Home Blog Page 6

Better’s Bitcoin Mortgage May Give the Lender Years of Control Over Borrowers’ Crypto

TL;DR

  • Better’s Bitcoin-backed mortgage lets home-buyers avoid selling Bitcoin, but pledged collateral may remain locked until the main mortgage is repaid or refinanced.
  • Better may reuse pledged Bitcoin while borrowers continue to carry exposure to its price and to the lender holding their collateral.
  • No margin calls reduce one risk, but borrowers still pledge 250% collateral and may face a sale after 60 days of delinquency.

Better Mortgage is offering home-buyers a way to fund a down payment without selling their Bitcoin. Newly disclosed terms show that borrowers may give up practical control of that crypto. The loss can last for years after the down-payment loan itself ends.

Under Better’s Bitcoin-backed mortgage, the lender may reuse pledged Bitcoin. The pledged Bitcoin can stay tied to the main home loan until the borrower repays or refinances it. That changes the risk calculation. Borrowers keep exposure to Bitcoin’s price, but they may lose access to the asset for years.

Keeping Bitcoin does not mean keeping control

The lender built the product around a simple appeal. A buyer who holds Bitcoin can use it to support a home purchase without first converting the asset into cash.

At closing, the borrower receives two loans. The home secures the first loan, a conventional mortgage. Bitcoin and a second claim on the property secure the other loan, which funds the down payment.

Borrowers must pledge $2.50 in Bitcoin for every $1 borrowed through the down-payment loan. The crypto moves from the borrower’s Coinbase account into Better’s custody account at Coinbase Prime.

The buyer still benefits if Bitcoin rises in value. But the buyer no longer has the same freedom to move, sell or otherwise use the pledged coins.

Better may reuse the pledged Bitcoin

The more unusual term covers what Better can do once it takes custody of the collateral.

Better told CoinDesk that it may rehypothecate the Bitcoin, meaning the lender can use pledged coins in another transaction. It promises to maintain an equivalent amount for eventual repayment, so the borrower depends on Better’s ability to make good. The collateral might not return for years or even decades.

Better said its agreements and custody structure comply with applicable laws, including insolvency rules. The company did not explain, according to CoinDesk, whether individual borrowers’ Bitcoin stays separately identifiable after reuse. It left unanswered what legal claim customers would have if Better or a financing partner failed.

The stakes on those questions grow when the underlying relationship can last 15 or 30 years.

No margin calls only address one type of risk

Bitcoin price declines alone do not trigger margin calls. Borrowers do not have to add collateral when the price falls. A price drop by itself does not cause an automatic sale.

Missed payments work differently. If a borrower becomes delinquent, Better may sell pledged Bitcoin after 60 days, following notice. Better says it would sell only enough to repay the debt and bring the account current.

Price declines are not the only risk borrowers carry. Liquidity risk and exposure to Better as a counterparty remain. Missed payments can still trigger a sale of the collateral.

Paying off the down-payment loan may not unlock the Bitcoin

Borrowers might expect that repaying the crypto-backed portion of the financing would return their Bitcoin. Better’s newer written response indicates otherwise.

The pledged Bitcoin can remain locked until the borrower fully repays or refinances the main mortgage. Paying off the separate down-payment loan early does not change that. A home sale requires the borrower to settle the down-payment loan before Better releases the collateral. For someone with a long-term mortgage, a down-payment tool can turn into a multi-year commitment of crypto assets.

Better hasn’t said what happens to an individual borrower’s Bitcoin if the company or a financing partner runs into trouble. It’s unclear whether that borrower would have a claim on specific coins, or just a claim in line behind everyone else.

Liquid Gets 3,400 Bitcoin Back, but $47 Million Still Remains With Hackers

TL;DR

  • Liquid Network recovered 3,400 BTC, about 85% of the Bitcoin withdrawn during the $320 million incident.
  • Roughly 598.5 BTC worth about $47 million remains with the group that carried out the withdrawal.
  • Liquid remains paused while Blockstream and federation members work through security fixes and prepare for a coordinated restart.

Liquid Network has recovered 3,400 BTC from the group behind the withdrawal that nearly emptied its Bitcoin reserve, bringing back about 85% of the funds taken in the $320 million incident. The return considerably reduces the immediate shortfall backing L-BTC, but roughly 598.5 BTC worth about $47 million remains with the self-described white hats.

The repayment came after Blockstream confirmed to the group, in an on-chain message, that it had patched the affected bridge nodes. Liquid has not returned to normal operations. Samson Mow, a former Blockstream executive who has been documenting the exchange on X, said discussions over the remaining Bitcoin are continuing.

Liquid Recovers Most of the Bitcoin, but Not All

The group had previously told Blockstream, through messages embedded in Bitcoin transactions, that it would return “most” of the funds once Blockstream fixed the software problem and patched the relevant nodes.

On September 7 at 09:19 UTC, Blockstream sent a PGP-signed message saying it had patched its bridge nodes and that it was safe to return the funds. Soon afterward, the group sent 3,400 BTC back to the federation address, in Bitcoin block 965,950.

The transfer restores most of the Bitcoin taken in the withdrawal. Before it, the federation held roughly 4,200 BTC backing L-BTC. The exploit had left only about 197 BTC in the reserve, creating an immediate gap between the amount of L-BTC in circulation and the real Bitcoin backing it.

What happened to the other 598 Bitcoin?

About 598.5 BTC remains at an address associated with the group, worth roughly $47 million at current Bitcoin prices.

What the group intends to do with it remains unclear. The remaining 15% could function as an informal bug bounty or “finder’s fee,” though neither Blockstream nor the Liquid Federation has confirmed any such arrangement.

The group has called itself “white hats.” Security researchers who responsibly disclose a vulnerability typically report it before touching any funds. Then they work with the affected company to fix the bug and agree on a reward, if any. This group withdrew nearly all of Liquid’s reserves first and contacted Blockstream only afterward to negotiate the terms of the return. Blockstream is continuing to communicate with the group over the outstanding funds.

Liquid Network still paused

Real work remains before Liquid resumes normal operations, even with 85% of the Bitcoin back in the federation’s wallet. Blockstream and federation members are working through additional security fixes and a chain split before attempting a coordinated restart. Mow has warned users not to send Bitcoin to Liquid peg-in addresses until the network is officially restored. He also said federation members have already deployed updated software as they prepare.

Why Liquid’s Security Keys Could Not Stop a 4,000 Bitcoin Withdrawal

TL;DR

  • A software bug let roughly 4,000 BTC, worth about $320 million, leave the reserves backing Liquid’s L-BTC token.
  • Nobody stole any federation keys. Every signature on the payout was valid.
  • The withdrawn Bitcoin has not moved, and Liquid Network’s reserve now holds about 197 BTC after the exploit.

Liquid Network disabled the bridge connecting it to Bitcoin after a $320 million exploit pulled roughly 4,000 BTC out of the reserves that back its L-BTC token. That is close to 95% of the 4,200 BTC the network held before the withdrawal. When that much Bitcoin disappears, the first suspect is usually a stolen key. That was not the case here. Bitquery, a blockchain research firm, traced the withdrawal to a software bug that let someone create L-BTC that was never backed by real Bitcoin, then exchange it for real Bitcoin anyway.

What Liquid is, in plain terms

Liquid is a sidechain, a companion network built on top of Bitcoin, developed by the company Blockstream. People send BTC into a shared reserve controlled by a group of institutions called the Liquid Federation, and receive an equal amount of a token called L-BTC in return. Moving funds requires eleven of the federation’s fifteen members to sign off. L-BTC settles faster than regular Bitcoin and can carry other assets, including tokenized dollars. Sending L-BTC back to the federation destroys the token and releases the matching BTC from the reserve. Liquid calls this process a peg-out. The federation is supposed to back every L-BTC in circulation one for one with real Bitcoin sitting in that reserve.

The withdrawal, step by step

SideSwap, a company that runs one of Liquid’s official peg-out desks, said a customer sent it 4,000 L-BTC at 14:05 UTC on September 6. SideSwap processed the order as it always does: it destroyed the L-BTC on Liquid and asked the federation to release the matching Bitcoin, using an authorization key known as a PAK that is unique to each approved desk. Twenty-three minutes later, at 14:28 UTC, the federation paid out roughly 3,996 BTC to the customer’s Bitcoin address.

SideSwap said its own PAK remained secure, and Liquid confirmed that none of its other keys were stolen either. Every signature involved in the payout was genuine. The network treated the 4,000 L-BTC as legitimate and released the Bitcoin that was supposed to back it.

Signs of a rehearsal

Bitquery’s investigation reaches back roughly a day before the exploit that drained Liquid Network’s reserves. The wallet behind it received about 2 BTC on September 4, from a mix of small, aged Bitcoin holdings, and converted it into L-BTC. Over the following day it made 92 test transactions on Liquid, most of them tiny.

Seventy of those transactions shared an unusual trait. Each carried a hidden amount alongside a note, written in plain text. That note identified the asset as L-BTC. Sixty-eight of them shared something more specific. Each carried the identical hidden amount and the identical cryptographic range proof, byte for byte. These proofs spread across Liquid blocks over about 14 hours. A range proof is the piece of math that lets a Liquid node confirm a hidden amount. It confirms the amount is not negative, without revealing the actual number. A negative amount would be a way to create Bitcoin that was never really there. So every node checks a range proof before it accepts a transaction. Nodes save time by remembering proofs they have already checked instead of checking them again.

Bitquery’s read is that repeating one identical proof 68 times looks like an attempt to get that exact proof lodged in the memory of every node on the network. What the wallet did with that positioning is the part the public record does not show directly, though the timing lines up closely with what happened next.

The suspected bug

SideSwap said within hours that the exploit traced back to a bug in Elements, the open-source software that runs Liquid Network. Its own system was not affected. Blockstream has not named the specific flaw.

Bitquery found a fix in the Elements codebase, first committed by a Blockstream engineer on August 3 and formally proposed as a pull request on August 31, that changed what a node’s cache remembers about a range proof it has already checked. Before the fix, the cache recorded only the proof itself. After the fix, it records the proof together with the specific asset and output it was checked against.

The pattern behaves like a guard who recognizes a badge and stops checking it. He never confirms who is wearing it or which door it is being used for. Show him that badge once, and he waves it through anywhere, on anyone. Before the fix, a node that had already verified one range proof would recognize it again. It would skip a real check the second time, even on a different transaction. That second transaction could carry a completely different amount of L-BTC. The 68 identical proofs planted across Liquid over 14 hours would have relied on exactly that gap. They marked one proof as already checked in the memory of nodes across the network. Nodes could then wave it through again once it mattered.

Nobody shipped the Fix

Developers merged the fix into Elements’ main code branch on September 2. They backported it to the older release line the next day. That was four days ahead of the exploit. Merging a fix into the source code is not the same as shipping it. Shipping means getting it to the nodes that run the network.

Software normally moves from a merged commit into a packaged release before node operators install it. That packaging step remained pending on September 6. The most recent released version of Elements dated back to April. It predated the fix by months. The nodes running Liquid that day ran that older, unpatched version. The fix had been sitting in public view on GitHub for weeks already. Anyone reading Elements’ commit history in late August could have seen what the old caching logic allowed. Blockstream folded the fix into an upcoming release candidate on September 6 at 17:21 UTC. That happened after the withdrawal had already taken place.

Blockstream has not confirmed this is the exact vulnerability the attacker exploited. The case for a connection is built on timing: the fix, the mint, and the release candidate all landed within days of each other, and no alternative explanation has surfaced.

A negotiation carried out in public

After the payout, the attackers moved the Bitcoin to a single address and wrote a short note directly into the blockchain, using a feature called OP_RETURN that lets anyone attach a small message to a transaction: “we are whitehats. contact us on chain.” Blockstream answered the same way roughly an hour later. It sent a small transaction of its own with a note asking the holder to email its security team.

Over the following hours the two sides traded seven messages this way. Galaxy Digital’s research head Alex Thorn reconstructed and published the sequence from the raw on-chain transactions. The exchange included an encrypted, signed note from Blockstream and a reply from the holder promising to return “most” of the funds once Blockstream fixed the bug and every node had the patch. Blockstream replied on September 7 that its bridge nodes were now patched and it was safe to send the funds back.

https://twitter.com/intangiblecoins/status/2096808321332158474

Not everyone accepts the “white hat” framing. Ledger’s chief technology officer, Charles Guillemet, wrote that draining a bridge before making any contact was not how security researchers usually behave. He raised the possibility that the actors found the bug with help from AI tools and were unfamiliar with standard disclosure practices. He offered the idea as speculation, not a confirmed explanation.

A separate party tried to take advantage of the standoff. On September 7, someone sent the holder a message impersonating Blockstream and asking for 3,900 BTC to be sent to a different address. Bitquery flagged the attempt as a likely scam, since the message carried no valid signature from Blockstream’s security key.

Where things stand

Liquid disabled its bridge nodes within hours of the incident, stopping Bitcoin and other assets from moving between the main Bitcoin chain and Liquid. It also asked exchanges to pause L-BTC deposits and withdrawals. The other assets Liquid carries, including tokenized dollars, are not backed by the Bitcoin reserve, so the shortfall does not affect their backing.

The withdrawn Bitcoin sits untouched at the address it landed in. The federation’s reserve backing Liquid Network now holds roughly 197 BTC, about 4.7% of what it held before the exploit. The exploit destroyed the fraudulent L-BTC the moment SideSwap cashed it out, without touching the honest L-BTC already in circulation, so the total supply of L-BTC did not shrink to match the reserve. Real Bitcoin now backs only about five cents of every dollar of L-BTC outstanding.

The holder has not put a number on how much “most” means in Bitcoin. Whether Liquid absorbs the remainder as a loss or treats it as the cost of finding the bug is a decision nobody has announced.

Hargreaves Lansdown Opens Bitcoin and Ether ETNs to UK Investors

Hargreaves Lansdown, the UK’s largest retail investment platform, began offering Bitcoin and Ether exchange-traded notes to eligible UK retail investors on September 3. The launch gives clients a new way to follow crypto prices without managing a wallet or private keys.

What Hargreaves Lansdown added

Hargreaves Lansdown listed nine bitcoin and ether notes, becoming the last major UK retail investment platform to introduce the products. Other providers had already acted after regulators reopened the market. Issuers include BlackRock’s iShares, WisdomTree, 21Shares, Invesco, CoinShares and Bitwise.

Hargreaves Lansdown crypto ETNs are available through its Fund and Share Account and Self-Invested Personal Pension, known as a SIPP. Clients cannot hold them in a Stocks and Shares ISA.

The platform serves about 2 million clients. Eligibility and knowledge checks determine which of them can actually trade the notes.

How a crypto ETN works

An exchange-traded note is a financial instrument issued by a company and listed on a stock exchange. Its price follows a specified asset or index.

For these products, the issuer uses investors’ money to acquire cryptocurrency through a regulated custodian. The note then tracks the market value of that cryptocurrency after fees.

An ETN is a debt obligation of the issuer, not a fund holding the cryptocurrency in trust for investors. If the issuer becomes insolvent, noteholders rank as unsecured creditors, unlike a fund structure such as an ETF, where the underlying assets are typically ring-fenced from the provider’s own finances. Like other ETNs, crypto ETNs are not deposits, and the Financial Services Compensation Scheme does not protect them. Investors could also lose money simply if cryptocurrency prices fall.

Investors buy and sell the note through their investment account during London Stock Exchange market hours. This makes the product familiar to share investors, but it removes the round-the-clock trading available on crypto markets.

Access comes with several safeguards

The FCA classifies crypto ETNs as Restricted Mass Market Investments, a high-risk category. Hargreaves requires clients to fit an eligible investor category and complete a test covering their knowledge and experience.

Next, a 24-hour cooling-off period applies before a client can view the available notes. The process is designed to limit immediate purchases of a product that can move sharply in value.

Costs extend beyond an issuer’s management fee. Hargreaves charges 0.35% a year for holding the notes, capped at £12.50 per month. Online dealing charges range from £3.95 to £6.95 per trade, depending on activity. The notes themselves carry annual product fees ranging from zero to 0.35% which is due in addition to the platform and dealing costs. 

A mainstream platform falls in line

Hargreaves Lansdown was the last of the UK’s large investment platforms to hold out against crypto ETNs. Its decision to launch means retail access through a familiar, regulated account is now the norm across the country’s major platforms rather than the exception.

UAE Institutions Can Now Trade Bitcoin and Ether Through Standard Chartered

Standard Chartered lets institutional clients in the United Arab Emirates trade Bitcoin and Ether directly through the bank. The service became available starting September 3, 2026. The trades run through the same electronic and foreign-exchange systems those clients already use for currency trading. Accessing crypto no longer means opening an account on a separate exchange.

How the trades work

The service covers deliverable spot trading: clients buy or sell bitcoin or ether at the current market price and receive the actual asset. That distinguishes it from a contract tied to the asset’s future value. Once a trade settles, clients choose where the asset goes. They can use Standard Chartered’s own custody service or route it to another custodian entirely, keeping trading and safekeeping separate if they prefer.

Built on an existing UAE and UK footprint

That structure did not appear from nothing. Standard Chartered has run a digital asset custody business in the UAE since September 2024. This week’s launch effectively wires a trading desk into it. The bank took the same approach in London first: deliverable Bitcoin and Ether spot trading went live for institutional clients through its UK branch in July 2025. Standard Chartered says that made it the first global systemically important bank, or G-SIB, to offer the service anywhere. It now makes the same claim about the UAE market, calling itself the only global bank there currently offering institutional crypto trading.

Institutions only, for now

Retail customers are shut out entirely. This is a service built for banks, asset managers and trading desks that already operate inside regulated financial relationships, not individual investors.

What’s still unclear

Standard Chartered has not named which institutions are using the new desk. What is clear is the pattern: UAE custody in 2024, a UK spot desk in 2025, and now UAE trading layered on top. Each step has moved crypto further into the bank’s existing infrastructure. Crypto has not become a separate business line of its own. Whether other global banks follow the same path is the open question the launch leaves behind.

- Advertisement -

FEATURED