ChainBleedv0.1 · open intel
← back to feed·INFRASTRUCTURE2020-11-13 · 5y ago
Incident · SLOWMIST

Liquid

Information Leakage
Estimated loss
VERDICT —OUT OF SCOPE
Root cause is infrastructure (DNS / cloud / database / third-party API) compromise, not on-chain contract logic. Pre-deployment source review would not surface this; coverage lives in cloud-security + supply-chain audit, separate discipline.
▰ METHOD
INFRASTRUCTURE
INFRASTRUCTURE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

Mike Kayamori, CEO of cryptocurrency exchange Liquid, posted a notice on the official website that a data leakage security incident occurred on the exchange on November 13. A domain hosting provider that manages a core domain name mistakenly transferred control of the account and domain name to a malicious intruder, allowing it to change DNS records, thereby controlling a large number of internal email accounts, and being able to partially damage the exchange’s Infrastructure and gain access to stored documents. After detecting the intruder, immediate action was taken to intercept and contain the attack to prevent further intrusions and reduce the risk of customer accounts and assets, while conducting a comprehensive review of the infrastructure. It can be confirmed that the customer's funds are safe, and the cold wallet based on MPC (Multi-Party Computing Protocol) is safe and has not been damaged. The relevant regulatory agencies have been notified of the intrusion and will continue to communicate in the next few days. The attacker may have obtained the user's email, name, address, and password. At present, Liquid is investigating whether the attacker has accessed the identity documents and photos submitted to KYC for verification, and will provide updates after the investigation.Liquid announced the final findings on January 20, 2021. Liquid stated that 169,782 items of user data including email addresses, names, encryption passwords, API keys, etc. have been leaked. Among them, the personal information that may be accessed illegally is the user who went through the KYC process before October 2018, such as the user's ID card, self-portrait picture, proof of address and other identity verification documents 28,639. Attack method (per SlowMist): Information Leakage. Reported loss: -.

Primary source
https://blog.liquid.com/security-incident-november-13-2020
Sourced from
slowmist
Technical record
chain
protocol
Liquid
bug_class
infrastructure
date_occurred
2020-11-13
loss_usd
source_id
sm:liquid::2020-11-13
Related — same bug class· infrastructure
2026-04-18
1mo ago
Kelp DAO
Infrastructure-level attack
infrastructure
$293.00M
OUT OF SCOPE
2026-04-18
1mo ago
DNS registrar for eth.limo
DNS hijacking
infrastructure
OUT OF SCOPE
2026-04-04
2mo ago
HypurrFi
Domain Hijacking
infrastructure
OUT OF SCOPE
2026-03-31
2mo ago
Steakhouse Financial
Social Engineering
infrastructure
OUT OF SCOPE
2026-03-19
2mo ago
Neutrl
DNS Hijacking
infrastructure
OUT OF SCOPE
2026-03-18
2mo ago
ETH
Neutrl
DNS Hijacking Attack
infrastructure
OUT OF SCOPE
ChainBleed — live web3 threat intelligence