Worked example · 2021-08
Liquid Global warm-wallet compromise — multi-chain — 2021-08-19
Summary
Liquid Global was a Japan-based / Singapore-incorporated cryptocurrency exchange operated by QUOINE PTE, ranked among the top 20 global exchanges by volume in 2021. On 2021-08-19 the exchange disclosed unauthorised access to its warm wallet infrastructure, with the on-chain manifestation a sweep of approximately $91M across BTC, ETH, ERC-20s, TRON, and XRP [liquidpostmortem2021] [merklesciliquid2021]. Per Liquid's own communication, the affected infrastructure used multi-party computation (MPC) for warm-wallet key management; the precise MPC-implementation-side failure mode was not fully publicly disclosed, and Liquid characterised the breach as warm-wallet compromise rather than MPC-protocol-cryptographic break [liquidpostmortem2021].
The on-chain laundering chain executed in characteristic Lazarus / DPRK shape. Elliptic's contemporaneous forensic reconstruction documents the ERC-20 → ETH conversion path through Uniswap and SushiSwap (~$45M of the ERC-20 portion), Tornado Cash mixing of the resulting ETH, and parallel laundering of the BTC and other-chain proceeds through their respective ecosystems [ellipticliquid2021]. The TRM Labs follow-up analysis traces the cross-chain laundering sequence — ERC-20 → ETH (mixed) → BTC (mixed) → consolidated wallets → crypto-to-fiat exchanges based in Asia — as a textbook Lazarus / TraderTraitor laundering chain [trmliquidsecond2021].
The off-chain entry vector is the structurally important but underspecified element of the case. Liquid did not publish a fully detailed technical post-mortem identifying the exact phishing / endpoint-compromise / vendor-supply-chain vector that admitted the attacker into the warm-wallet operational environment. The public forensic record at v0.1 places the case inside the broader DPRK / TraderTraitor 2021 cohort — the same cohort that produced the LinkedIn fake-job-offer / fake-recruiter pretext + endpoint-compromise pattern documented at canonical-anchor level by the Ronin (T15.001) and DragonEx (T15.001) cases — but does not pin Liquid's specific entry vector to a single sub-Technique. OAK's classification convention is to map the entry-vector class (T15.001 / T15.003) at the cohort-cluster level while noting that the precise sub-Technique is not publicly individuated.
For OAK's purposes Liquid 2021-08 is the canonical T15 2021 anchor for the exchange-side warm-wallet compromise via DPRK off-chain entry vector class. The case sits structurally between KuCoin 2020 (operator-internal hot-wallet key compromise, T15-class entry vector documented in worked-example layer ahead of T15 taxonomy) and DMM Bitcoin 2024 (vendor-supply-chain compromise via Ginco LinkedIn fake-coding-test, T11.001 + T15.001/T15.003 + T15.002 chain) — the same DPRK-cluster operational continuity, the same on-chain laundering shape, the same realised-loss-vs-attribution-vs-recovery posture, but with the precise off-chain sub-Technique under-specified relative to the 2024 cohort's level of public disclosure.
Timeline (UTC unless noted)
| When | Event | OAK ref |
|---|---|---|
| Pre-event (likely Q1–Q2 2021 per cohort patterning) | Off-chain entry vector compromises Liquid / QUOINE operator-side environment; precise sub-Technique (LinkedIn fake-recruiter, malicious-coding-test, fake-investor pretext, supply-chain compromise of a wallet-software vendor) not publicly individuated at v0.1 | T15.001 and/or T15.003 (cohort-class mapping) |
| Pre-event | Attacker establishes implant / MITM layer / signing-host position sufficient to enable the warm-wallet sweep at the on-chain layer | (T15.003 endpoint state — cohort-class) |
| 2021-08-19 (early UTC) | Attacker initiates concentrated outflow from Liquid warm wallets; sweeps 107 BTC, ~9M TRON, ~11M XRP, and ~$60M in 67 ERC-20 tokens to four attacker-controlled addresses | T11.001 broadly construed — extraction at the warm-wallet signing surface |
| 2021-08-19 | Liquid Global publicly discloses the breach; halts deposits and withdrawals; blacklists four attacker addresses; migrates remaining wallet balances to cold storage | (operator response) |
| 2021-08-19 onward | Attacker begins ERC-20 → ETH conversion through Uniswap and SushiSwap | (downstream chain — DEX laundering precursor pattern, same shape as KuCoin 2020) |
| 2021-08-19 onward | Attacker deposits converted ETH into Tornado Cash mixer; parallel BTC laundering through CoinJoin-class infrastructure | T7.001 mixer-routed hop |
| 2021-08-19 onward | Cross-chain laundering chain (ERC-20 → ETH mixed → BTC mixed → consolidated wallets → Asia-region crypto-to-fiat off-ramps) executed across following days/weeks | T7.003 cross-chain laundering |
| 2021-08-25 | Liquid Global discloses $120M loan from FTX (Sam Bankman-Fried) to backfill the operational shortfall and resume customer withdrawals | (operator response — third-party recapitalisation) |
| 2021–2022 | Chainalysis and Elliptic publish wallet-cluster attribution to DPRK-aligned operators; case included in 2021 cumulative DPRK-stolen-funds aggregate | G01 attribution (inferred-strong) |
| 2022-04 | FBI / CISA / Treasury joint advisory on TraderTraitor (Lazarus / APT38 / BlueNoroff / Stardust Chollima) consolidates DPRK-cluster attribution at the cohort level; does not name Liquid specifically | (cohort attribution surface) |
| 2022-02 | Liquid Global acquired by FTX following the prior loan; subsequently subsumed into FTX's 2022-11 collapse | (operator dissolution — outside OAK on-chain Tactic scope) |
What defenders observed
- Warm-wallet MPC infrastructure is not by itself a sufficient defence against off-chain operator-side compromise. Liquid's warm-wallet key management used MPC, which protects against direct key-material theft but does not protect against an attacker who has compromised the operator-side environment that initiates and authorises wallet operations. The relevant threat model is the operator-side authorisation surface (signing-host compromise, MITM layer, transaction-request manipulation) rather than the cryptographic-protocol surface. Fireblocks's post-event commentary makes the same point at the lessons-learned level for organisations evaluating MPC custody
[fireblockslessons2021]. Defenders evaluating MPC-based custody should ask "what is the authorisation flow that gates a sign request, and what compromises that flow?" rather than "is the MPC implementation cryptographically sound?". - The on-chain laundering chain is textbook Lazarus / TraderTraitor and the recovery posture follows from it. ERC-20 → ETH via DEX → Tornado Cash for the EVM proceeds; parallel BTC mixing for the Bitcoin proceeds; cross-chain consolidation into Asia-region off-ramps. The same chain shape appears in KuCoin 2020 (with DEX laundering as an emerging pattern at that time), in Ronin 2022, in WazirX 2024, and at the largest scale in Bybit 2025. The recovery posture is correspondingly bounded: where the laundering rail closes through mixer infrastructure inside the operational window, on-chain recovery is structurally foreclosed. Liquid's $91M loss was absorbed by operator-side recapitalisation (the FTX loan) rather than recovered through tracing.
- The attribution surface is cohort-level, not per-incident, at v0.1. Chainalysis and Elliptic published the wallet-cluster attribution in the months following the breach; the April 2022 FBI / CISA / Treasury joint advisory consolidated the cluster-level attribution but did not name Liquid specifically. By OAK convention the case is
inferred-strong, notconfirmed. Contributors writing other 2020–2022 OAK-G01 cases should expect this — the per-incident named-target attribution surface for crypto-specific events accelerated post-2022 (Ronin 2022, DMM Bitcoin 2024, WazirX 2024 are the canonical post-2022 confirmed-attribution anchors), and many earlier incidents remain industry-forensic-attributed only. - Token-issuer freezes did not feature as a recovery surface in this case the way they did at KuCoin. Liquid's affected asset mix included 67 distinct ERC-20s, but the public forensic record does not document a coordinated industry-response freeze comparable to KuCoin 2020. Several plausible explanations: the attacker's post-extraction conversion to ETH through Uniswap / SushiSwap was sufficiently fast that issuer-side freezes would not have caught the funds in their original asset class; the asset mix was less concentrated in freeze-capable issuers than KuCoin's; the post-KuCoin operational playbook had not yet stabilised at the per-issuer level by August 2021. Defender ecosystem-level monitoring should treat the KuCoin recovery rate (~84%) as the upper-bound case for asset-mixed exchange compromises, with Liquid as a closer-to-base-rate datapoint where the laundering-rail timing closed before the response chain could engage.
- Operator-side recapitalisation via third-party loan is a distinct recovery mechanism with its own preconditions. Liquid's $120M FTX loan is not a recovery in the on-chain forensic sense — the stolen funds were not returned — but it is a recovery in the operational sense — customer withdrawals resumed and the operational solvency hole was filled. The mechanism preconditions are (a) discoverable operator identity with a creditworthy counterparty, (b) regulatory-relationship continuity that admits the loan instrument, (c) a counterparty with strategic interest in the affected exchange. The mechanism is not generalisable — the FTX 2022-11 collapse subsequently took Liquid down with it as a consequence of the acquisition that followed the loan.
What this example tells contributors writing future Technique pages
- T15 / T15.001 / T15.003 mapping at the cohort-cluster level is the right OAK convention when the precise sub-Technique is not publicly individuated. The Liquid case sits inside the broader DPRK / TraderTraitor 2021 cohort whose pretext-and-payload pattern is well-documented at the cohort level (the LinkedIn fake-job-offer / fake-recruiter family) but is not individuated for Liquid specifically in the public forensic record. Contributors classifying similar cases (where the operator-cluster attribution is strong but the per-incident sub-Technique is not pinned) should follow the convention used here: map T15.001 and/or T15.003 at the cohort level with explicit acknowledgement of the under-specification, rather than inventing a precise sub-Technique that is not in the public record.
- The T15-to-T11.001 chain has been operationally stable across 2020–2025 for the OAK-G01 exchange-compromise class. Liquid 2021 fits the pattern that KuCoin 2020 anchored at the worked-example layer ahead of the T15 taxonomy (operator-internal hot-wallet key compromise via off-chain entry vector → on-chain extraction at the wallet-signing surface) and that DMM Bitcoin 2024 anchored at the canonical T11.001 + T15.001/T15.003/T15.002 cohort-defining level. Worked examples for future OAK-G01 exchange compromises should preserve the chain framing (T15-class entry vector → T11-class on-chain extraction → T7-class laundering → OAK-G01 cluster-graph attribution) even when the per-incident sub-Technique is under-specified.
- The MPC custody narrative deserves explicit treatment in T11 / T15 worked examples to avoid defender mis-framing. Liquid's compromise is sometimes summarised in popular reporting as "MPC was hacked" — a framing that is technically wrong (the MPC protocol's cryptographic guarantees were not broken) and operationally misleading (MPC as a primitive is not a sufficient control against operator-side authorisation-flow compromise). The Bybit 2025 / Safe{Wallet} case repeats the same defender-mis-framing risk on a much larger scale. Contributors writing T11 / T15 worked examples for MPC-based custody compromises should be explicit about which surface failed (operator-side authorisation flow) versus which surface held (MPC cryptographic protocol), to avoid over-generalising "MPC failure" lessons that don't reflect the actual threat model.
- The 2020–2021 DPRK exchange-compromise cohort is structurally complete: KuCoin / Liquid / Bithumb-class events plus emerging DEX-routing laundering. OAK's worked-example anchors at v0.1 are KuCoin 2020 (T15 2020 anchor, taxonomy-pre-dated), Liquid 2021 (T15 2021 anchor, this case), Bithumb 2017 (pre-OAK-active-year). DragonEx 2019 and Coincheck 2018 are the broader cohort companions. Contributors should treat this set as the operational T15 / T11 evidence base for the OAK-G01 exchange-compromise class through the post-2022 indictment-class disclosure shift (Ronin 2022, DMM 2024, Bybit 2025).
Public references
[ellipticliquid2021]— Elliptic forensic write-up of the Liquid Exchange hack including the asset-breakdown (107 BTC / 9M TRON / 11M XRP / ~$60M in 67 ERC-20s) and the on-chain ERC-20 → ETH → Tornado Cash → BTC laundering reconstruction.[merklesciliquid2021]— Merkle Science Hack Track analysis: contemporaneous on-chain reconstruction with the four blacklisted attacker addresses and the warm-wallet compromise framing.[liquidpostmortem2021]— Liquid Global's own public statement (translated Japanese blog post) characterising the breach as warm-wallet compromise; identifies the MPC custody architecture without disclosing the precise failure-mode internals.[coindeskliquid2021]— CoinDesk reporting on the $90M+ loss and the MPC warm-wallet target.[coindeskftxloan2021]— CoinDesk coverage of the 2021-08-25 $120M loan from FTX to Liquid Global.[trmliquidsecond2021]— TRM Labs follow-up analysis tracing the cross-chain laundering sequence (ERC-20 → ETH mixed → BTC mixed → consolidated wallets → Asia-region crypto-to-fiat off-ramps) as a textbook Lazarus / TraderTraitor chain.[chainalysisdprk2022]— Chainalysis 2022 publication including Liquid in the 2021 DPRK-stolen-funds aggregate (~$400M across 7+ events that year); cluster-level attribution.[fbicisatreasurytrader2022]— FBI / CISA / Treasury April 2022 joint advisory on TraderTraitor; consolidates DPRK-cluster attribution at the cohort level (Lazarus / APT38 / BlueNoroff / Stardust Chollima).[fireblockslessons2021]— Fireblocks post-event commentary on lessons for organisations evaluating MPC-based custody following the Liquid case.
Discussion
Liquid Global 2021-08 is OAK's canonical T15 2021 worked example for the exchange-side warm-wallet compromise via DPRK off-chain entry vector class, anchoring the T15 Tactic for an active year that previously had no per-incident anchor in the corpus. The case sits structurally between KuCoin 2020 (T15-class entry vector documented in worked-example layer ahead of the T15 taxonomy) and DMM Bitcoin 2024 / Bybit 2025 (T11.001 + T15.001/T15.003/T15.002 chain at canonical-anchor level) — the same DPRK-cluster operational continuity, the same on-chain laundering shape, the same realised-loss-vs-attribution-vs-recovery posture, but with the precise off-chain sub-Technique under-specified relative to the 2024+ cohort's level of public disclosure.
The defender lesson is that the OAK-G01 exchange-compromise class has been operationally stable for the entire 2020–2025 active period, with the structural failure point consistently at the operator-side authorisation flow rather than at the cryptographic-custody-primitive layer. Contributors writing future OAK-G01 worked examples should preserve this framing: the class is not "exchange custody got hacked" but "operator-side authorisation flow got compromised, then the on-chain extraction surface was the warm-wallet / hot-wallet / signing-pipeline that the operator-side flow gates." This framing keeps the threat model honest and points defenders at the right mitigation surface (operator-side authorisation hardening, off-chain destination verification, signing-host MDM / EDR, anti-phishing controls) rather than at the wrong one (cryptographic custody-primitive evaluation).
The recovery profile is the second teaching point. Liquid's $91M loss was absorbed by operator-side recapitalisation (the FTX loan) rather than recovered through on-chain tracing, in contrast to KuCoin 2020 (~84% recovery via coordinated industry response). The variable that drove the difference was the asset-mix-vs-laundering-rail-timing fit: KuCoin's loss was disproportionately in freeze-capable ERC-20 issuers and the laundering rail was delayed by DEX-routing throughput; Liquid's loss converted to ETH through DEXes faster than the issuer-freeze surface could respond. Contributors writing future T15 / T11 worked examples should treat the time-to-mixer-or-DEX metric as a first-class recovery-prediction signal, with the KuCoin / Liquid contrast as the canonical worked datapoint pair.
The attribution status (inferred-strong, OAK-G01 / DPRK at the cluster level, with OAK-G08 BlueNoroff operator-fingerprint overlap) is the realistic ceiling at v0.1 and should remain so absent a future FBI / DOJ / Treasury / NPA per-incident statement comparable to the December 2024 DMM Bitcoin advisory. The 2022-04 TraderTraitor joint advisory consolidates the cluster-level attribution but does not single out Liquid; the FTX 2022-11 collapse subsequently subsumed Liquid as a corporate entity, foreclosing the most likely path to a per-incident enforcement disclosure. Contributors should not over-claim attribution beyond inferred-strong for this case.
Techniques demonstrated (7)
- OAK-T11.001 Third-Party Signing-Vendor UI / Signing-Flow Compromise
- OAK-T15.001 Social Engineering of Operator Personnel
- OAK-T15.003 Operator-Endpoint Compromise (Developer Workstation / Signing Machine)
- OAK-T4.003 Address Poisoning
- OAK-T7.001 Mixer-Routed Hop
- OAK-T7.003 Cross-Chain Bridge Laundering
- OAK-T8.002 Cross-Chain Operator Continuity