Loading prices…
🩸BEARISH

Liquid Bridge Loses 4,000 BTC as CTO Rejects Whitehat Claim

Ledger's CTO publicly disputes the framing, comparing the drain to the Ronin hack while exchanges freeze LBTC. Blockstream says the SideSwap key was used, not compromised.

Ledger CTO Charles Guillemet said about 4,000 BTC were pegged out of the Liquid bridge, with an OP_RETURN message reading "we are whitehats. contact us on chain." He publicly disputed the framing, arguing that legitimate white hats do not drain a bridge and then solicit contact on-chain after the fact. He compared the event to the Ronin hack, in which attackers compromised validator keys to steal roughly $625 million, and noted the "let's talk" approach echoed the Euler exploiter's post-attack negotiation.

Why it matters

The Liquid Network is one of the longest-running Bitcoin sidechains, used by major venues for faster BTC settlement. A drain of this magnitude on a federated bridge pulls the same structural risk that has hit every major cross-chain bridge in the past three years, including Wormhole, Ronin, Harmony, and Nomad, into the Bitcoin sidechain ecosystem. Blockstream confirmed the incident on-chain and asked the party to contact its security team.

Market impact

The funds were withdrawn via SideSwap's Peg-out Authorization Key (PAK), though Blockstream says the key itself was not compromised. Exchanges handling LBTC have been notified and have paused or are pausing deposits and withdrawals. Other Liquid-issued assets, including USDT, DePix, and RWAs, are reported unaffected. Liquid has temporarily disabled bridge nodes, effectively pausing the sidechain while federation members work to restore activity. The next catalyst is whether any of the 4,000 BTC returns to a Blockstream-controlled address, and how SideSwap explains use of its PAK without a reported key compromise.

Related tokens
$BTC $LBTC

Frequently asked questions

  1. How much BTC was drained from the Liquid bridge?

    About 4,000 BTC were pegged out of the Liquid Network bridge, according to Ledger CTO Charles Guillemet, who flagged an on-chain OP_RETURN message claiming 'we are whitehats.'

  2. How did the attacker withdraw the funds?

    Blockstream confirmed the funds were withdrawn using SideSwap's Peg-out Authorization Key (PAK). Blockstream says the key itself was not compromised.

  3. Are other Liquid assets affected by the incident?

    No. Liquid confirmed that other assets on the sidechain, including USDT, DePix, and RWAs, are unaffected by the incident.

  4. What is the Liquid Network doing in response to the drain?

    Liquid temporarily disabled bridge nodes, effectively pausing the sidechain while federation members work to restore activity. Exchanges handling LBTC have paused or are pausing deposits and withdrawals.

  5. Why is Ledger's CTO skeptical of the 'whitehat' claim?

    Charles Guillemet argued that legitimate white hats do not drain a bridge and then solicit contact on-chain after the fact, comparing the situation to the Ronin hack and the Euler attacker's post-exploit negotiation.

Source attribution
Aggregated from WuBlockchain · Verified · Last refreshed 50m ago
Open original →