Bitcoin Hacks Expose Weak Links in Chain: What Investors Need to Know
Recent Bitcoin failures highlight the importance of security when buying and holding cryptocurrency. In the past week, three separate incidents drained millions from a sidechain, minted fake tokens on a cross-chain bridge, and compromised customer data at a bank. The attacks exploited weaknesses in code, contracts, and even email authentication.
The first incident occurred on September 6, when hackers drained Blockstream's Liquid sidechain of nearly $320 million worth of Bitcoin. A bug in the Elements range-proof cache allowed attackers to create fake L-BTC tokens that could be swapped for real Bitcoin. Although a fix was publicly available on GitHub since September 1, it was not implemented in time to prevent the hack.
Just three days later, Symbiosis' BridgeV2 contract was exploited by an attacker who minted over 46 billion fake syBTC tokens - more than 2,000 times the total number of Bitcoin that will ever exist. However, only a small portion of these tokens were sold on Uniswap before their true nature was discovered.
Revolut's attackers also successfully compromised customer data by creating a domain that looked like an official law-enforcement portal and tricked bank staff into handing over sensitive information. Fortunately, Revolut customers retained control of their Bitcoin holdings.