Visualização normal

Ontem — 9 de Setembro de 2026Security Affairs
  • ✇Security Affairs
  • Hackers Drain $320 Million From Liquid Network, Then Return Most of It Pierluigi Paganini
    Crypto exchange network Liquid Network lost $320 million overnight, then got most of it back after the hackers demanded a bug fix instead of a ransom Bitcoin’s Liquid Network, a sidechain built by Blockstream and used by dozens of exchanges to move funds faster and more privately than the main Bitcoin blockchain allows, got drained of roughly 4,000 of the 4,200 Bitcoin sitting in its federation wallet on September 6. The attackers, who described themselves as white-hat hackers, have sinc
     

Hackers Drain $320 Million From Liquid Network, Then Return Most of It

8 de Setembro de 2026, 17:35

Crypto exchange network Liquid Network lost $320 million overnight, then got most of it back after the hackers demanded a bug fix instead of a ransom

Bitcoin’s Liquid Network, a sidechain built by Blockstream and used by dozens of exchanges to move funds faster and more privately than the main Bitcoin blockchain allows, got drained of roughly 4,000 of the 4,200 Bitcoin sitting in its federation wallet on September 6.

The attackers, who described themselves as white-hat hackers, have since returned 3,400 of those crypto coins, worth around $262.6 million, while keeping roughly 598 BTC, close to $47 million, for themselves.

Update: 3,400 BTC of the roughly 4,000 BTC withdrawn on September 6 has been returned to the @Liquid_BTC Federation wallet. The return followed confirmation from @Blockstream that the affected bridge nodes have been patched. Approximately 598 BTC remains outstanding, and…

— Samson Mow (@Excellion) September 7, 2026

The size of the initial theft makes this much more serious than another crypto hack. The attacker took nearly 95% of the wallet’s Bitcoin in a single transaction, leaving the fund behind Liquid’s L-BTC token with only about 197 BTC.

This wasn’t a partial breach. The attacker drained almost the entire collateral pool that should back every L-BTC token with an equal amount of real Bitcoin.

How the money actually left is the more technically interesting part. According to Bitrue’s breakdown of the exploit, the attackers didn’t steal a private key or compromise any authorization credentials at all. A software bug in Elements, the open-source code powering Liquid Network, apparently let more L-BTC exist than the system’s real Bitcoin reserves should have allowed, and that unbacked token was then redeemed for genuine BTC through SideSwap’s authorized peg-out mechanism. Liquid itself confirmed the specific access point directly, stating plainly that the funds moved through SideSwap’s authorization key, and that key itself was never compromised.

What happened next is where this stops looking like an ordinary crypto heist. Rather than demanding a ransom payment or threatening to dump the stolen coins, the attackers negotiated entirely in public, writing messages directly into Bitcoin transactions using the OP_RETURN field, a way to embed small amounts of arbitrary data on-chain.

The discussion between @Blockstream and the white-hat hacker (WHH) regarding the ~4000 BTC from @Liquid_BTC is happening in public. It seems to be their preference over email. As it's hard to follow the chain of messages in OP_RETURN, here's a summary with links.

11:30 AM PDT -… https://t.co/IEXyFpBITx

— Samson Mow (@Excellion) September 7, 2026

Their opening demand, relayed through Liquid’s own channels, was refreshingly blunt: fix the underlying vulnerability first, confirm every node is patched, and only then would they send the money back.

Blockstream appears to have met that condition. After the team confirmed that the affected bridge nodes had received the security patches, the attackers returned 3,400 BTC to the federation wallet. They first checked that they had the correct return address. They then kept the remaining 598 BTC, effectively rewarding themselves for the bug discovery. Former Blockstream executive Samson Mow provided updates during the incident but warned that the recovery is not over. The network remains paused while federation members complete more security work, resolve a chain split caused by the freeze, and restore confidence that L-BTC has full Bitcoin backing before they restart the network.

Whether “white hat” is the right label here is a genuinely contested question, and not just semantically. Security specialist Alena Vránová pushed back hard against the framing on social media, arguing that exploiting a vulnerability, draining $320 million, and demanding a fix before returning the money still meets the legal definition of extortion, potentially carrying felony charges and prison sentences up to 20 years in the US. Calling yourself ethical after the fact doesn’t retroactively make unauthorized access to someone else’s wallet legal, whatever bug you’re fixing on the way out.

If you attacked @Liquid_BTC fix it fast I'd reckon to avoid serious trouble.

If you exploit vuln, steal 4k BTC and demand a fix for ransom, that's EXTORTION.

This can mean felony charges and long prison time. In the U.S. up to 20 years, and computer-fraud charges can add more. https://t.co/aekesa5K0n

— Alena V. (@AlenaSatoshi) September 7, 2026

The incident also creates a long-term trust problem that a security patch cannot fix. Galoy founder Nicolas Burtey argued that, even if the funds return in full, the attack has already damaged trust in Liquid. Who will trust Liquid with their money after this? The federated system promises one-to-one Bitcoin backing for every L-BTC token, but this attack showed that guarantee can fail. Recovering most of the funds does not erase that failure.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Liquid Network)

Antes de ontemSecurity Affairs

Peter Thiel ‘s Secret Society Leak Creates a Perfect Target List for Espionage, Influence Operations, and Blackmail

19 de Junho de 2026, 04:42

A simple website flaw exposed members, political profiles, login tokens, and dating data from Peter Thiel ‘s secretive Dialog network.

Dialog, a private invitation-only organization cofounded in 2006 by billionaire tech investor Peter Thiel, has spent two decades refusing to disclose its membership. That position became harder to maintain last week when Swiss hacktivist maia arson crimew, known for exposing the US government’s No Fly List, found an open directory embedded in the source code of dialog.org that was visible to anyone who viewed the page. WIRED independently verified the contents and obtained the registration list for Dialog’s 2026 retreat, scheduled for August 12-16 near Dublin, Ireland.

“A trove of internal records from a secret society for powerful figures in US politics, finance, and tech was left exposed online, WIRED has confirmed, naming participants in its events and revealing sensitive personal details they were assured would stay private.” reported Wired. “The group, called Dialog, is a private, invitation-only organization cofounded in 2006 by the billionaire tech investor Peter Thiel. It convenes US officials, foreign government figures, and Silicon Valley executives at off-the-record annual retreats.”

The 2026 list names 222 registrants, 87 of them first-time attendees. Others have histories stretching back more than a decade, a handful to the founding itself. None used a government email address, placing their attendance outside public records laws.

The roster is not a list of adjacent power. It’s power in direct regulatory relationship with itself. Treasury Secretary Scott Bessent appears alongside Auren Hoffman, Dialog’s chairman, who founded location-data broker SafeGraph and identity-resolution firm LiveRamp. Senator Ted Cruz, who chairs the committee overseeing the FTC and its data-privacy authority, is listed in the same directory. Palantir cofounder Joe Lonsdale, whose software runs case management for ICE and data fusion for the Pentagon, appears alongside Army Secretary Dan Driscoll and Representative Jim Himes, ranking member of the House Intelligence Committee, which oversees agencies Palantir contracts with.

Forbes confirmed additional members including investor Marc Andreessen and investor and former Facebook board member Jim Breyer.

General Alexus Grynkewich, NATO’s supreme allied commander Europe and head of US European Command, is recorded as having attended Dialog gatherings since 2021.

The session agenda for the 2026 retreat includes “Navigating WWIII,” “Battlefield Technologies,” “Bring Back Nuclear,” and “Build-a-Cult,” the last moderated by the founder of the Christian networking site Pray.com. There’s also “How’s Your Sex Life?” which presumably has a different moderator.

“The website directory names sitting Trump administration officials, two US senators, six members of the Paypal Mafia, a former Middle East chief of intelligence, and a sitting ambassador to the United States, along with the founders and directors of many of the country’s largest surveillance, data-broker, and advertising-data companies.” Wired continues.

The leaked registration list adds names not in the public directory of 113: Randy Kroszner, former Federal Reserve governor now on the Bank of England’s Financial Policy Committee; Jonathan Greenblatt, CEO of the Anti-Defamation League; Ryan Stowers, executive director of the Charles Koch Foundation; Roger Myerson, Nobel laureate economist; and a cluster of Google and Google DeepMind executives including Tom Lue, who leads global affairs for the frontier AI division.

The data breach is structurally embarrassing because it was entirely avoidable. The directory was served to any visitor who viewed the page’s source code. A separate Dialog page at app.dialog.org presents a sign-in screen with no terms of service, no indication the application is restricted, and no invitation requirement. The records sat in Airtable, a commercial database, and included for each participant their membership status, every retreat attended, biography, home city, and a private access token functioning as a login credential.

Dialog also runs a matchmaking service. Its registration form asks whether participants are “looking for love” and offers to include single respondents in “future matchmaking.” A separate site at dating.dialog.org hosts an app pitched as “meaningful connections for exceptional people.” The form also collects each registrant’s political leaning, which Dialog promised would never be shared.

“That data, and the matchmaking responses, were exposed in the leak.” concludes Wired.

The data collected by Dialog could be valuable for criminals or intelligence agencies because it reveals personal vulnerabilities, relationship status, political views, and access to influential networks. Such information can support targeted phishing, social engineering, honey-trap operations, blackmail, or influence campaigns. The risk is amplified because participants are often members of the global elite, making them attractive intelligence targets. Many may be highly accomplished in their fields but still willing to share sensitive personal details in trusted environments, creating opportunities for manipulation and exploitation.

An internal guide for event moderators, also found in the exposed directory, instructs them to remind participants that everything is off the record, keep comments concise and “nonobvious,” and model brief introductions to “avoid status signaling” in a room full of senators, dignitaries, and tycoons. The discipline imposed on members apparently didn’t extend to basic website security.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Peter Thiel)

❌
❌