The Liquid Network security incident has generated a second, separate threat: social-engineering attacks against users.
Blockstream has issued an official phishing warning after impersonators began posing as Liquid, Blockstream and support staff.
What the phishing messages claim
Blockstream says common lures include:
- “mandatory security update” notices;
- fake portfolio-update requests;
- fake reimbursement checks;
- instructions to “re-peg” assets;
- installer downloads;
- requests for recovery phrases or PINs;
- urgent fund-transfer instructions.
These messages exploit user uncertainty following the Liquid incident.
What users actually need to do
Blockstream’s official message is unusually clear:
Users do not need to:
- move funds because of the incident;
- enter a recovery phrase;
- enter a PIN;
- install software sent by email or DM;
- use an unsolicited reimbursement portal;
- “re-peg” through a link sent by support.
Why this is a separate risk event
The original Liquid exploit involved infrastructure and bridge security.
The phishing campaign targets users directly through deception.
A user can therefore lose funds even if the underlying Liquid vulnerability has already been patched.
Likely attack path
The typical social-engineering sequence is:
- attacker identifies Liquid/Blockstream users;
- user receives urgent fake support message;
- fake site mimics official branding;
- user enters seed phrase/PIN or installs malicious software;
- attacker drains self-custodied assets.
No protocol exploit is required.
Evidence Status
Confirmed / Official
- Blockstream has warned of active impersonation.
- Attackers are using fake Liquid/Blockstream branding.
- Reimbursement, security-update, re-peg and installer lures are being used.
- Blockstream says it will never ask for recovery phrases or PINs.
Developing
- Number of targeted users.
- Number of successful wallet drains.
- Fake domains and infrastructure.
- Any law-enforcement or registrar takedowns.
Risk Assessment
High user-security risk.
What to Watch Next
Fake domain registrations, wallet-drain reports, malicious installers, phishing emails and support-account impersonation.
FAQ
Is there an official Liquid reimbursement portal users must visit?
Blockstream says users should not act on unsolicited reimbursement or recovery links.
Should users re-enter seed phrases after the Liquid incident?
No.
Will Blockstream ask for a PIN or recovery phrase?
Blockstream says it will not.
Is this the same as the original Liquid exploit?
No. This is a separate social-engineering threat.
Can self-custody users still lose funds?
Yes, if they expose recovery credentials or install malicious software.
What is the safest action?
Use only official channels and ignore unsolicited recovery instructions.