Ledger CTO Challenges ‘Whitehat’ Claim After Liquid’s 4,000 BTC Peg-Out

Coinmama
Coinmama


TLDR:

  • Ledger CTO challenges the whitehat claim after Liquid’s 3,996 BTC peg-out was valued at $318.4 million.
  • Liquid says the peg-out used SideSwap’s PAK, while the key itself and other authorization keys stayed secure.
  • The 3,996 BTC transfer represented roughly 95% of Liquid’s Bitcoin reserves, intensifying control scrutiny.
  • Liquid paused bridge activity as most withdrawn BTC remained concentrated and LBTC backing stayed matched.

Liquid Network is investigating an unusual peg-out involving roughly 4,000 BTC after actors behind the withdrawal described themselves as “whitehats.” Ledger CTO Charles Guillemet has challenged that description, arguing that legitimate researchers usually disclose vulnerabilities before moving substantial collateral.

The September 6 transaction moved about 3,996 BTC from federation-controlled reserves while Bitcoin traded near $79,675. The transfer was worth approximately $318.4 million. A later transaction carried an OP_RETURN message stating, “we are whitehats. contact us on chain.”

Ledger CTO Challenges Whitehat Claim After Liquid’s $318M Peg-Out

Guillemet argued that withdrawing hundreds of millions of dollars before opening communication differs sharply from conventional vulnerability disclosure practices. His comments shifted attention from the transfer itself toward the conduct of the actors controlling the funds.

The Ledger CTO compared the situation with major bridge and protocol exploits where attackers later communicated with affected projects. He cited the 2022 Ronin bridge attack and the 2023 Euler Finance exploit.

Binance

Ronin lost more than $600 million after stolen validator keys allowed unauthorized withdrawals. Euler Finance later recovered assets following negotiations after an exploit initially drained about $197 million.

However, those historical comparisons do not establish malicious intent in the Liquid Network incident. The roughly 4,000 BTC has not been reported as rapidly dispersed or laundered. Instead, most of the funds remained concentrated following the peg-out.

The actors also explicitly requested contact through the Bitcoin blockchain. Blockstream later responded using an on-chain message and asked the party controlling the funds to contact its security team.

However, no confirmed agreement or asset return has been reported. The central issue therefore remains whether the actors’ whitehat description matches their actions. That claim has not been independently verified.

Liquid Probes How 3,996 BTC Cleared Its Peg-Out Security Controls

The Liquid Network later confirmed a security incident and said the withdrawal passed through SideSwap’s Peg-out Authorization Key, known as PAK. Nevertheless, the network said SideSwap’s key itself was not compromised.

Other authorization keys were also reported as uncompromised. That finding has intensified scrutiny over how the transaction satisfied Liquid’s normal withdrawal requirements. Liquid uses a federated security model.

Fifteen functionaries operate the network, while an 11-of-15 quorum controls the Bitcoin peg. Normally, LBTC must be destroyed before matching BTC can leave federation-controlled reserves. PAK restrictions provide another layer by limiting peg-outs to authorized Bitcoin addresses.

On-chain analysis indicated that corresponding LBTC was burned during the withdrawal. That meant the remaining LBTC supply continued to retain matching Bitcoin backing. The distinction reduced immediate concerns about uncovered LBTC liabilities. However, the transaction still represented roughly 95% of Liquid’s Bitcoin reserves.

Liquid responded by notifying exchanges, which paused or prepared to pause LBTC deposits and withdrawals. Bridge nodes were also temporarily disabled while federation members continued investigating. Assets including USDT, DePix, and tokenized real-world assets were not affected, according to the network.

The incident now centers on two verified questions. Investigators must establish how the authorization process permitted the peg-out and whether the withdrawn BTC will be returned.

The post Ledger CTO Challenges ‘Whitehat’ Claim After Liquid’s 4,000 BTC Peg-Out appeared first on Blockonomi.

Source: https://blockonomi.com/ledger-cto-challenges-whitehat-claim-after-liquids-4000-btc-peg-out/





Source link

Bybit

Be the first to comment

Leave a Reply

Your email address will not be published.


*