Liquid Hack

REPORTED LOSS $97.0M
High Access Control

What happened

Liquid Global reported an August 2021 security incident in which warm wallets were accessed and digital assets were moved out of exchange custody. Elliptic estimated the stolen assets at more than $97 million at the time of its analysis.

Technical Root Cause

The exact vulnerability and initial-access method were not established in the cited sources. The evidence supports a warm-wallet compromise and subsequent on-chain laundering, without confirming a smart-contract exploit or specific key-theft path.

Case & protocol details

Classification CeFi
Protocol Type Exploit/Access control
Official Website www.liquid.com/
Protocol Twitter/X @Liquid_Global

How it happened

  1. Liquid detected unauthorized access to wallets used for online operations.
  2. The exchange moved remaining assets to cold storage and notified partner exchanges.
  3. Elliptic observed ETH and token swaps through decentralized exchanges, followed by transfers toward Tornado Cash.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.