White-hat whale moves 4,000 BTC; spot ETFs top 2026 inflows

BTCC
Changelly


A reported “white hat” actor has taken nearly 4,000 Bitcoin worth about $319 million from the Liquid Network, according to an incident update posted by the Blockstream-run sidechain community. Liquid subsequently paused bridge operations and asked exchanges to stop both LBTC deposits and withdrawals while it investigates what went wrong.

Liquid Network says the withdrawal was executed via SideSwap using a Peg-out Authorization Key, while insisting that the key used was not compromised. Still, the federation wallet balance shown in Liquid’s explorer dropped sharply—from roughly 4,200 BTC to about 207.275 BTC—prompting renewed scrutiny of how Liquid’s peg security functions when something unusual bypasses expected controls.

Key takeaways

  • Liquid says bridge nodes were disabled temporarily, effectively pausing the Liquid sidechain until the issue is resolved.
  • The incident involved an LBTC peg-out executed through SideSwap, with Liquid stating the Peg-out Authorization Key was not compromised.
  • Liquid told exchanges to pause LBTC deposits and withdrawals while the team attempts to contact the actor and assess security gaps.
  • An OP_RETURN message claimed the funds were extracted by “whitehats,” but neither the claim nor the technical details are fully verified publicly.

Liquid freezes bridge activity after a major LBTC outflow

According to the initial reporting in Liquid Network’s incident communications, a “shade under 4000 Bitcoin” worth approximately $319 million was withdrawn from Liquid. Liquid Network also referenced an unverified on-chain message—via OP_RETURN—asserting responsibility and asking to be contacted “on chain.”

In response, Liquid disabled bridge nodes, stating this stops any new transactions from being submitted to the network. The operational consequence is straightforward: without bridge nodes, the sidechain’s peg mechanics can’t continue normally, which is exactly what traders and exchanges need when a suspected peg-out route may be functioning unexpectedly.

Binance

“Bridge nodes have been temporarily disabled, so no new transactions can be submitted to the network. Effectively, the Liquid sidechain is paused until this issue is resolved.”

How Liquid’s peg-out is supposed to work—and what the incident challenges

Under standard Liquid mechanics, LBTC is burned on the sidechain before Bitcoin is released on the main chain. The withdrawal flow depends on authorization rules that require a multisignature setup (Liquid describes this as 11-of-15 multisig functionaries) and a whitelist for approvals.

That structure is meant to prevent exactly the kind of unauthorized peg-out that would drain funds from the federation wallet. The incident therefore raises questions that go beyond the size of the withdrawal: it challenges whether the controls around approvals and whitelisting performed as intended, or whether there is an unexpected pathway in the way approvals are generated and executed.

Crypto analyst DBCrypto argued that the behavior appears more consistent with an extraction that leaves funds “sitting on Bitcoin” rather than being rapidly mixed, describing it as potentially closer to “whitehat extraction than theft.” At the same time, DBCrypto said the broader security implications remain serious: either the required signatures and authorization logic were effectively satisfied, or the whitelist/control mechanisms designed to block such events did not hold.

SideSwap role and Liquid’s assertion about key security

Liquid said the withdrawn funds were sent via Sideswap, specifically through the SideSwap PAK (Peg-out Authorization Key). In Liquid’s statement, the PAK used in the transaction was not compromised, and it claimed that no other related keys were compromised either.

Liquid also reported that it had already established how the LBTC involved in the order was created—through a bug in Elements software. While the incident details in the public account focus on the peg-out authorization process and the status of the key, the Elements reference matters because it suggests the failure may have started earlier than the final Bitcoin withdrawal itself.

For market participants, the key implication is practical: if an Elements-level bug can affect how LBTC is created or approved for peg-out, then the operational risk isn’t confined to a single malicious transaction. Instead, it may require a broader review of how sidechain issuance and peg-out eligibility interact, and how those conditions are validated before bridge processing is allowed to resume.

What to watch as Liquid and related operators investigate

Liquid and its ecosystem appear to be working through a familiar incident sequence: identify which steps deviated from expected behavior, confirm whether any authorization keys were actually compromised, and determine what fixes or compensating controls are necessary before restarting bridge functions.

At the time of the provided coverage, Blockstream and Adam Back had not posted public updates on the incident timeline, but Samson Mow (Jan3 CEO) said “everyone is actively working to resolve this.” The immediate items for users and exchanges are likely straightforward—follow Liquid’s instructions to pause LBTC deposits and withdrawals until the bridge is re-enabled and the underlying security question is addressed.

Until Liquid publishes more technical detail on the peg-out authorization flow, the nature of the Elements bug, and why the multisig/whitelist protections were insufficient (or circumvented), the central uncertainty will remain the same: whether this was a one-off exploitation path or a systemic weakness that could reappear in other peg operations. Readers should watch for the moment bridge nodes return and for any concrete post-mortem describing exactly which authorization or validation step failed.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure



Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*