Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
Hackers drain reserves of a Bitcoin sidechain, forcing a shutdown
The recovery-first approach to data resilience
People See One Brand. The Internet May Show Them Hundreds More.
Enterprises Need More Than Vulnerability Management in the Age of AI
From frontier policy to boardroom action: how enterprises should gover...
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      The recovery-first approach to data resilience

      The recovery-first approach to data resilience

      Monday, September 7, 2026, 4:21 PM Asia/Singapore | Features
    • Featured

      Dealing with agentic AI governance and resilience challenges

      Dealing with agentic AI governance and resilience challenges

      Tuesday, September 1, 2026, 11:51 AM Asia/Singapore | Features
    • Featured

      How well do you know your agent?

      How well do you know your agent?

      Thursday, August 20, 2026, 3:21 PM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

News

Hackers drain reserves of a Bitcoin sidechain, forcing a shutdown

By CybersecAsia editors | Tuesday, September 8, 2026, 11:44 AM Asia/Singapore

Hackers drain reserves of a Bitcoin sidechain, forcing a shutdown

A possible bug in software could have been exploited by hackers: 4,000 bitcoin drained from the sidechain’s federation wallet

On 6 September 2026, hackers withdrew roughly 4,000 bitcoin (valued at about US$320m) from the Liquid Network’s federation wallet on Sunday, forcing the Bitcoin sidechain to suspend all activity while Blockstream attempts to establish contact with the actors behind the withdrawal. 

The outflow represented approximately 95% of Liquid’s reported bitcoin reserves, which totaled around 4,200 BTC prior to the incident; the federation wallet now holds just over 207 BTC, according to Blockstream’s proof-of-reserves page.

The funds were moved using the SideSwap Peg-out Authorization Key, although Liquid stated that neither this key nor any other federation keys had been compromised.

SideSwap, a federation member responsible for executing peg-outs on behalf of users, confirmed its key had not been breached, and said Blockstream determined the L-BTC involved in the transaction was created due to a bug in the Elements software.

Heist details

According to Bitcoin Magazine, the attackers appear to have exploited an inflation vulnerability on the sidechain to mint more than 4,000 LBTC that did not previously exist, then redeemed them for real bitcoin from the federation’s 11-of-15 multisig wallet. Because the transactions appeared valid under the flawed consensus rules, the federation members’ hardware security modules automatically signed off on the withdrawal. Also:

  • Two transactions confirmed in block 965,780 moved the funds to a single address, as reported by The Defiant. 
  • Four hours later, the recipient consolidated the bitcoin and attached a message via the OP_RETURN data field stating: “we are whitehats. contact us on chain”. 
  • Blockstream responded on-chain with a message directing the hackers to its security email. A separate transaction from a third party offered a Signal contact, although JAN3 CEO Samson Mow noted that message “did not come from the same address” holding the funds.
  • Subsequently, bridge nodes had been disabled, effectively freezing the sidechain, and exchanges were instructed to pause LBTC deposits and withdrawals.
  • Other assets issued on Liquid, including Tether (USDT), DePix, and tokenized real-world assets, were unaffected.  Mow said Aqua wallet’s Liquid features were impacted but that on-chain bitcoin transactions continued to function, adding, “Everyone is actively working to resolve this. These are difficult times but we’ll pull through.”
  • Ledger chief technology officer Charles Guillemet has questioned whether the conduct aligned with responsible disclosure norms, writing, “White hats don’t drain a bridge and then solicit an ‘on-chain’ contact,” while allowing that “this could be people with good intentions that intensively played with recent LLMs and are not used to responsible disclosures.”

Investigations ongoing

Users holding LBTC currently have limited options. The underlying bitcoin is not redeemable while the network remains paused, and the confidential nature of Liquid transactions makes it difficult to determine how much LBTC is held by retail users versus institutions.

Crypto analyst DBCrypto has noted the coins have not been mixed, and remain stationary on-chain — behavior “more consistent with a whitehat extraction than a theft.”

In May 2026, Blockstream had published a roadmap that included work on a “BitVM-style 1-of-n bridge” designed to reduce reliance on the federated multisig, but that system is not yet live — and Sunday’s withdrawal went out through the very architecture it was meant to replace.

Share:

PreviousThe recovery-first approach to data resilience

Related Posts

Fighting fraud with AI/ML is on ACFE professionals’ radars

Fighting fraud with AI/ML is on ACFE professionals’ radars

Monday, March 11, 2024

Four emerging threats need close monitoring in the global financial services industry

Four emerging threats need close monitoring in the global financial services industry

Wednesday, May 11, 2022

Ransomware targeting SEA SMEs actually dropped in 2020: report

Ransomware targeting SEA SMEs actually dropped in 2020: report

Wednesday, April 21, 2021

The new face of fraud in the AI era

The new face of fraud in the AI era

Tuesday, November 25, 2025

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • People See One Brand. The Internet May Show Them Hundreds More.

    Monday, September 7, 2026
    The gap between what organisations …Read More »
  • Cohesity Delivers New Managed Clean Room Capability to Enhance HCLTech VaultNXT

    Wednesday, September 2, 2026
    Cohesity Clean Room solution and …Read More »
  • Visa Launches Enhanced A2A Protect Innovations to Help Financial Institutions Stop Fraud Before Money Leaves Accounts

    Wednesday, September 2, 2026
    New unified fraud score is …Read More »
  • Malaysia’s Cybersecurity Leaders to Convene at the 34th Edition Cyber Security Summit Malaysia 2026

    Tuesday, September 1, 2026
    Summit to Bring Together More …Read More »
  • ICAC Commissioner in Vienna to meet new UNODC Chief to foster anti-corruption strategic collaboration and unveil ICAC’s AI enforcement system “Tianma” at UNODC’s anti-graft conference

    Tuesday, September 1, 2026
    VIENNA, Sept. 1, 2026 /PRNewswire/ …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.