Seems that an Elements rangeproof cache bug may've gotten exploited. Fix for suspicious issue was committed just last week and attackers could've monitored the public commits and exploited the bug before fix was ever pushed?
Sort of self-fulfilling prophecy if true, that's a leading theory anyhow.
fix: range proof cache bind to asset and scriptpubkey
BTC Liquid Network is not decentralized and does not purport to be. It's a federated sidechain, that is... it's a blockchain that runs alongside the Bitcoin blockchain (using a two-way peg that lock real BTC on the Bitcoin blockchain and issues an equivalent amount of Liquid BTC on the Liquid sidechain) but blocks can only be added to the Liquid Network sidechain by some of the handpicked members of the federation.
You are conflating the original BTC network and a lot of the other projects in the cryptocurrency / token / stable currency space.
Every time there was a new token that was 80% reminded or was governed by a central company, the original cryptocurrency enthusiasts cried fowl.
Most people don't read the fine print, don't read the founding white papers, and don't care about the differences between the protocols and the networks when they should.
I'm not sure if there is actually any evidence of this? Criminals do very well without crypto. If you look at percent of the economy that is fraudulent, it is quite large. If you look at percentage of crypto economy that is fraudulent, it is surprisingly similar
There are always complaints on here about how Google is only paying $X for vulns. One advantage of decentralized digital money is that its bug bounties are self funding and the payout amount researcher-controlled.
That's always a possibility, and I'm sure it has happened a lot. I would suspect with the size of liquid it's more likely it was an exploit, but either way I don't think we'll ever know!
A few extra steps. Usually, the rug pull doesn't involve directly taking something that belongs to other people, but instead, selling your own thing in a dishonest way.
I mean of course it was. Everything in this whole ludicrous space is a scam of one kind or another. It's amazing to me that this is still even a point of discussion. It's obviously a rug pull.
Are you thinking of ETH? All the bitcoin classic forks are over various aspect of network rules (eg. block size or block reward), not to roll back a transaction like ETH classic.
Seems that an Elements rangeproof cache bug may've gotten exploited. Fix for suspicious issue was committed just last week and attackers could've monitored the public commits and exploited the bug before fix was ever pushed?
Sort of self-fulfilling prophecy if true, that's a leading theory anyhow.
fix: range proof cache bind to asset and scriptpubkey
https://github.com/ElementsProject/elements/commit/c26d719c2...
lmao, PR description says:
> Fixes a number of small issues picked up during LLM scans
https://xcancel.com/Liquid_BTC/status/2096696272447218108#m
Xcancel is back? When did that happen?
https://news.ycombinator.com/item?id=49588988 "Nitter and XCancel resume service after legal advice" 5 hours ago
Why do they say it's white hat hackers?
While moving the funds, the attackers left an OP_RETURN message with the text "we are whitehats. contact us on chain" https://mempool.space/tx/c103de95817b43f2df635ec6f35ff126ca2...
Purported white-hat hackers. The implication is that these people are presumably describing themselves as such, but it may not actually be true.
I can imagine one’s hat changing color when faced with a pot that big…
Maybe they are against epstein and genocide. You should look up how much epstein worked to fund bitcoin.
The same reason scam artists describe themselves as businessmen
Presumably to try and reduce the chance of a mass panic among their users.
9 times out of 10 when an exchange or broker is "hacked" its been the operators of the exchange.
You have worded this like a fact, but this is your opinion.
What do they care if there's a panic? They have "paused the sidechain". No one can act on their panic.
Wasn't this all supposed to be decentralized? How can a foundation choose to unilaterally "pause the sidechain"?
BTC Liquid Network is not decentralized and does not purport to be. It's a federated sidechain, that is... it's a blockchain that runs alongside the Bitcoin blockchain (using a two-way peg that lock real BTC on the Bitcoin blockchain and issues an equivalent amount of Liquid BTC on the Liquid sidechain) but blocks can only be added to the Liquid Network sidechain by some of the handpicked members of the federation.
What the fuck did you just say to me? (/s)
You are conflating the original BTC network and a lot of the other projects in the cryptocurrency / token / stable currency space.
Every time there was a new token that was 80% reminded or was governed by a central company, the original cryptocurrency enthusiasts cried fowl.
Most people don't read the fine print, don't read the founding white papers, and don't care about the differences between the protocols and the networks when they should.
$320m, not a bad haul.
More than enough to buy yourself a pardon if you get caught.
And remember that there is precedence for Trump pardoned financial criminals avoiding restitution.
One disadvantage of decentralized money, criminals gain more power. Many such cases
This is a centralization failure. Please learn more before commenting.
I'm not sure if there is actually any evidence of this? Criminals do very well without crypto. If you look at percent of the economy that is fraudulent, it is quite large. If you look at percentage of crypto economy that is fraudulent, it is surprisingly similar
There are always complaints on here about how Google is only paying $X for vulns. One advantage of decentralized digital money is that its bug bounties are self funding and the payout amount researcher-controlled.
That is a natural consequence of banks and governments losing power. That power balance shifts towards the citizens... some of whom are criminals.
The coin fanboys will argue that the bankers and government were criminals as well.
This is worded in a way that pretends like the banks and governments themselves aren't considered criminals by the masses.
“Inside job.”
It’s not "hackers". It’s an inside job, and a rug pull.
That's always a possibility, and I'm sure it has happened a lot. I would suspect with the size of liquid it's more likely it was an exploit, but either way I don't think we'll ever know!
Usually we do find out, and in a majority of cases we find out it is a scam by the operators.
how is it a rug pull? if it's an inside job, doesn't that just make it theft?
What's the difference to you between a rug pull and theft?
A rug pull involves convincing someone to buy something first.
Theft doesn’t have to involve any convincing.
This is a pretty basic distinction. Perhaps you were thinking of “fraud”?
A few extra steps. Usually, the rug pull doesn't involve directly taking something that belongs to other people, but instead, selling your own thing in a dishonest way.
A rug pull means you hype and then sell on the open market without.
Rug pull is a trap, which can include theft. (You pull the rug and the victim in the cartoon would fall into the spikes hole).
Yeah it was.
I mean of course it was. Everything in this whole ludicrous space is a scam of one kind or another. It's amazing to me that this is still even a point of discussion. It's obviously a rug pull.
Time for bitcoin classic++?
Are you thinking of ETH? All the bitcoin classic forks are over various aspect of network rules (eg. block size or block reward), not to roll back a transaction like ETH classic.
Yeah… because in 15 years bitcoin has never forked for a hack. What a brain dead comment
Is there any indications that this and the ColdCard heist could in fact be escaped distilled agents from the huggingface and similar attacks?
Now they have 300 million dollars
That should keep openai liquid for an extra 45min or so.