JAN32026-09-15 23:38:50JAN3 says Indra hit by denial-of-service attack, forward swaps temporarily disabledJAN3 said its newly launched swap infrastructure, Indra, was hit by a denial-of-service attack, according to monitoring cited by Bitcoin News. While the team investigates, forward swaps have been temporarily disabled. JAN3 also said swaps that were already in progress may face delays. Indra was developed by JAN3 to replace Boltz in Aqua. The infrastructure is designed to let users move Bitcoin between the Lightning Network and Liquid. JAN3 noted, however, that Liquid peg operations remain limited. The company did not provide further details on the attack or a timeline for restoring the affected swap function in the information provided.810
Liquid2026-09-15 12:36:17Samson Mow says Blockstream may offer a bounty if remaining Liquid funds are returnedBitcoin News said in a post on X that Samson Mow commented on the handling of stolen funds tied to Liquid. According to Mow, Blockstream has refused to pay a ransom, though he did not rule out the possibility of offering a bounty if the hacker returns the remaining stolen assets. Mow said the funds belong to Liquid users, which means Blockstream cannot negotiate over that money. He added that any bounty, if offered, would need to be structured as a separate and reasonable arrangement rather than as part of ransom talks. The remarks frame Blockstream’s position as a refusal to negotiate directly over user-owned assets while leaving open a distinct path tied to the return of the remaining funds.620
Policy Regula2026-09-12 02:00:38Foresight’s weekly Web3 roundup tracks CLARITY Act changes, MetaMask split, meme coin frenzy and security shocksForesight News’ latest weekly Web3 roundup pulls together the stories that dominated crypto conversation over the past week, spanning meme coin speculation, U.S. regulatory debate, infrastructure shifts and fresh security incidents. On the speculative end, Hunter Biden-linked token LAPTOP launched on Base and quickly fell more than 99%, while the SLINK case on Robinhood Chain showed how a social-account compromise and celebrity association could drive a token from roughly $500,000 to $82 million before collapsing. The report also highlighted the rapid rise of trading tools built for FOMO-driven markets and a new "stock-meme" narrative on BNB Chain tied to tokenized equities. On the policy and business side, U.S. Senate Republicans released a 630-page revised CLARITY Act that would redraw oversight lines between the SEC and CFTC and bring certain "fake DeFi" projects under CFTC registration. MetaMask formally split from Consensys and repositioned itself as a broader consumer-facing financial platform, while Circle’s Chelsea sponsorship raised questions in Hong Kong over cross-border promotion of an unauthorized stablecoin. Foresight also noted the launch of Solana prediction market site world.xyz, which went offline temporarily on day one after traffic surged. Security stories remained central. Singaporean defendant Malone Lam pleaded guilty in a case tied to the theft of 4,100 BTC, Liquid halted operations after an attacker used abnormal L-BTC to redeem nearly 4,000 BTC, and WOO X faced scrutiny over multi-day withdrawal delays reported by users and highlighted by ZachXBT.1170
Blockstream2026-09-11 06:58:52Blockstream rejects ransom demand over Liquid hack, says remaining BTC will be pursued through legal channelsBlockstream said it will not pay a ransom to the attacker behind the Liquid incident, stating that taking assets without authorization and refusing to return them is theft rather than responsible disclosure or white-hat conduct. The company said it has been in contact with the attacker in an effort to secure the return of user funds, but it will not accept the behavior or the conditions attached to it. Blockstream also said it will not allow open-source software developers to bear a ransom burden far beyond their level of economic participation. The firm added that the bitcoin can still be returned and that the attacker can still align with white-hat standards. If the remaining funds are not returned, Blockstream said it will work with law enforcement, exchanges, service providers, and forensic experts to trace and recover the assets and identify those responsible. Foresight News noted that the attacker posted an on-chain message on Sept. 9 demanding a 10% bounty from Blockstream’s own funds, while earlier reporting cited by Foresight said about 3,400 BTC had been returned and roughly 600 BTC remained outstanding.810
Liquid2026-09-10 12:57:03Galaxy’s Alex Thorn says Liquid’s approved-address rule did not stop the bitcoin thievesAlex Thorn, head of firmwide research at Galaxy Digital, said Liquid’s approved-address restriction did not prevent the Sept. 6 attackers from moving bitcoin off the sidechain. According to CertiK, the incident began when a software flaw let an attacker create about 3,998.5 L-BTC that had no bitcoin backing, then convert those tokens into real BTC through Liquid’s own withdrawal process. Unchained reported that the withdrawals drained about 95% of the bitcoin pegged into Liquid before the sidechain was frozen the same day. Liquid’s developer documentation says peg-outs require a Peg-out Authorization Key, or PAK, and states that only users with registered PAK entries can withdraw to Bitcoin. Thorn said on Unchained’s Uneasy Money podcast that the restriction did not actually bind the attackers because ordinary users often rely on intermediaries such as federation members or exchanges. He pointed to a workflow described in Liquid’s documentation and said SideSwap would accept a destination address and auto-forward withdrawn BTC to that address. CertiK attributed the exploit to ambiguous cache-key encoding in the rangeproof verification cache. Liquid and SideSwap both said the withdrawal system itself remained intact, and Liquid said no key, including SideSwap’s, had been compromised. The attackers have since returned 3,400 BTC and kept 598.5 BTC.820
Samson Mow2026-09-10 12:48:50Samson Mow warns alleged Liquid attacker, says all user assets must be returned in fullSamson Mow warned the alleged attacker involved in the Liquid incident, saying the person may have left more traces than expected, according to monitoring cited by Bitcoin News. Mow said 「正义之网广泛且无法逃脱,不会放过任何人。」, which translates to a warning that justice is wide-reaching and inescapable. He also challenged the attacker’s reported demand to return bitcoin in exchange for a bounty, questioning whether it was wise to publicly admit taking bitcoin and then ask for a reward. Mow added that roughly $5 billion in Liquid-related assets, including L-BTC, Tether and real-world assets, belong to their respective issuers and holders, so they should not be used as the basis for calculating any bounty. He said that regardless of whatever else may be negotiated, all user assets must be returned in full.850
Blockstream2026-09-09 12:11:50White Hat Group in Liquid Incident Demands 10% Bug Bounty From BlockstreamA white hat hacker group tied to the Liquid exploit incident has accused Blockstream of spending only $1.5 million, or possibly no money at all, to secure assets worth $5 billion, according to monitoring cited by Bitcoin News. In a new on-chain message, the group said Blockstream should use its own funds to pay a bug bounty equal to 10% of the assets involved. It also warned that if Blockstream refuses to pay, holders would face a 15% loss. The group added that it plans to release the private key needed to decrypt earlier conversations with Blockstream. Previously, the group returned 3,400 BTC to the Liquid Federation, while about 600 BTC remain outstanding.960
Liquid2026-09-08 20:24:52Liquid Exploit Mints About 4,000 Unbacked L-BTC, Report SaysLiquid Federation said an attacker exploited a cache bug in Elements’ range-proof validation and minted about 4,000 L-BTC without reserve backing. The tokens were then exchanged for real BTC through SideSwap’s authorized peg-out route. Liquid’s functional entities treated the transactions as valid and released about 4,000 BTC from the federation reserve. Before the incident, Liquid held about 4,205 BTC, while its reserve fell to a low of 197 BTC before operations were suspended. The attacker, who identified as a white hat, has since returned 3,400 BTC. About 598.5 BTC remains outstanding. The report said no private keys were compromised and that the peg-out mechanism itself operated as designed. Liquid remains offline. Blockstream is preparing an emergency Elements v23.3.4 release and is working to restore the network with 1:1 Bitcoin reserve backing.930