Liquid Network is reviewing a major incident after about 3,996 BTC, valued at $318.4 million, was withdrawn from its reserves in a single transaction. The actors behind the withdrawal described themselves as “whitehats” in an on-chain message, prompting extensive scrutiny from industry leaders and the wider crypto community.
Ledger CTO questions whitehat status
Ledger Chief Technology Officer Charles Guillemet publicly raised doubts about the legitimacy of the “whitehat” claim. He stated that taking control of such a significant amount of BTC without prior disclosure to network operators does not align with standard security research procedures.
Guillemet compared the event with previous high-profile protocol exploits, referencing the 2022 Ronin bridge attack that resulted in losses exceeding $600 million and the 2023 Euler Finance incident in which assets were ultimately returned after negotiations.
Withdrawing hundreds of millions before communication is completely different from disclosing a vulnerability, and this conduct diverges from established whitehat practices, Guillemet argued. The focus has turned to whether these actors’ actions genuinely warrant the label they chose for themselves.
Despite similarities to some previous bridge exploits, the BTC that left the Liquid Network has not been reported as widely dispersed or laundered. In a notable move, the individuals behind the peg-out posted an OP_RETURN message on the blockchain, inviting contact: “we are whitehats. contact us on chain.”
Blockstream responded on the Bitcoin blockchain, urging the party in control of the funds to reach out to its security team. However, there have been no confirmed negotiations or asset returns as of now, and independent verification of the whitehat claim remains outstanding.
Liquid investigates peg-out mechanics and security model
Following the withdrawal, Liquid Network confirmed that the peg-out utilized SideSwap’s Peg-out Authorization Key (PAK), an additional security layer. The network stated that neither the PAK nor any other authorization keys appeared to be compromised, intensifying debate over whether existing withdrawal safeguards were adequate.
Liquid employs a federated security structure where 15 functionaries govern the network, and an 11-of-15 quorum is required to unlock Bitcoin from reserves. The system mandates that Liquid Bitcoin (LBTC) must be destroyed before a matching amount of BTC can be released, with peg-out authorized only to approved addresses via the PAK mechanism.
On-chain analysis confirmed that the proper amount of LBTC was burned during the withdrawal process, ensuring the liquid supply of LBTC remained fully backed and minimizing immediate risk of unbacked liabilities.
Nonetheless, the nearly 4,000 BTC peg-out amounts to around 95% of the network’s total BTC reserves. This scale led exchanges to temporarily suspend LBTC-related deposits and withdrawals in order to mitigate further exposure. Liquid paused bridge node activity while its investigation proceeded, but confirmed that USDT, DePix, and tokenized assets held on the platform were unaffected.
Critical market tools and next steps
The Liquid security incident comes at a time when technical volatility can dramatically shift crypto market dynamics. For traders navigating sudden events—whether triggered by a major Federal Reserve announcement or an unexpected altcoin listing—monitoring all relevant data is crucial. In these environments, switching between multiple apps for charts, news, and portfolio updates has grown costly for investors. As a result, many have turned to privacy-first solutions like CryptoAppsy to bring real-time charts, price alerts, asset-specific news, and macroeconomic data together on a single platform, with no account required.
Investigators continue to focus on two key areas: how this peg-out passed normal authorization checks and whether the withdrawn BTC might ultimately be returned. The answers may shape trust in federated security models going forward.





USDT
AAPL
