The first COVID stimulus check was $1,200.
At the time, that bought ~0.18 BTC.
The proposed check is $5,000.
Today, that buys only ~0.06 BTC.
More than 4x the dollars per check, yet roughly 1/3 as much Bitcoin.
You are running out of time.
🚨 TODAY: The SEC issued an order granting temporary, conditional exemptive relief to Tokenized Securities Venues from the definition of “exchange” in the Exchange Act to trade tokenized NMS stock using innovative permissioned automated market makers and liquidity pools.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.
Liquid hack explained.
Liquid has confidential transactions that hide the amounts for improved privacy. A bug in how these transactions are validated caused inflation of Liquid BTC (L-BTC) and allowed hackers to empty the entire side chain.
Liquid nodes don't see the amounts of a confidential transaction, so to make sure that the transaction is still valid and doesn't cause inflation nodes check something called a balance proof and a range proof.
The balance proof establish that sum of the input amounts equal the output amounts, i.e., that "x L-BTC going in and x L-BTC going out". But there's a catch. Only relying on a balance proof isn't enough. You also need the range proof.
The range proof establishes that a hidden output amount falls within a positive range. That means a valid output must be at least 1 L-sat and at most 2^64 − 1 L-sats. Range proofs make sure that you can't mint "negative L-BTC".
Why is this even necessary? Remember, the amounts are hidden and a hidden negative amount would allow extra positive outputs to balance against it. Without a range proof, a transaction could say "I've put 1 L-BTC in, and I'm taking two outputs out: one with 4000 L-BTC and one with -3999 L-BTC)."
This is going to cause a disaster in a little bit.
Once the balance proof, the range proof, and other validations pass, a transaction is regarded as valid and can pass consensus. However, because especially the range proof is computationally expensive, Liquid nodes cache the result of a successful range proof in memory. Essentially, the node remembers "I saw this range proof before and it was valid, all good!".
In order to recognize the same range proof later on, you need to assign a label to it. This is called a cache key. This cache key is the actual cause of the bug.
The way this cache key was constructed allowed two different transactions to collide on their cache key. Essentially, one valid transaction (1 L-BTC in, 1 L-BTC out) had the same cache key as an invalid transaction (1 L-BTC in, 4000 L-BTC out).
Here's the hack: the attackers submitted the valid transaction (1 L-BTC in, 1 L-BTC out) first. Liquid nodes verified this transaction successfully, created a cache key called REKT and stored it in their cache. Then the attackers carefully crafted a second invalid transaction with (1 L-BTC in, 4000 L-BTC out) that created the same cache key REKT.
Instead of validating the second transaction and realizing that it printed money out of thin air, Liquid nodes found it in their cache and said "hey I saw this transaction before, everything is fine" and that caused the inflation.
The attackers then took their 4000 L-BTC and withdrew 4000 BTC onto the Bitcoin base chain.
Note: I might have gotten some details wrong, and I'm aware that I simplified quite a bit. I wrote this post to help people understand what happened. Please feel free to correct me in the comments or add more details below.
If someone hacks your Gmail, they don't need your passwords.
They can reset everything.
Bank. Instagram. Apple ID. Crypto. PayPal. Password manager.
Your Gmail isn't email.
It's the master key to your entire life.
Here's how to lock it down in 10 minutes: 🧵
Change your parents' router DNS to 1.1.1.2 and 1.0.0.2
Cloudflare blocks malware and phishing at the network level
Free antivirus that actually works. Nothing to install/update/disable
Ledger CTO, Charles Guillemet, has already addressed this in a comprehensive thread (see link below).
As part of our standard security process, the Ledger Donjon, our in-house security research team, identified a bug affecting certain clear signing flows in the Ledger signer Ethereum app and patched it on August 12th, two weeks before public disclosure. This reflects our security-first approach: continuous internal research, rapid remediation and responsible disclosure.
Proactively discovering and patching vulnerabilities through regular firmware and app updates is routine at Ledger. The Donjon leverages advanced AI on an ongoing basis to find and fix issues as rapidly as possible, minimising risk to users.
If you're on the latest version of the Ethereum app (1.22.2) the patch is applied and you benefit from the fix. This highlights the importance of keeping your signer firmware and apps always up to date.
More details: https://t.co/55a9aUnYg7
[What about Ledger Nano S users?]
This specific Ethereum bug didn't apply to the Ledger Nano S, but it's recommended to always update to the most recent supported versions of apps and firmware.
🚨Critical security update for LEDGER hardware wallets
A critical vulnerability has been identified in the Ethereum app on Ledger hardware wallets. It could allow a malicious application to alter the details of a transaction during signing, without this being visible on the device screen.
This has been fixed in Ethereum app version 1.22.2. If you use a Ledger device, please update ASAP
While you're in there, it's also good practice to make sure Ledger Live and your device firmware are fully up to date.
Like many open source Bitcoin projects, CLN has received a number of AI-generated CVE reports from multiple sources over the past 10 days. Our small team, together with several invaluable open source contributors, has been working intensively to validate and triage these reports and develop fixes where needed.
We’re now working through a broader remediation strategy. The first step is a point release containing many of these fixes, and we will strongly recommend upgrading. We’re aiming to have an initial version of the point release available within the next few days.
If CLARITY continues to stall because of Democratic obstruction, the @CFTC will utilize its existing authorities to begin establishing a regime for crypto asset markets. We owe it to the American people to do so.
Here's how we'll get it done ⬇️