguised Extortion?

marsbitIeri 03:01

White Hackers Withdrew $320 Million from Liquid Network Using Artificial Token Emission

On September 6, 2026, nearly 4,000 BTC (approx. $320 million) was withdrawn from the Liquid Federation wallet on the Bitcoin sidechain, Liquid Network, by presumed "white hat" hackers. The attackers exploited a vulnerability in the Elements software, allowing them to artificially create 4,000 L-BTC tokens (pegged 1:1 to BTC) and legitimately exchange them for real Bitcoin via the peg-out mechanism. The service provider SideSwap processed the exchange, destroying the fake L-BTC and releasing the BTC from the federation's reserves. Blockstream, the developer of Liquid Network, confirmed the federated keys were not compromised. The attack only affected the L-BTC peg mechanism; other assets on Liquid were untouched. Following the incident, the attackers communicated via a Bitcoin blockchain message, identifying themselves as white hats and initiating negotiations. They have promised to return a "large part" of the funds once the vulnerability is patched. This incident highlights a recurring risk in cross-chain bridges: attacks targeting token issuance logic rather than storage keys. While the main Bitcoin chain remains unaffected, the event underscores the systemic reliance on trust in bridge code and the challenges in detecting such vulnerabilities until funds are withdrawn. Negotiations between Blockstream and the attackers are ongoing.

cryptonews.ru2 giorni fa 09:46

White Hackers Withdrew $320 Million from Liquid Network Using Artificial Token Emission

cryptonews.ru2 giorni fa 09:46

活动图片