Crypto news report · source clearly identified
Liquid's Attackers Called Themselves White Hats, Ledger's CTO Isn't Buying It
Around 4,000 BTC were transferred out of the Liquid Network bridge in a single transaction. The actors left an on‑chain message claiming to be white‑hat hackers, a claim questioned by Ledger’s CTO.
Liquid Network, a Bitcoin layer‑2 sidechain, experienced a major incident when roughly 4,000 Bitcoin (BTC) were moved from its federation wallet to an external address. The transfer was executed via the SideSwap peg‑out service and was followed by an on‑chain message stating the actors were “white‑hats” and inviting contact.
What happened
At 14:05 UTC, a customer sent 4,000 L‑BTC to SideSwap’s peg‑out service. The Liquid federation then paid out 3,996 BTC 23 minutes later. Blockstream traced the funds to a bug in the Elements software and identified the receiving address as bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte. The address contains the message “we are whitehats. contact us on chain.”
Immediate response
Liquid froze its bridge nodes to stop further peg‑outs and notified exchanges, many of which paused L‑BTC deposits and withdrawals. Other assets on the network, such as USDT, DePix and real‑world tokens, were reported as unaffected.
Industry reaction
Charles Guillemet, Chief Technology Officer at Ledger, expressed skepticism about the “white‑hat” label, comparing the incident to the Ronin hack where validator keys were compromised. He noted that typical white‑hat disclosures do not involve draining a bridge and then seeking on‑chain contact, though he allowed for the possibility of inexperienced actors.
Current status of the funds
Public blockchain data shows the receiving address still holds about 3,998 BTC, while the Liquid federation wallet retains roughly 197 BTC. The same address later posted another message asking whether returning most of the funds to the federation would be acceptable.
Implications
The event represents roughly 95 % of all Bitcoin pegged to Liquid, according to Galaxy Research. The incident highlights the risks associated with bridge mechanisms and the importance of robust validator security.
Source & attribution
News Source
- Publisher
- BeInCrypto
- Original date
- September 7, 2026, 3:44 AM
- Original headline
- Liquid's Attackers Called Themselves White Hats, Ledger's CTO Isn't Buying It