A few months ago I was in Dusseldorf and they violently dragged a guy out of the U-bahn in Neuss because he had no ticket and no ID. I think they were more pissed about the ID than the ticket. The only other place I've ever seen such violence by public transport functionaries was in Moscow whenever they kick the homeless out of line 5.
What I mean? That being honest and not causing a public hostage situation is not as rewarding as just forcing the issue. In fact, I'm deep in the fucking red.
Even if Blockstream publicly states, "it's a bug bounty, we gave it to them" these btc have a huge target on them. There is no world where they don't have to take significant measures to obfuscate the source of these coins. Is there something I don't understand here?
inside job ? with rumours swirling around back, blockstream, employees, and finances for a while now, maybe a good old fashioned rugging was in play, lol
This re-enforces and just proves further that bitcoin is secure. With the inflation bug that was exploited in monero and now liquid, also rumored zcash in the past; the theme is that confidential transactions introduce complexity and a large attack surface for exploitation. What many said was one of Bitcoins flaws (lack of onchain privacy) actually is its strength. The trade-off of going without confidential transactions onchain, in exchange for solid transparency and security.
Privacy can still be achieved via coin control, coinjoin, payjoin, coinswap, lightning. This liquid hack only proves further how secure Bitcoin really is. Bitcoin does not use confidential transactions which resulted in hacks of things which do like monero, Liquid, (zcash?). I was a fan of liquid network, though going forward I lack confidence in confidential transactions on anything.
Seems like the negotiations between Blockstream and the hacker are still ongoing
Miguel Medeiros on X is doing a nice job of keeping track:
And then more recently:
Block stream statement:
source
https://twiiit.com/Blockstream/status/2097127976672342487
https://twiiit.com/_miguelmedeiros/status/2097124663960785165
How much bitcoin did they keep?
598BTC
I should never send a responsible disclosure again.
What does this mean?
Being a bad guy pays better.
not always but you are probably right 80 percent
I'm just doing the cope thing over here telling myself about how not being the bad guy is better for the soul.
split it 50/50
it’s what I should do when a stock is overpriced
I always think this when I pay for a tram ticket and then nobody cared
A few months ago I was in Dusseldorf and they violently dragged a guy out of the U-bahn in Neuss because he had no ticket and no ID. I think they were more pissed about the ID than the ticket. The only other place I've ever seen such violence by public transport functionaries was in Moscow whenever they kick the homeless out of line 5.
maybe they will give more back once some additional negotiation is completed 🤔
What I mean? That being honest and not causing a public hostage situation is not as rewarding as just forcing the issue. In fact, I'm deep in the fucking red.
stop being so pessimistic
stop being in the red!
Thank you for your service. I also need missile defense
Is there any world where these coins are free and clear? Seems like even if Block stream agreed not to pursue, there are other entities that will.
Apparently. If he could've taken away a genuine 5-10 BTC, then it wasn't the same case. But 598 BTC..I can't digest it. It's way too much.
Yes but I will not tell you how.
this is unbelievable
they actually returned most of the funds
I was thinking around 10 to 20 percent, 15 is the middle
Holy moly
Update:
Hacker sends the remaining 600 BTC back to themselves with message after encrypted back and forth with blockstream:
:(
I wonder what that is about?
I wonder if the 600BTC kept was an agreement or they just unilaterally decided their bounty was worth a 15% tip lol
3400 returned is better than 0 I suppose.
"Either we keep this much or keep it all and your network dies" makes the hat grey, not white imo.
This doesn't make sense to me:
Even if Blockstream publicly states, "it's a bug bounty, we gave it to them" these btc have a huge target on them. There is no world where they don't have to take significant measures to obfuscate the source of these coins. Is there something I don't understand here?
I think he'll return more. He must do it or he's not a white hat.
598 BTC isn't what a white hat would takeaway.
Agreed.
Doesn't sound like white hat behavior
Blockstream has a war chest but I doubt even they can fill that hole, I guess 1LBTC=0.85BTC for the foreseeable
So much for saving money on opening a Lightning channel
600 is quite the bounty. I imagine they will return more.
Somewhere Adam Back exhales
Plus Opensats will pay for the tokens ahahah
Now that this and the coldcard hack, how much is work on convenants really worth? A few 1000 BTC?
That's a large bounty. I think they should negotiate he should keep 10-20 bitcoin or something. Definitely a difficult situation.
Need that meme where they at the party 🥳 and bro is saying 'they don't know about the 4,000 btc hack'
And then it was mostly paid back
This is going down as ultimate bitcoin lore
What a crazy 48hrs
inside job ? with rumours swirling around back, blockstream, employees, and finances for a while now, maybe a good old fashioned rugging was in play, lol
Such crazy drama
This re-enforces and just proves further that bitcoin is secure.
With the inflation bug that was exploited in monero and now liquid, also rumored zcash in the past; the theme is that confidential transactions introduce complexity and a large attack surface for exploitation. What many said was one of Bitcoins flaws (lack of onchain privacy) actually is its strength. The trade-off of going without confidential transactions onchain, in exchange for solid transparency and security.
Privacy can still be achieved via coin control, coinjoin, payjoin, coinswap, lightning. This liquid hack only proves further how secure Bitcoin really is. Bitcoin does not use confidential transactions which resulted in hacks of things which do like monero, Liquid, (zcash?). I was a fan of liquid network, though going forward I lack confidence in confidential transactions on anything.