风险雷达

/ high

Liquid 事件后出现 Phishing Campaign:Blockstream 警告 Fake Recovery / Re-Peg / Security Update

Blockstream 警告 impersonator 正利用 Liquid incident 发送 fake security update、reimbursement portal、re-peg instruction 和软件安装链接。用户不应输入 recovery phrase、PIN 或按 unsolicited message 转移资金。

2026年9月12日最后更新 10:30 UTC约 1 分钟

Liquid Network incident 之后,出现了一个独立的新风险:

攻击者冒充 Liquid、Blockstream 和 Support Staff 进行 phishing。

这和原始 bridge exploit 不是同一个事件。

Fake Message 会说什么?

Blockstream 公布的常见 lure 包括:

  • Mandatory security update;
  • Portfolio update;
  • Reimbursement check;
  • Re-peg instruction;
  • Installer download;
  • Recovery phrase / PIN request;
  • Urgent transfer instruction。

这些内容都在利用用户对 Liquid incident 的焦虑。

用户实际上不需要做什么?

Blockstream 明确表示,因为这次 incident,用户不需要:

  • 主动移动资金;
  • 输入 recovery phrase;
  • 输入 PIN;
  • 安装 email/DM 发来的软件;
  • 进入 unsolicited reimbursement portal;
  • 点击所谓 re-peg link。

为什么这是独立风险?

原始 Liquid incident 是 infrastructure / bridge security。

Phishing 是:

Social Engineering / Credential Theft

即使 protocol bug 已修复,用户仍可能因为泄露 seed phrase 而损失资产。

典型攻击路径

  1. Attacker 找到 Liquid / Blockstream 用户;
  2. 发送 urgent support message;
  3. Fake site 模仿官方品牌;
  4. 用户输入 recovery phrase/PIN 或安装 malware;
  5. Self-custody asset 被直接 drain。

Evidence Status

Confirmed / Official

Blockstream 已正式警告 active impersonation,并明确说不会要求 recovery phrase 或 PIN。

Developing

Targeted user count、successful drains、fake domains、malware infrastructure、takedown。

Risk Assessment

High user-security risk。

What to Watch Next

Fake domains、wallet drains、malicious installer、support impersonation、registrar takedown。

FAQ

有官方 reimbursement portal 要登录吗?

不要相信 unsolicited reimbursement link。

需要重新输入 seed phrase 吗?

不需要。

Blockstream 会问 PIN 吗?

官方说不会。

这和 Liquid exploit 是同一个事件吗?

不是。

Self-custody 用户还会有风险吗?

会,如果泄露 recovery credential。

最安全做法是什么?

只用官方渠道,不响应 unsolicited recovery message。