# "private key" (compromised OR stolen OR leaked) — X 热门讨论 (2026-09-24 05:44 UTC)
## @Kryp_Toon (KrypToon) · 09-23 12:00 · ♥20 ↻1 💬14 🚨 The $320M Liquid Incident Was Not Primarily a Key-Management Failure
The Liquid Network incident is a useful reminder that bridge security is wider than private-key security.
Roughly 4,000 BTC, worth about $320 million at the time, was withdrawn from a federation wallet after a transaction-validation vulnerability reportedly allowed unbacked L-BTC to be created and exchanged for real Bitcoin. Blockstream said the relevant key itself was not compromised.
That distinction matters. A bridge can protect keys perfectly and still fail if its software accepts an invalid state transition.
Most of the funds were later returned, and patched software was deployed, but the architectural lesson remains: custody, issuance logic, validation rules and emergency controls all have to agree on what “backed” means.
For bitcoin:native infrastructure, proof of reserves is only one layer. The software enforcing redemption and issuance assumptions is another.
Secure keys cannot compensate for incorrect validation logic.
Disclaimer: Security analysis only. Incident figures can change as recoveries, reconciliations and investigations continue.
bitcoin:native @Blockstream #Bitcoin #LiquidNetwork #BridgeSecurity #Cybersecurity https://x.com/Kryp_Toon/status/2102729696979079345