BTC Liquid Network is not decentralized and does not purport to be. It's a federated sidechain, that is... it's a blockchain that runs alongside the Bitcoin blockchain (using a two-way peg that lock real BTC on the Bitcoin blockchain and issues an equivalent amount of Liquid BTC on the Liquid sidechain) but blocks can only be added to the Liquid Network sidechain by some of the handpicked members of the federation.
You are conflating the original BTC network and a lot of the other projects in the cryptocurrency / token / stable currency space.
Every time there was a new token that was 80% reminded or was governed by a central company, the original cryptocurrency enthusiasts cried fowl.
Most people don't read the fine print, don't read the founding white papers, and don't care about the differences between the protocols and the networks when they should.
I think it's more that the 'original cryptocurrency enthusiasts' tend to look the other way, because the more of these weird shitcoins/nfts/networks get minted, the more their numbers go up.
It's 2026. Show of hands, who here actually uses any of this, and why?
This is funny. Is this analogous to finding a wallet on the street and returning it (in my locale: and getting a finders fee), or is this analogous to taking a wallet from a drunk sleeping person (morally dubious), contacting them the day after to return the wallet, or is it just stealing per se.
Where I live it's only theft if there is an intention to unlawfully take ownership of the good. As an example, forgetting to pay in a supermarket lies exactly on that boundary. Take a cart or hide a product and you won't get away. Try to pay, payment fails and you don't notice, walk away and get apprehended and you might convince the judge that you had no intention to unlawfully take ownership.
A few extra steps. Usually, the rug pull doesn't involve directly taking something that belongs to other people, but instead, selling your own thing in a dishonest way.
In a rug pull, the thing you own (usually some kind of digital asset) goes down in value, leaving you with less money than you started with, whereas theft leaves you no longer possessing the asset itself.
I mean of course it was. Everything in this whole ludicrous space is a scam of one kind or another. It's amazing to me that this is still even a point of discussion. It's obviously a rug pull.
That's always a possibility, and I'm sure it has happened a lot. I would suspect with the size of liquid it's more likely it was an exploit, but either way I don't think we'll ever know!
Seems that an Elements rangeproof cache bug may've gotten exploited. Fix for suspicious issue was committed just last week and attackers could've monitored the public commits and exploited the bug before fix was ever pushed?
Sort of self-fulfilling prophecy if true, that's a leading theory anyhow.
fix: range proof cache bind to asset and scriptpubkey
Are you thinking of ETH? All the bitcoin classic forks are over various aspect of network rules (eg. block size or block reward), not to roll back a transaction like ETH classic.
There are always complaints on here about how Google is only paying $X for vulns. One advantage of decentralized digital money is that its bug bounties are self funding and the payout amount researcher-controlled.
I'm not sure if there is actually any evidence of this? Criminals do very well without crypto. If you look at percent of the economy that is fraudulent, it is quite large. If you look at percentage of crypto economy that is fraudulent, it is surprisingly similar
Plenty, search for cases of ransomware for example, you will find hundreds of instances where they demand payment by cryptocurrency, at least 1B per year.
I worked at blockstream back in 2017 and developed the original cryptographic range proofs which are the ancestors some of the involved code here. However, the vulnerabilities here and the whole liquid product as it exists today postdates my involvement in the company (while I was there it was under initial development but envisioned quite differently than what they eventually did), and I haven't followed any of it closely since.
But I gave this issue a quick look based on the transactions and github history.
Underlying issue was related to validation caching. Signatures and proofs are expensive to validate, to improve performance and prevent certain DOS attacks their validation is cached. It's important that the key used in the cache capture everything that goes into the validation decision (though to prevent some attacks its important not too much goes into the key, or an attacker can flood with valid proof attacked to insignificantly different transactions).
It appears to me that there was a longstanding vulnerability-- stemming back to the introduction of multiple-asset-support-- which could cause a consensus split/ddos. But on a lazy review I can't come up with any way of translating it into theft. I see how someone could make an invalid transaction that would be falsely accepted by nodes that have cache state from a constructed prior transaction, but the ways I can come up with results in the invalid transaction just burning assets--- not directly very useful. [Big asterisks on the non obviously exploitable here, I've only thought about it for a minute or two and I really know fairly little about assets support in Liquid-- but exploiting it would require being able to create a fake 'shadow' asset with the a generator that is the negation of a real asset.]
In any case: This was recently fixed, but the "fix" introduced a hash collision vulnerability: The new fields added to the hash were not delimited. Failing to include type information like lengths in hashes is a perennial problem in cryptographic protocols.
Imagine you have a protocol where you sign a {comment, command} tuple, each a string. If the protocol computes the hash by just concating the command and comment and they're variable length fields, then you could get a signature of {"boring comment containing dangerous command", "boring command"} but then present it to someone as {"boring comment containing ","dangerous command boring command"} and have the signature pass. That sort of thing.
This new vulnerability has a somewhat straight forward path to exploitation and prints funds out of thin air.
Based on some of the public comments about nodes rejecting the attack transaction, I'm guessing they rolled out the "fix" to the federation in advance of publishing the changes because they seem to have accepted an attack that everyone else was still rejecting.
Advanced private deployment of a 'fix' might have gave them the confidence to drop the fix on github with little fanfare as it was "already fixed", but doing so painted a target on the issue that remained. Interestingly, off the shelf open weight AI like Kimi K3 immediately identify the new vulnerability without any particularly artful prompting. Makes me wonder if "safe" AI played a role in the introduction of the new, more serious, vulnerability.
I'm going to guess that anyone who actually knows more has their hands busy dealing with the return of the funds. I'm not sure if anyone has ever taken and then returned 1/3rd of a billion dollars worth of assets before.
I'm told by someone who threw AI at it that there may be a way to exploit the initial longstanding vulnerability by counting on the fact that updates to validation cache are non-atomic: You can make an invalid transaction that primes the cache before its rejected. But that these priming transactions can't propagate in the network (because they're invalid)... so getting them to the parties that need to sign the blocks might have been impractical to exploit.
There’s kind of an interesting thread here about open source, which is usually thought of as more secure because of more eyes on the code, actually being less secure because an accidental merge can be exploited instantly with LLM’s monitoring. Is there a lot more security value in obscurity than before?
Great, blog spam comments on HN now? Where is the "Cry that no independent regulator audited their systems and that the transactions were not reversible" coming from? Neither the Twitter thread nor the HN comments even mention anything about this, just the typical argument against yourself?
> I am just saying that this would not happened with a normal bank
Ok, but who were you quoting before? I too see how polarized your view seems to be, given you started this conversation with arguing against yourself for some reason.
skinfaxi | 9 hours ago
simonw | 9 hours ago
mvdtnz | 9 hours ago
cool_dude85 | 9 hours ago
Kranar | 9 hours ago
thephyber | 7 hours ago
Every time there was a new token that was 80% reminded or was governed by a central company, the original cryptocurrency enthusiasts cried fowl.
Most people don't read the fine print, don't read the founding white papers, and don't care about the differences between the protocols and the networks when they should.
vkou | 6 hours ago
It's 2026. Show of hands, who here actually uses any of this, and why?
jeremyjh | 8 hours ago
thephyber | 7 hours ago
pingupongu | 23 minutes ago
tom_ | 9 hours ago
kennywinker | 7 hours ago
wjnc | 2 hours ago
Where I live it's only theft if there is an intention to unlawfully take ownership of the good. As an example, forgetting to pay in a supermarket lies exactly on that boundary. Take a cart or hide a product and you won't get away. Try to pay, payment fails and you don't notice, walk away and get apprehended and you might convince the judge that you had no intention to unlawfully take ownership.
faitswulff | 9 hours ago
greyface- | 8 hours ago
greyface- | 5 hours ago
https://mempool.space/tx/91271efcbb5ab29abfc38ae635f0644e3ba... "Please contact security@blockstream.com"
https://mempool.space/tx/bd81219691eb1e22475c5985d847fa888c3... from Blockstream, unknown PGP message
https://mempool.space/tx/3a3eac4a26395b8c2563aaf1eb8b1b77798... from attackers, "sending most back to bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr, is that ok"
https://mempool.space/tx/8a444eed65c4584f138e08ee138f61490ef... from Blockstream, PGP-signed "Yes, thank you."
https://mempool.space/tx/83825b2135dd0abac12c9dfe17f29ab81b3... from attackers, "Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix. The detail is as follows (encrypted using https://blockstream.com/pgp.txt)." with unknown PGP-encrypted payload
As of writing, no response from Blockstream, and funds are still controlled by the attackers.
Daviey | 9 hours ago
mitxela | 9 hours ago
embedding-shape | 9 hours ago
xyst | 9 hours ago
fxwin | 9 hours ago
knorker | 9 hours ago
bagels | 8 hours ago
antonvs | 8 hours ago
Theft doesn’t have to involve any convincing.
This is a pretty basic distinction. Perhaps you were thinking of “fraud”?
s1artibartfast | 8 hours ago
brador | 7 hours ago
fxwin | 23 minutes ago
mvdtnz | 8 hours ago
pingupongu | 26 minutes ago
Incipient | 8 hours ago
jeremyjh | 8 hours ago
atian | 7 hours ago
cypherpunks01 | 9 hours ago
Sort of self-fulfilling prophecy if true, that's a leading theory anyhow.
fix: range proof cache bind to asset and scriptpubkey
https://github.com/ElementsProject/elements/commit/c26d719c2...
solenoid0937 | 8 hours ago
> Fixes a number of small issues picked up during LLM scans
galkk | 8 hours ago
gruez | 7 hours ago
galkk | 6 hours ago
medellin | 7 hours ago
georgemcbay | 8 hours ago
More than enough to buy yourself a pardon if you get caught.
thephyber | 7 hours ago
etothepii | 8 hours ago
the_real_cher | 7 hours ago
kennywinker | 7 hours ago
TZubiri | 8 hours ago
lmz | 7 hours ago
dotancohen | 7 hours ago
The coin fanboys will argue that the bankers and government were criminals as well.
thephyber | 7 hours ago
peab | 6 hours ago
TZubiri | 2 hours ago
groundzeros2015 | 6 hours ago
knorker | an hour ago
atian | 7 hours ago
aizk | 6 hours ago
killingtime74 | 6 hours ago
nullc | 5 hours ago
But I gave this issue a quick look based on the transactions and github history.
Underlying issue was related to validation caching. Signatures and proofs are expensive to validate, to improve performance and prevent certain DOS attacks their validation is cached. It's important that the key used in the cache capture everything that goes into the validation decision (though to prevent some attacks its important not too much goes into the key, or an attacker can flood with valid proof attacked to insignificantly different transactions).
It appears to me that there was a longstanding vulnerability-- stemming back to the introduction of multiple-asset-support-- which could cause a consensus split/ddos. But on a lazy review I can't come up with any way of translating it into theft. I see how someone could make an invalid transaction that would be falsely accepted by nodes that have cache state from a constructed prior transaction, but the ways I can come up with results in the invalid transaction just burning assets--- not directly very useful. [Big asterisks on the non obviously exploitable here, I've only thought about it for a minute or two and I really know fairly little about assets support in Liquid-- but exploiting it would require being able to create a fake 'shadow' asset with the a generator that is the negation of a real asset.]
In any case: This was recently fixed, but the "fix" introduced a hash collision vulnerability: The new fields added to the hash were not delimited. Failing to include type information like lengths in hashes is a perennial problem in cryptographic protocols.
Imagine you have a protocol where you sign a {comment, command} tuple, each a string. If the protocol computes the hash by just concating the command and comment and they're variable length fields, then you could get a signature of {"boring comment containing dangerous command", "boring command"} but then present it to someone as {"boring comment containing ","dangerous command boring command"} and have the signature pass. That sort of thing.
This new vulnerability has a somewhat straight forward path to exploitation and prints funds out of thin air.
Based on some of the public comments about nodes rejecting the attack transaction, I'm guessing they rolled out the "fix" to the federation in advance of publishing the changes because they seem to have accepted an attack that everyone else was still rejecting.
Advanced private deployment of a 'fix' might have gave them the confidence to drop the fix on github with little fanfare as it was "already fixed", but doing so painted a target on the issue that remained. Interestingly, off the shelf open weight AI like Kimi K3 immediately identify the new vulnerability without any particularly artful prompting. Makes me wonder if "safe" AI played a role in the introduction of the new, more serious, vulnerability.
Interestingly, it looks like the funds are being returned: https://mempool.space/tx/3a3eac4a26395b8c2563aaf1eb8b1b77798...
I'm going to guess that anyone who actually knows more has their hands busy dealing with the return of the funds. I'm not sure if anyone has ever taken and then returned 1/3rd of a billion dollars worth of assets before.
nullc | 5 hours ago
rgbrgb | 5 hours ago
teravor | 5 hours ago
alex_duf | 2 hours ago
This shortens the exploit window
ranger_danger | 2 hours ago
harrouet | 2 hours ago
- Give your money to shenanigans who pretend to know what they're doing
- [...]
- Cry that no independent regulator audited their systems and that the transactions were not reversible.
embedding-shape | 58 minutes ago
harrouet | 52 minutes ago
But I see how polarized you are about the topic.
embedding-shape | 51 minutes ago
Ok, but who were you quoting before? I too see how polarized your view seems to be, given you started this conversation with arguing against yourself for some reason.
pingupongu | 29 minutes ago
Get rid of it.
pingupongu | 27 minutes ago
How many forks and psyops until people realize?