Finst

Liquid Hack of $320 Million Puts Identity in the Spotlight

The Liquid Network hack and recent leaks at Trezor and other companies show that KYC data is often harder to recover than stolen bitcoin.

Liquid Hack of $320 Million Puts Identity in the Spotlight

Key Takeaways

  • The Liquid Network lost about $320 million in one exploit on September 7.
  • Evin McMullen says stolen bitcoin can sometimes still be tracked, but leaked identity data is almost impossible to repair.
  • He warns that crypto companies store too much personal data, while AI agents increase the risk of new data leaks.

The roughly $320 million (€277 million) hack on the Liquid Network puts not just crypto security at the center of the conversation, according to Evin McMullen, but especially the difference between reversible onchain theft and lasting identity damage. The CEO and co-founder of Billions says stolen bitcoin can sometimes still be tracked or returned, while leaked names, addresses, and ID numbers are much harder to recover.

Liquid Hack and Data Leaks

On September 7, a blockchain that moves bitcoin between exchanges lost about $320 million in one exploit. Based on the context around the incident, this was the Liquid Network, a Bitcoin sidechain from Blockstream. The attackers reportedly posed as so-called white-hat hackers and even left a message in a Bitcoin transaction telling Liquid to address a specific vulnerability.

At the same time, Trezor said another 67,000 customers were hit by a leak of names, phone numbers, and home addresses through a shipping partner. In a separate incident, about 200,000 records were exposed, including government ID numbers alongside verified wallet addresses. McMullen also points out that address data stolen in 2020 from a hardware wallet maker is still being abused years later in bitcoin scam letters sent by mail. A larger data leak at a broker also shows how quickly identity data and wallet addresses can combine into a long-term risk.

Why Identity Matters More

The core of his argument is that crypto companies often collect more identity data than they need. Crypto exchanges, hardware wallet makers, and on-ramps ask for documents, addresses, and other sensitive details, making them an attractive target for attackers. According to McMullen, that is a structural problem, because a verified trait of a customer can also be confirmed without storing a full identity file.

He contrasts that with a model where only proof is needed that someone is, for example, a real, sanctioned customer, without a passport sitting on a server. He says that matters more now that more software is starting to act on people’s behalf.

AI Agents Increase the Risk

McMullen warns that the rise of AI agents could put even more pressure on this model. If those agents start making payments for people and keep dragging their owner’s full identity along every time, he says the result could be not just a few new honeypots, but billions of them. For European crypto readers, this ties into a broader debate about privacy, KYC, and the way exchanges and wallets store data.

His bottom line is blunt: the $320 million (€277 million) in stolen bitcoin may still come back, but addresses, IDs, and faces will not. That shifts the debate from wallet security alone to how much personal data crypto infrastructure should actually keep.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.