Blockstream Bug Opened Liquid Network to $16 Million Bitcoin Theft

2020-6-30 04:36

Blockstream’s Liquid Network contained a vulnerability until today that could have allowed millions in BTC to get stolen. The bug was disclosed by James Prestwich, a Bitcoin developer and founder of the crypto startup Summa One.

How the Bug Works

The security vulnerability affected an essential account on the Liquid Network due to inconsistent timelocks.

That inconsistency could have allowed employees to withdraw Bitcoin from through an emergency recovery process that requires 2 of 3 keyholders to sign a transaction. This bug would bypass the proper multisig process, which requires 11 of 15 keyholders to sign a transaction.

According to Prestwitch, the vulnerable account controlled 870 BTC ($8 million) for over an hour this week. However, the bug could have compromised millions of dollars before the last transaction: the potential exploit has existed for 18 months and affected more than 2,000 UTXOs.

Blockstream’s Response

Blockstream CEO Adam Back has responded and admitted that the bug was a “known issue.”

Back says that a complete fix has been underway for some time, but has been delayed for several reasons. He added that developers are currently working with the Liquid Federation to create and deploy a final patch. Right now, a workaround is in place that will solve the problem in a temporary and limited way.

Adam Back noted that Blockstream’s handling of the situation “is not up to [its] usual standard of trust-minimization.” To Blockstream’s credit, no funds have actually been stolen. Furthermore, the bug only opens the possibility of internal theft by employees—not an outside attack.

Why Blockstream Is Controversial

Blockstream and the Liquid Network are somewhat controversial among the crypto community, especially among the Bitcoin community.

While Blockstream funds development of Bitcoin itself, the company’s Liquid Network is a federated sidechain that stores BTC outside of the main Bitcoin blockchain. That means that the company maintains significant control over the funds of users who trust it—typically enterprises and exchanges that rely on it for transfers and settlement.

Liquid’s bug is unlikely to affect general crypto holders. Regardless, the news is a reminder that investors who wish to maintain maximum control over their Bitcoin should do so by holding it in their own non-custodial wallet.

Similar to Notcoin - Blum - Airdrops In 2024

origin »

Bitcoin (BTC) на Currencies.ru

$ 67853.49 (-1.31%)
Объем 24H $27.089b
Изменеия 24h: -1.36 %, 7d: 1.24 %
Cегодня L: $67853.49 - H: $68823.97
Капитализация $1337.212b Rank 1
Цена в час новости $ 9125.56 (643.55%)

bitcoin blockstream network liquid bug btc disclosed

bitcoin blockstream → Результатов: 126


Фото:

Blockstream Satellite 2.0 Allows Users to Synchronize Bitcoin Node Without Internet Connection

Blockstream, the Canada-based distributed ledger technology (DLT) project dedicated to improving the Bitcoin (BTC) network, has announced the launch of Blockstream Satellite 2. 0. The team says the latest upgrade comes with a standards-based transmission protocol, additional bandwidth, and coverage areas, while also allowing users to synchronize the entire Bitcoin node without an Internet connection, accordingRead MoreRead More.

2020-5-6 00:07


Blockstream представила язык Minisсript для Bitcoin

В биткоине всегда был механизм, позволяющий тратить монеты более сложным (не только через один ключ) методом: система скриптов (Script). И хотя скрипты сегодня в первую очередь используется в платежах с одним ключом, они также являются основой для кошельков с мультиподписью, атомарных свопов и Lightning Network.

2019-9-9 15:22


Sacrilegious Binance Reorg Would ‘Erode’ Bitcoin: Blockstream

By CCN: Blockstream CEO Adam Back told the What Bitcoin Did podcast that the block reshuffling proposed by Binance CEO Changpeng Zhao would raise “geopolitical issues” had it been attempted. Accept That Bitcoin Is Final Back explained why the idea of a chain reorganization as a means to punish hackers or rescue lost bitcoins is a terrible idea.

2019-5-15 12:25


Main Bitcoin Development Company Blockstream Releases c-lightning 0.7 BTC Scalability Software

Blockstream, one of the biggest powerhouses in Bitcoin and blockchain technology, has recently introduced a new version of C-Lightning, its own Bitcoin software for scalability. According to Blockstream’s official website, the new version is the result of a lot of hard work over a period of 8 months by many different people all over the […]

2019-3-5 04:50


Фото:

‘Extinguishing Capacity’: Bitcoin Could Swallow All M1 Fiat At $223K Per Coin

$223,186 is the price Bitcoin would need to be in order to convert the entire world supply of fiat currency, industry figures calculated July 2. M1 Fiat Could Go At Less Than $250k Part of an ongoing debate on social media, Blockstream CEO Adam Back and CSO Samson Mow joined Bitcoin Think editor Beautyon in discussing the phenomenon of ‘hyperbitcoinization’ – the as yet untested process by which consumers abandon fiat en masse for Bitcoin.

2018-7-3 00:00


Blockstream представила новую версию решения c-lightning

Разработчик биткоин- и блокчейн-решений компания Blockstream представила бета-версию c-lightning (v0. 6), которая является одной из основных имплементаций протокола Lightning Network. We’re excited to announce the c-lightning beta! v0.

2018-6-26 09:45


MAST – новое решение для Биткоин

MAST в скором времени станет новым инструментом для увеличения гибкости смарт-контрактов, а также для обеспечения масшабируемости, и, конечно же, конфиденциальности данных в сети Биткоин. Ведущие разработчики из Blockstream и Bitcoin Core уверены, что именно с помощью такого простого софтфорка можно существенно увеличить потенциал и спрос на цифровую валюты Биткоин. Основными составляющими будут механизмы P2SH и […]

2018-6-22 15:11