Bitcoin Ecosystem Hit by String of Hacks Resulting in Hundreds of Millions Lost
A series of hacks between September 6 and 11 targeted various platforms in the Bitcoin ecosystem. Liquid, a sidechain, was drained of approximately $320 million on September 6 due to a bug in its Elements range-proof cache. The attackers created L-BTC with no underlying Bitcoin value and swapped it for real BTC.
The issue had been publicly known since September 1, but the fix was not applied to the computers running Liquid. As a result, around $47 million is still missing. Three days later, Symbiosis was breached when an attacker exploited its BridgeV2 contract, minting over 46 billion fake syBTC tokens. However, only 4.39 WBTC were sold through Uniswap before the market realized what had happened.
Revolut, a bank, suffered a phishing attack on September 12 when attackers created a domain that looked like an official law-enforcement portal and requested customer files. The bank handed over sensitive information, including full Bitcoin transaction histories, but customers' coins remained intact.
The hacks highlight the importance of security measures in the Bitcoin ecosystem. A spot Bitcoin ETF, such as iShares Bitcoin Trust (NASDAQ:IBIT), holds coins through a custodian, leaving it vulnerable to breaches at that level. Regulated exchanges hold coins on their own balance sheets and are susceptible to collapse. Self-custody, where individuals manage their own private keys, eliminates the need for third-party security measures.
Hackers targeted various platforms in the Bitcoin ecosystem between September 6 and 11, causing significant losses. Liquid was drained of approximately $320 million due to a bug, while Symbiosis suffered from an exploited contract. Revolut's phishing attack showed how attackers can use fake domains to steal sensitive information. The hacks emphasize the importance of security measures in protecting against breaches.