Bitcoin Layer 2 community Liquid Community has reported a safety incident by which purported white-hat hackers withdrew roughly 4,000 BTC, value $320 million, from the Liquid Federation pockets.
Blockstream is making an attempt to contact the events concerned by means of a signed on-chain message.
Community Bug Should Be Mounted First
In an replace, Liquid mentioned the funds have been withdrawn utilizing the SideSwap PAK (Peg-out Authorization Key) however acknowledged that the important thing itself was not compromised and that no different keys have been in jeopardy. Crypto exchanges have been knowledgeable and have already suspended, or are getting ready to droop, LBTC deposits and withdrawals.
Liquid mentioned different belongings on the community, together with USDT, DePix and real-world belongings, weren’t affected. The community has additionally quickly disabled its bridge nodes, that means new transactions can’t be submitted. Consequently, the sidechain is successfully paused whereas the problem is being addressed.
“Liquid wallets might be impacted, and we’re sorry for any inconvenience. Federation members are actively engaged on resolving this so we are able to restore regular community exercise.”
The general public back-and-forth between Blockstream and the occasion claiming to be the white-hat hacker behind the withdrawal is constant on-chain. In accordance with Samson Mow, the hacker seems to desire speaking publicly moderately than by way of e-mail, and is posting messages by way of Bitcoin transaction knowledge.
They even requested Blockstream to make contact on Sign at @m671aw.70″
The change started at 11:30 AM PDT, when the hacker wrote, “we’re whitehats. contact us on chain.” Blockstream responded at 12:31 PM on September 6 and requested the hacker to contact its safety staff by e-mail. Later, Blockstream despatched an encrypted, PGP-signed message to the hacker’s key.
The dialogue between @Blockstream and the white-hat hacker (WHH) relating to the ~4000 BTC from @Liquid_BTC is going on in public. It appears to be their choice over e-mail. Because it’s exhausting to observe the chain of messages in OP_RETURN, right here’s a abstract with hyperlinks.
11:30 AM PDT -… https://t.co/IEXyFpBITx
— Samson Mow (@Excellion) September 7, 2026
At 7:20 PM, the hacker mentioned they deliberate to ship many of the funds again and requested whether or not a specified handle was acceptable. About an hour later, they mentioned the bug wanted to be mounted first, and added,
“The chain is beneath threat at newest commit proper now. Make sure that each node is patched. Then we’ll switch the cash again safely after confirming the repair.”
Blockstream replied, “Sure, thanks,” at 8:30 PM. As of 9:12 PM PDT, round 3,998.5 BTC remained unmoved. There have been no additional messages from both facet.
Uncommon Hacker Habits
Ledger CTO Charles Guillemet was skeptical of the white-hat declare and identified that reputable safety researchers wouldn’t usually drain a bridge after which ask to be contacted on-chain.
He drew parallels with the Ronin hack, by which attackers stole round $625 million after compromising validator keys, and the Euler exploit, the place the attacker sought to barter the return of funds after the theft.
The transfer to Sign additionally did little to alter Guillemet’s opinion that the conduct was in contrast to common white-hat exercise. Regardless of this, the exec famous that legal teams don’t usually attain out to their victims both.
The publish Supposed White-Hat Hackers Drain $320 Million in BTC From Liquid Community, Say They’ll Return It After Repair appeared first on CryptoPotato.