خبری درباره‌ی Ronin (RON)

Liquid sidechain exploited for 4,000 BTC, hackers demand bug fix before return

COINTURK NEWS ۹ روز پیش خلاصه‌ی فارسی · ۴۴۷ کلمه
Liquid sidechain exploited for 4,000 BTC, hackers demand bug fix before return

Blockstream’s Liquid Network, a Bitcoin sidechain used for faster and more private transactions, halted operations on Sunday after roughly 4,000 BTC, valued at about $320 million, were withdrawn from its primary federation wallet. This wallet is responsible for backing every liquid Bitcoin (L-BTC) in circulation. Incident details and immediate response Shortly after the incident, SideSwap, a platform offering a peg-out service and Liquid federation member, explained that it received 4,000 L-BTC from a user at 14:05 UTC. These tokens were promptly burned under a legitimate process, and 23 minutes later, the federation wallet paid out 3,996 BTC to the user. The withdrawal was executed using SideSwap’s Peg-out Authorization Key. Both Blockstream and SideSwap maintained that neither the peg-out key nor any other federation key was compromised. Instead, they pointed to a software bug affecting Elements, the open-source framework upon which Liquid operates. Before the event, the federation wallet held approximately 4,200 BTC. This figure plunged to around 200 BTC—about 5% of its previous balance—following the transactions. MetricBefore IncidentAfter IncidentFederation wallet balance (BTC)4,200200BTC Withdrawn–~4,000Mini dictionary: Elements, an open-source blockchain platform developed by Blockstream, enables the creation of sidechains like Liquid and allows for advanced features such as confidential transactions and pegged assets. White-hat claims and on-chain negotiation The party behind the withdrawal identified themselves as “whitehats,” leaving an on-chain message requesting Blockstream to contact them. An hour later, Blockstream responded via another on-chain message, initiating a communication exchange secured with PGP signatures attached to Bitcoin transactions. The hackers offered to return the majority of the stolen BTC, setting a single condition: Blockstream must patch the identified Elements software bug and update every node to prevent further exploitation. Blockstream agreed to these terms in another message, expressing appreciation and confirming its willingness to address the vulnerability. The hackers conveyed their intent by stating in an on-chain message, “we are whitehats. contact us on chain,” setting the stage for negotiations that would hinge on a critical software update. Industry reactions and ongoing risks Charles Guillemet, chief technology officer at Ledger, questioned the attackers’ ethics, noting that genuine white hats typically do not empty bridge wallets and then open negotiations through on-chain contact. He compared the situation to high-profile breaches including Ronin and Euler, later critiquing the shift in what constitutes a white-hat approach as the bug fix condition emerged. Samson Mow, previously Blockstream’s security chief, published a detailed timeline of the communication and placed the hackers’ final controlled balance at around 3,998.5 BTC. Industry executives have pointed out the evolving negotiation tactics in exploit cases, observing that, “Now they steal the money and refuse to give back the funds before the vulnerability is fixed,” reflecting a shift in white-hat conventions.

عنوان اصلی (انگلیسی): Liquid sidechain exploited for 4,000 BTC, hackers demand bug fix before return

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به Ronin

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.