Liquid Exchange Suffered $80M Hack

  • Liquid has now paused deposists and withdrawals, and has started moving its assets into cold storage, as the attacker was able to gain access to their hot wallets.
  • While the exchange is yet to announced the extent of the breach, on-chain data shows that around $80 million worth of tokens has been moved to wallets associated with the hacker.
Hacker wear anonymus mask

Shutterstock

Major Japanese cryptocurrency exchange Liquid has suffered an attack that saw around $80 million worth of tokens being moved off the platform, Liquid said via Twitter on 19 August.

According to the announcement, only Liquid’s hot wallets were affected by the hack, and the platform is now moving all of its assets into cold storage. The exchange paused withdrawals and deposits shortly after it discovered the breach, and was quick to identify four cryptocurrency wallets that are believed to be connected to the hacker. Liquid tweeted:

While Liquid is yet to announce the extent of the hack, on-chain data shows the four wallets in question received more than $80 million worth of tokens. More precisely, the Bitcoin wallet received 106 BTC, while the Ethereum one was sent around $69 million worth of ETH and other ERC-20 tokens. The Tron and XRP addresses, on the other hand, have received digital assets worth over $10 million. The exchange has promised to provide regular updates as it continues its investigation into the breach.

Liquid is now working with various exchanges in an attempt to freeze the stolen funds. Shortly after Liquid’s announcement, KuCoin’s CEO Johnny Lyu said his platform had already blacklisted all the addresses that have been connected to the hack.

This is the second time the exchange has suffered a security breach in 12 months. Back in November 2020, Liquid warned its users that an intruder was able to gain access to their data, and while their funds were safe at the time, users were warned to be vigilant of any phising attempts.

Discussion
Related Coverage
Bored Ape Yacht Club Discord Channel Compromised
  • Bored Ape Yacht Club, Doodles, Shamanzs, and Nyoki Discord channels have all been compromised by a hacker, who attempted to use phishing links to steal NFTs.
  • Security researchers have noted that the attacker most likely used a Discord ticket tool to gain access to the NFT-focused channels.
April 1, 2022, 11:58 AM
bayc

Shutterstock

Liquid Suffers Security Breach, User Data Possibly Exposed
  • The exchange has said that its customers’ funds remain safe, and that the attacker was not able to access its MPC-based and cold storage crypto wallets.
  • Liquid customers were warned to be on the lookout for phishing attempts, as the intruder had access to data such as users’ emails, names and addresses.
Binance is Investigating a False “KYC Leak”
  • An unidentified individual has requested 300 BTC from Binance in exchange for withholding 10,000 photos that bear similarity to some of its KYC data.
  • The individual later leaked some images through a Telegram group, but they did not contain the digital watermark imprinted by Binance’s system.