虎嗅

The Illusion of Crypto Asset Security: When Hackers, AI, and “White Hats” Rip Off the Veil of Deception

原文:加密资产安全幻象:当黑客、AI与“白帽”撕下底层的遮羞布

The “Veil” of the Crypto World Has Been Torn Off: A Deep Review of Trust, Code, and Human Nature

Hello everyone, I’m your financial journalist. Today, we’re not talking about how much Bitcoin has risen in value or which celebrity has bought some more coins, but about a “shocking case” that occurred in September 2026.

This article comes from the public account “Skei Suisu Kan,” which uses a very sharp pen to reveal the cruel realities beneath the glamorous facade of the crypto world. In simple terms, **the crypto world, which once made you think, “As long as my technology is strong enough and my equipment is expensive enough, my money is absolutely safe,” is now experiencing an unprecedented crisis of trust.

To make it easier for everyone to understand, I’ve broken down this long article into five key parts and explained them in plain language: What exactly happened? Why is it so serious? And what should we, ordinary people, think about it?

---

1. Review of the Core Incident: 4,000 Bitcoins Disappeared “Out of Thin Air,” Yet the Hacker Claims to Be a “Good Person”?

[Plain Language Summary]

It’s like you go to the bank to deposit some money, and the bank says, “Don’t worry, we have a safe.” But one day, a thief slips into the safe, doesn’t break the lock, doesn’t knock down the wall, and instead uses a small bug in the bank’s system to print 4,000 fake deposit receipts. Then, with these fake receipts, the thief exchanges them for real cash at the counter. Even more absurdly, after the theft, the thief leaves a note on the wall that says, “I’m a white-hat hacker (a good hacker); fix the bug, and I’ll return the money, but I’ll charge a 10% fee.” The bank says, “This is robbery, not bug fixing!” In the end, the thief returns part of the money but keeps nearly $50 million as a “fee.”

[Detailed Explanation]

  • Who was the victim? Liquid Network. This is a “sidechain” of Bitcoin (you can think of it as a parallel road or additional lane for Bitcoin), operated by Blockstream, with the support of more than 80 major exchanges. It was created to solve the problem of slow Bitcoin transactions.
  • How was it hacked? The hacker didn’t break the password or steal the private keys. Instead, they exploited a vulnerability in the underlying software to create non-existent tokens (LBTC). Then, through the normal redemption process, they exchanged these fake tokens for real Bitcoins.
  • Why is it so scary? Because the entire process appeared “legal” to the system. It’s like you insert your card into an ATM, and due to a machine malfunction, it gives you more money than you deposited; from the machine’s perspective, the transaction was successful.
  • What was the outcome? Blockstream refused to pay the ransom, insisting it was theft. In the end, the hacker returned most of the money (about 3,400 BTC) but kept 598 BTC (about $47 million). This wasn’t just a loss of money; it was also a collapse of industry credibility. If even a platform regulated by a consortium of giants can have 95% of its reserves stolen, who can ordinary investors trust?

---

2. The “Illusion” of Hardware Wallets: The Safety Box You Think You Have Is Actually Paper-Thin

[Plain Language Summary]

Many people think, “I won’t keep my coins on an exchange; I’ll store them in a hardware wallet (a device like a USB flash drive) offline, so no one can steal them.” This article shows you that that’s completely wrong. Hardware wallets weren’t hacked; what was attacked were people and manufacturing defects.

[Detailed Explanation]

Here are two real cases that are quite alarming:

  • Case 1: People Are the Biggest Vulnerability (January 2026)
  • A wealthy individual lost $284 million. The hacker didn’t hack his device; instead, they pretended to be a customer service representative from Trezor (a well-known hardware wallet brand) and, through carefully crafted conversations, tricked him into giving them his recovery phrase (equivalent to a bank card password, ID, and fingerprint).
  • Lesson: No matter how advanced the lock, it can’t prevent the owner from giving the keys to a scammer. Social engineering is more dangerous than hacking skills.
  • Case 2: Hardware Has Inherent Defects (August 2026)
  • Coldcard, another well-known hardware wallet, was exposed to a major bug. Due to a configuration error during software compilation, the “true random number generator” responsible for generating random numbers was turned off, and a predictable pseudo-random number generator from a computer was used instead.
  • Consequence: Attackers didn’t need to steal your device; they could calculate your private key on a regular computer. As a result, 5,000 wallets were robbed, resulting in a loss of over $110 million.
  • Simple Metaphor: You bought a “bulletproof” lock, but the manufacturer forgot to install a spring when it left the factory, so the lock core was loose. You think you’re using high technology, but you’re actually using a plastic lock.

[Core Point]

“Offline cold wallets” are no longer “cold” in the mathematical sense. Hardware is not an absolutely secure fortress; it’s just an additional layer that can be bypassed or has its own flaws.

---

3. The Violence of the Physical World: When “Digital Assets” Become a Target of Robbery

[Plain Language Summary]

If you weren’t scammed and used a reliable hardware wallet, are you safe? No, there’s still the oldest and most brutal threat: physical coercion (using force). This means kidnapping someone, breaking into a place, and forcing them to transfer assets.

[Detailed Explanation]

  • Statistics: In the first half of 2026, losses due to physical coercion exceeded $30 million. The proportion of such attacks soared from 14% last year to 37%.
  • Precise Description: Hackers no longer act randomly; they use information from the blockchain (how many coins you hold), leaked databases, and social media (where you live, your sleeping habits, what coffee you drink) to create a detailed “victim profile.”
  • Frightening Reality: When your wallet address is marked as belonging to a “whale” (someone with a large amount of assets), your digital wealth is no longer just abstract code; it’s like a “reward notice” posted on your forehead.
  • Cruel Comparison: Asymmetric encryption (a mathematical algorithm) is theoretically strong, but in the face of physical force, it’s worthless. You can have the most complex password in the world, but if someone threatens you with a knife and asks you for it, the password becomes useless.

[Core Point]

Cryptocurrency has shifted the risk from “banks being robbed” to “individuals being robbed.” While you have complete control over your assets, you also bear the risk of personal safety.

---

4. The “New Normal” of 2026: The Foundation Is Unbroken, but the Upper Layers Are in Ruins

[Plain Language Summary]

Looking at the long term, 344 security incidents occurred globally in the first half of 2026, resulting in losses of $1.3 billion. But here’s the key detail: the underlying code of Bitcoin (the consensus protocol and cryptography) has never been breached. What was attacked were all the “application layers” built on top of Bitcoin—exchanges, smart contracts, cross-chain bridges, and hardware wallets.

[Detailed Explanation]

  • Shift in Attack Focus: It used to be impossible for hackers to break Bitcoin itself (e.g., cracking the SHA-256 algorithm); now they target economics and human nature.
  • Common Tactics:
  • Smart Contract Vulnerabilities: A single mistake in the code can lead to the loss of funds.
  • Lightning Loan Attacks: Borrowing a large amount of money, manipulating prices, and then returning it with a profit.
  • Predictor Manipulation: Manipulating the data sources that influence Bitcoin prices.
  • Example: On the Cronos chain, the Tectonic protocol was exploited; attackers increased the token price by 100 times in 20 minutes, then borrowed the assets and fled, causing a loss of $75 million.
  • Deeper Logic: We thought the crypto world was “trustless” (no need to trust banks or intermediaries), but trust hasn’t disappeared; it’s just shifted. We used to trust banks and courts; now we trust code, hardware manufacturers, random number generators, and customer service representatives.
  • Conclusion: Code, hardware, and human nature are more vulnerable to attack than banks. We paid a high price for “decentralization” but got a weaker foundation of trust.

---

5. The Embarrassment of Social Cryptocurrencies: The Apple Phone Is Still There, but No One Dares to Bet Their Whole Wealth on It

[Plain Language Summary]

As mentioned at the beginning of the article, there’s a group of people who all have an Apple phone from Europe or the US, specifically used to store cryptocurrencies. It’s not just a tool; it’s also a form of “social currency” that shows they have money, taste, knowledge, and belong to a certain circle.

[Detailed Explanation]

  • The Original Purpose of Isolation: Using a less-used phone with a clean number was to reduce the risk of social engineering attacks.
  • Irony of Reality:
  • The Liquid incident shows that chain mechanisms can be manipulated, and your isolation can’t protect you from systemic flaws.
  • The Trezor/Coldcard incidents show that hardware can be bypassed, and your isolation can’t protect you from manufacturer bugs or scammer tactics.
  • Physical coercion shows that isolation is meaningless in the face of violence; it can’t protect you from someone with a knife.
  • Final Outcome: The Apple phone is still there, and the rules of the circle are still in place, but no one dares to bet all their wealth on it. Once, having a cryptocurrency wallet was a symbol of status; now, it’s more like a high-risk gamble. You can still use it, but you must realize that there’s no “absolute security” – only varying probabilities of risk.

---

Lessons for Ordinary People (From the Journalist)

1. No Absolutely Secure Cryptocurrencies: Don’t believe any claims of “100% security.” Exchanges, hardware wallets, and sidechains can all be hacked.

2. People Are the Biggest Weakness: No matter how advanced the technology, as long as it involves human interaction (entering passwords, clicking links, answering calls), there’s a risk of being scammed. Stay vigilant, don’t trust “customer service” representatives, and don’t reveal your recovery phrases.

3. Diversify Your Risks: Don’t put all your eggs in one basket. Don’t store all your assets in one exchange, one hardware wallet, or one wallet address.

4. Protect Your Privacy: Share less about your wealth and your activities on social media. Blockchain data is public, so you need to protect your privacy yourself.

5. **Rationally View “Trustlessness”: The crypto world hasn’t eliminated trust; it’s just shifted the objects of trust. You now have to trust code, hardware manufacturers, and human behavior, all of which are more vulnerable than banks.

In One Sentence:

The crypto world still holds opportunities, but it’s no longer the utopia where “knowing the technology means easy success.” It’s become a complex ecosystem with high risks, high volatility, and many human-induced pitfalls. The Apple phone you use to store your assets represents not only your wealth but also your understanding of this fragile world.