Normal view

There are new articles available, click to refresh the page.
Today — 13 September 2026Main stream

Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up

13 September 2026 at 09:27

Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet.

The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up appeared first on SecurityWeek.

Before yesterdayMain stream

Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

11 September 2026 at 21:50

Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket.

The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityWeek.

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

11 September 2026 at 08:48

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek.

Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

11 September 2026 at 04:47

Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model.

The post Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion appeared first on SecurityWeek.

Tech In Plain Sight: Meet The Robot That Does CPR

10 September 2026 at 10:00

Usually in Tech In Plain Sight, we talk about technology you probably see every day, even if you don’t notice it. But we hope you don’t get to see one of the latest crop of medical robots, such as the LUCAS chest compression system. If you watch the popular TV series “The Pitt”, though, you may have caught a glimpse of one of these medical marvels. They aren’t fiction. They are very real devices.

Calling them robots might be stretching the definition a little. They don’t roam the halls looking for patients. But once attached to someone in cardiac arrest, they can take over one of the most important — and physically demanding — parts of CPR: chest compressions.

Keep The Blood Moving

When someone’s heart stops pumping blood, time is critical. CPR doesn’t normally restart the heart on its own. Instead, chest compressions produce enough blood flow to keep oxygen reaching the brain and heart while rescuers work on the underlying problem and, when appropriate, use a defibrillator.

Doing that well is harder than it looks on television. Current American Heart Association guidelines call for adult chest compressions 100 to 120 times per minute, at least 5 cm deep but generally no deeper than 6 cm, while allowing the chest to recoil fully between compressions. Interruptions should be kept to a minimum.

That’s hard physical work. In fact, studies show compression depth begins to fall after only about 90 to 120 seconds, which is one reason CPR teams normally swap compressors every two minutes. But a robot doesn’t get tired.

Meet LUCAS

LUCAS stands for Lund University Cardiopulmonary Assist System, reflecting the device’s origins in Lund, Sweden. Early versions entered clinical use around 2002-2003 and were pneumatically powered. Later versions replaced the compressed-gas system with an electric motor and battery.

The current LUCAS 3 looks something like a small drill press straddling the patient as you can see in the video below. A backplate goes beneath the torso, and a frame locks onto it. An electrically driven piston presses a suction-cup-like pad against the sternum. Internally, the motor drives a belt and ball screw that moves the piston up and down.

Factory settings are around 102 compressions per minute and roughly 53 mm compression depth for a typical adult, although parameters can be configured.

Beyond tirelessness, another obvious advantage is that LUCAS doesn’t need hands. Medics can deal with ventilation, drugs, defibrillation, IV access, and the dozens of other things occurring during a cardiac arrest. More importantly, the device can keep compressing while a patient is being carried, wheeled through corridors, or transported in an ambulance — situations where doing good manual CPR is awkward and sometimes dangerous to the practitioner.

So Does It Save More People?

You might reasonably expect perfectly regular machine CPR to beat a tired human. Large randomized trials haven’t demonstrated that, however. The 4,471-patient PARAMEDIC trial found 30-day survival of 6.3% with LUCAS versus 6.8% with manual CPR, not a statistically significant difference. The 2,589-patient LINC trial similarly found essentially identical four-hour survival — 23.6% versus 23.7% — and no significant improvement in longer-term neurological outcomes.

That doesn’t make the machines useless. It says something slightly different: high-quality mechanical CPR hasn’t proven superior to high-quality manual CPR as a routine replacement. The International Liaison Committee on Resuscitation currently recommends against routine mechanical CPR, while specifically noting that it can be a reasonable alternative when sustained manual compressions are impractical or would endanger the practitioner.

One issue is setup. Installing the machine adds a time penalty: compressions must stop briefly while the backplate and mechanism are positioned. Good training is essential to keep that interruption short. Another problem is that some studies show potential links to higher rates of internal chest injuries, such as bleeding around the lungs. There have also been rare device malfunctions or power failures that can compromise care.

Not The Only Game In Town

LUCAS isn’t alone. ZOLL’s AutoPulse takes a very different mechanical approach. Instead of a piston pushing on one spot, a motor tightens a broad load-distributing band around the patient’s chest.

There’s also the German corpuls cpr, which returns to the piston idea but uses a cantilevered single-arm mechanism. That leaves much of the chest unobstructed and makes the system useful during procedures such as cardiac catheterization.

So perhaps these aren’t quite the autonomous robot doctors science fiction promised us. But when your heart has stopped, and a machine is tirelessly pumping your chest a hundred times a minute while the medical team works around it, you probably won’t complain. We hope you don’t have to find out.

We’ve seen DIY devices, though certifying medical devices for actual use isn’t for the faint of heart. Robots can also help train humans to do better CPR.

Featured image is a still from the instructional video “Physio-Control LUCAS 3 Chest Compression System – Hospital Use” by MFI Medical.

The Quantum Issue: WTF Is Quantum Computing?

By: Shinobi
10 September 2026 at 09:00

Bitcoin Magazine

The Quantum Issue: WTF Is Quantum Computing?

What is quantum computing? How is a quantum computer different from a regular computer? What relevance does this have to Bitcoin?

New Bitcoiners have been inevitably bumping into these questions and having to confront the issues they dredge up regarding Bitcoin’s exposure to what is very much an existential threat to its existence if a viable quantum computer were to be developed. 

The ability to own bitcoin rests on the foundational assumption that without directly leaking a copy of it, no one but the person who possesses a private key can sign to transact with coins secured by that key. Quantum computing calls that assumption into question. 

Quantum computers are not just “computers, but faster.” They function in a very fundamentally different way from a classical computer, and as such they are much more efficient than classical computers at very specific kinds of computations. Now obviously, I’m not going to actually explain how quantum computers work in minute detail within four pages, but I will give you the core intuition of how they are fundamentally different from a classical computer. 

So let’s take a look at how both kinds of computers interact with things like large cryptographic keys. 

Classical Computers

Everything stored in a classical computer (or just computer from here on out) is stored as a series of 1s and 0s. Each bit (1 or 0) is precisely a 1 or 0; there is no ambiguity. When a piece of data is stored, it’s 1s and 0s. When a piece of data is manipulated or modified, it is done bit by bit, step by step, on each 1 or 0. 

That is how a computer works. It linearly, one step after the other, modifies the discrete unambiguous pieces of data that it is storing. It can’t skip ahead, or shortcut (in terms of the steps it’s taking, not more efficient ways to do things mathematically), it has to go through the steps of whatever computation it is doing one by one. 

When you generate a private key using a computer, it acquires a random value (you inputting dice, general user input, randomness from device hardware, etc.) and stores that in memory as 1s and 0s. From there it has to multiply this value by the elliptic curve’s generator point to get a public key. This is accomplished with an algorithm, that boiled down to its most basic level, is literally instructions on what bits to take, how to modify them, what circuits to “push” them down on a physical level to accomplish that, and in the end put the new value that has been modified bit by bit back into memory. 

There are other steps to arrive at an actual valid address, but for the purposes of this article those are not necessary to go into (but they are just like the above step, just step by step instructions on how to modify 1s and 0s in memory). 

So what if someone wanted to use a computer to guess someone else’s private key? 

There are 2256 possible private keys. That’s 115,792,089,237,316,195,423,570,985,008,687,907,853,269,984,665,640,564,039,457,584,007,913,129,639,936 different possible keys. 

A computer would have to try every single one of those possible private keys, one after the other (or however many at a time it can do in parallel), step by step following the exact instructions above for generating keys. The more of them you try to check in parallel, the more computing power you need, with no ability to find any shortcuts around that cost. 

The less computing power you want to use, the more time it will take, the less time you want it to take, the more computing power you need. 

This is an impossible task to accomplish with a computer. On one side you have a computation cost that every computer on Earth is not enough to pay, and on the other side you have a cost in time that is so high every star in the universe would die before you checked them all. 

To actually accomplish your goal, you need another option besides checking one by one linearly or in parallel. That’s where quantum computing comes in.

Quantum Computers

Quantum computers don’t work with discrete states. Everything is precisely a 1 or a 0. The most basic piece of information in a quantum computer is a qubit (the quantum version of a bit). Unlike a bit, a qubit is in a superposition where it is both simultaneously a 1 and a 0. It only settles into one or the other discrete states when it is observed

This is one of the key building blocks that allow a quantum computer to compute differently. The other is entanglement. Qubits aren’t just stored in isolation, the physical atoms representing them and collapsing to a discrete state when observed are entangled together. This means when entangled atoms are observed and collapse to a single state, the entangled atoms collapse to the same state, no matter how far apart they are. 

Now here’s where things get weird, and I’m going to have to get a little hand-wavy; you should still walk away with an intuitive understanding of why quantum computers are fundamentally different from a classical computer. An algorithm on a classical computer is a set of instructions to take a specific set of bits, and step by step modify them according to the algorithm’s instructions, until finishing and outputting the finished set of new bits. So the algorithm step by step takes one discrete state and turns it into another. 

Qubits don’t store discrete states until they are observed and collapse to one. They store probabilities. When you have a set of qubits entangled of any given size (like in this hypothetical case 2256), each given possible state that it collapse to has a certain probability of collapsing to that given state. 

Quantum algorithms, rather than being step by step instructions to operate on discrete states, are a set of instructions on how to operate on those entangled qubits in a way that alters the probabilities of different outcomes. Constructive interference is used to increase the probability of a correct outcome, and destructive interference to decrease the probability of incorrect outcomes (note that this is NOT the noise or interference that makes it difficult for physical quantum computers to function accurately, that is a different concept). 

So while a classical computer would have to check each individual private key one by one to find the one matching a specific public key, a quantum computer can simply run a few times using the right algorithm and arrive at the correct answer. It does not do this by “checking all the possibilities at once.” It simply modifies the probabilities of what a superposition will collapse into. 

This is why a quantum computer could break the assumptions underlying elliptic curve cryptography, and a classical computer could not (and it is also why quantum computers are only useful for certain types of computations with a massive possible space of answer candidates to check). 

Don’t Panic

This fundamental difference between classical and quantum computation means, that yes, if a viable quantum computer is actually produced, that functions correctly, then the underlying assumption that secures all Bitcoiners’ individual bitcoin is broken. All of those funds are insecure. 

Yes, this is a serious risk if such a device is actually manufactured, and it works, but we are not entirely unprepared. We understand the problem, we understand the exposure, and a good number of possible solutions to many different facets of the problem are coming together. 

Breathe, and relax. Through the rest of this issue we are going to walk you through the whole problem. 

This piece is featured in the latest Print edition of Bitcoin Magazine, The Quantum Issue. We’re sharing it here as an early look at the ideas explored throughout the full issue.

This post The Quantum Issue: WTF Is Quantum Computing? first appeared on Bitcoin Magazine and is written by Shinobi.

Hunting the Wild Vibrotruck

9 September 2026 at 11:18

A few weeks ago, my wife was out walking the dog, and she sent me four or five photos of small orange boxes planted all around our neighborhood. (OK, I’ll bite!) They had little cards on them explaining that they were geophones, and a QR code on them that lead to a website with all the details. Munich was getting a large-scale seismic survey to map out our underground water, with the aim of using it for geothermal heat and power in the near future.

How do you map up to five kilometers under the earth? You pound the ground, sending shockwaves downward, and then listen for their reflections. At the boundaries between different layers, the change in the speed of sound in the different media cause reflections. Calculating the time it took for a given reflection to reach you lets you figure out how deep the layer boundary is.

The seismic survey procedure goes like this: geophones are set out at roughly 20 m intervals in lines spaced around 300 m apart that run roughly north-south, while “vibrotrucks” drive a roughly east-west course, creating mini-earthquakes every 20 meters along the way. Covering a surface of 1,000 km^2 with over 120,000 sample locations and exciting them 86,000 times is going to take a while. Lucky for me, they started in my part of town.

Hot Water

Because the earth is essentially a ball of hot molten metal with a thin and crispy outer crust, and because there is radioactive decay going on even within the crusty bit, temperatures rise as you dig down: roughly 30 °C per kilometer. And Munich has this fantastic source of water that’s folded under the earth in a layer that dates back to the Jurassic, which makes it both low in dissolved minerals and sitting just around 3 km down: at 100 °C. This turns out to be the sweet spot in terms of difficulty of drilling and heat gained from doing so.

Blessed with hot water underground, the question is how to best use it. The plan at the moment is to situate a number of geothermal plants around the city, drill relatively large bore holes at each site that reach down 1 km to 2 km, and then drill diagonally down after that to spider out into a larger source of water. This “extended reach drilling” pulls from a larger heat source, prevents cool spots, and has only recently become technologically feasible.

Which brings us to the GIGA-M study. A 3D map of the underground will help plan out where to put the geothermal plants, in which directions the runners will need to be drilled, and generally how to best coordinate the resource. There were a number of individual smaller surveys done over the last 20 years, and Munich and the surroundings already have a number of geothermal plants, but this survey aims to fill in all of the gaps.

The Hunter and His Prey

It was a Thursday morning when my wife thought she heard some pounding and humming outside. She was wrong, but it got us to look at the online map, and while they weren’t in our neighborhood just yet, they were probably within easy driving distance. I threw my camera and tripod in the car and headed out.

The Big Vibrotrucks

Out in the country, just outside of Grossdingharting (you can’t make these names up!) I spotted a plume of dust rising up from a field. Was it just a farmer tilling? Or was it a vibrotruck? I drove through the woods on a logging road, and when I came out, I was nearly face-to-face with the beasts.

They were loud, and I felt the rumble when I stepped out of the car, so I ran up and asked if I could film it. They said “sure”, and I set up the tripod. The first video I shot, apparently I hadn’t screwed the camera down hard enough in the tripod, and it vibrated loose. So I ran another 20 m further and tightened everything down.

I’m not going to lie: it was exceedingly loud and very exciting. I drove back home and couldn’t wait to review the footage.

The next morning, I heard the same sound outside my own house. They were driving vibrotrucks around in the field about a block up the street. I grabbed the camera and ran out barefoot to get footage. And then Saturday morning, while cooking blueberry pancakes for the family, they drove up my street. Am I stalking the vibrotrucks, or are they stalking me?

An engineer asked if they could stand in our front yard, so I took my chance to bombard him with questions. He seemed stoked to talk about it.

Geophones and Vibrotrucks

When you stand next to one of these things, first it shakes, and then you can hear a bassy tone, and then it rises and stops. They’re obviously doing a frequency sweep, much like you would use a sonar chirp to help disentangle the multiple reflections from one another.

The sweep means that even if they receive two reflections at once, they will hear two different pitches because one signal traveled further than the other, and comes from the earlier, lower-pitch part of the impulse. It also makes for a very easy to find signature. Correlating these times of flight across the entire array of geophones gives a 3D map of the underground layer discontinuities.

You can see from a cleaned up version of the audio that they’re sweeping from something like 6 Hz up to maybe 96 Hz.  The lower end sounds like distinct hammering, and the top end a humming. Here is another video, with filtered audio. Because you feel the vibrations through your feet and in your chest, the live experience is a little bit like this with more noise. Play on good headphones or with a subwoofer for maximum effect.

Of course, the time of flight matters. I asked if each geohpone had a GPS timebase, and the friendly engineer told me that they individual geophones don’t – too expensive – but that when they install one, they connect it to a laptop with GPS that records the location and sets the geophone’s clock. When they harvest them, they record the location again, dump the time to verify that the clocks haven’t drifted too much, and then pull down all of the recorded timestamped data.

Why do they drive around in pairs? It’s simply because they make twice the vibration. The two trucks are actually synced together in phase, so they emit as one. The trucks have a GPS-disciplined clock inside, so they know exactly when they start each cycle and can derive the time-of-flight to all of the receiving geophones. The rest is math.

He also mentioned that it was too bad that I only got to experience the smaller “urban” vibrotrucks like the one outside my house. I kept my mouth shut – nobody needs to know that I’m a vibrotruck stalker.

Why hostile state cyber activity is now a day-to-day business risk

9 September 2026 at 10:53

Christopher Clark, Cyber Security Incident Response Team Director, Thrive 

Geopolitical escalation can become a cyber security problem for businesses far more quickly than many boards expect.

The National Cyber Security Council (NCSC) has warned that UK critical infrastructure faced more than 200 cyber incidents over the past year, with around three-quarters believed to be linked to state actors. Analysis of the conflict involving Iran has also found cyber retaliation following military escalation within hours, bringing events overseas much closer to the day-to-day reality of UK organisations.

That risk has already been demonstrated on UK soil. In July, a cyber-attack reportedly linked to Iranian hackers forced a small UK power generator offline for four days. The government said there was no risk to the wider energy system, but the incident shows how quickly geopolitical cyber activity can translate into operational disruption.

Energy, healthcare, water and telecoms remain obvious targets because disruption can affect essential services. Yet, hostile state activity does not stop at the boundary of critical infrastructure.

Hostile state risk extends beyond critical infrastructure

A business does not have to be an obvious target to become one. It may be connected to a larger customer, supplier, regulator or public body that an attacker ultimately wants to reach. In other words, you do not have to be the objective. You just have to be the way in.

There is also the risk of spillover. Targeting can follow politics rather than the size of a company or its balance sheet. If an organisation has operations or suppliers connected to a live conflict, it can become collateral even when nobody set out specifically to target it.

Businesses also need to reconsider what hostile state activity is likely to look like inside their own environments. The most significant intrusions are not necessarily the noisiest.

Security teams may be watching for malware, failed logins or a sudden increase in DDoS activity. Capable attackers increasingly use valid credentials and legitimate administration tools, allowing malicious behaviour to resemble normal activity.

There may also be no obvious warning to investigate. If the plan is to wait for one, the organisation may already be too late by the time it appears.

A better working assumption is that a capable actor could already be inside, or could get in without immediately triggering an alert. The question then becomes what they can actually do once they have that foothold.

Trusted technology can create the same problem. Management platforms and legitimate system tools can be repurposed by attackers, while compromised software packages can provide access to many organisations at once. Activity entering through a tool or supplier that the business already trusts may attract less scrutiny because it appears legitimate.

The same principle applies to suppliers. If a connected partner has been compromised, one of the first questions should be what has been done to separate that organisation from your own environment. Continuing normal access without understanding what happened risks transferring their exposure into your network.

Organisations should know how they would isolate an affected supplier and what evidence would be required before connectivity resumed. They may need confirmation of how the attacker entered and which systems were affected, alongside assurance that the access has been removed. Shared applications or other connections may have to remain unavailable until that information is clear.

That can be uncomfortable for the business, but restoring connectivity too quickly can create a much bigger problem later.

The time available to make these decisions is shrinking. Threat actors can analyse newly disclosed vulnerabilities and move to exploitation quickly, with AI making parts of that process faster. In some cases, organisations can be exposed within hours of a vulnerability becoming known.

Patch management therefore cannot always wait for the normal maintenance cycle. Teams need to know which vulnerable systems create the greatest risk and be ready to prioritise them when a new vulnerability emerges.

Geopolitical risk can also outlast the immediate conflict.  A ceasefire does not automatically remove access established during a period of heightened activity, nor does it mean proxy groups will stop operating. Attackers have good reason to preserve a foothold that may be useful later. I have seen access remain available inside an environment for three years or more.

That is why an easing of geopolitical tension should not automatically be treated as a reduction in cyber risk.

Containment depends on preparation and experience

Preparation has to focus on containing an attacker as well as keeping them out. Standing privileges should be kept to a minimum, networks should be segmented so an attacker cannot move freely towards critical systems or backups, and offline backups need to be regularly tested.

Organisations also need a clear view of their external attack surface and where their greatest points of exposure lie. Regular tabletop exercises should use realistic scenarios informed by current threat intelligence.

If an attacker gained access through a VPN or compromised supplier, what could they reach next? How far could the incident spread? And who has the authority to cut them off?

That authority needs to be clear before an incident. Time can be lost when technical teams know what needs to happen but must wait for decisions on whether systems can be disconnected or business processes interrupted.

Experience is equally important. Frameworks provide structure, but serious incidents rarely follow a script. Responders who have handled repeated compromises understand where investigations can stall, which decisions cannot wait and what needs to be secured before systems are safely returned to service.

For many organisations, maintaining that level of incident response experience entirely in-house is difficult. What matters is having access to people who have dealt with incidents under real operational pressure and can apply that experience quickly when normal assumptions no longer hold.

Hostile state cyber activity should now be treated as a routine business risk rather than something considered only when international tensions make the headlines.

Organisations should be asking a more immediate question: if something gets through today, how far can it spread before we stop it?

Answering that question before an attack happens can make the difference between a contained security incident and a prolonged operational crisis.

The post Why hostile state cyber activity is now a day-to-day business risk appeared first on IT Security Guru.

US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

9 September 2026 at 08:32

Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.

The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek.

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

9 September 2026 at 06:00

Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block.

The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek.

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

8 September 2026 at 15:20

The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities.

The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek.

Liquid Gets 3,400 BTC Back After On-Chain Talks; White Hats Keep 598.5 BTC

By: Juan Galt
7 September 2026 at 18:02

Bitcoin Magazine

Liquid Gets 3,400 BTC Back After On-Chain Talks; White Hats Keep 598.5 BTC

The “White hat” party that withdrew nearly 4,000 bitcoin from the Liquid Network federation wallet on Sunday returned 3,400 BTC to the wallet on Monday. About 598 BTC, or 15% of the consolidated pile, stayed at the same holder address as an implied bounty fee worth 48 million dollars.

The return transaction (bc49a46d), confirmed at 16:09 UTC on September 7. It returned exactly 3,400 BTC to the labeled Liquid peg script address and sent the 598.5 BTC change back to the “White hat” hacker address as change. 

The transfer followed a day of messages written into Bitcoin blocks. The White hats first published transaction on chain with a message in the OP_RETURN arbitrary data field “contact us on chain”; the message came from the address holding the 4000 BTC taken from the Liquid Network. 

A Blockstream-linked address answered with “Please contact security@blockstream.com”. Later notes from that sender carried Electrum-encrypted payloads and PGP signatures that can be verified against Blockstream’s published security key.

In block 965869, the White hats asked in the clear text whether sending “most” back to the federation script was acceptable. The 1,000-sat output on that transaction was only a message carrier. 

Soon after, the White hats wrote “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.” followed by an encrypted blurb of text to Blockstream’s PGP key

In the same block, a clear-signed reply from the Blockstream sender said “Yes, thank you.” Hours later, the same Blockstream posted another clear-text note: “Bridge nodes are patched, safe to return the funds”. 

Minutes after the 3,400 BTC landed. The white hats sent back 85% of the funds, keeping 15% as an implied finder’s fee. The choice was celebrated by some on X as ‘better than keeping 100%’ while others were a bit shocked at the amount. While 15% might sound reasonable, the total sum is so large that it nears $50 million at today’s prices. Blockstream was clearly not happy about the finder’s fee, as four encrypted messages followed onchain a few hours later, likely after the main fires had been put out at the office and the lawyers had a chance to have a say in the matter. An hour later, one more encrypted message was posted from Blockstream.

The White hats replied with two encrypted messages. Blockstream replied once an hour later. Then the White hats published a simple yet meaningful “ 🙁 ” sad face emoji. This emoji does a lot of work. It suggests that negotiations did not go well over reducing the size of the bounty. Blockstream wizards are clearly ‘big mad’ about the size of that finder’s fee. What exactly was said in those encrypted messages is not known and Blockstream has made no public statements on the matter. But we can only assume the saga is not over.

The full chat can be easily followed on this vibe-coded site (by yours truly). A couple of other researchers are keeping tabs on the conversation and on-chain data, such as Sjors’s GitHub gist and Alex Thorn from Galaxy Research

Liquid’s Sunday statement is still the network’s last official account post: purported whitehats withdrew about 4,000 BTC through the SideSwap peg-out path, the PAK itself was not compromised, other issued assets were unaffected, and the sidechain was paused. Liquid and Blockstream had not posted a new statement on the 3,400 BTC return as of this writing. SideSwap had said the L-BTC in the original peg-out “came from an Elements bug.” 

This post Liquid Gets 3,400 BTC Back After On-Chain Talks; White Hats Keep 598.5 BTC first appeared on Bitcoin Magazine and is written by Juan Galt.

❌
❌