greysonz (OP)
Member


Activity: 70
Merit: 28
gz
|
 |
September 06, 2026, 07:43:21 PM |
|
Almost 4,000 BTC just moved from the Liquid Network bridge all at once. OP Return saying: "we are whitehats. contact us on chain". TXID: c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19 
|
|
|
|
|
PrivacyG
Legendary

Activity: 1638
Merit: 3018
Fight for Privacy.
|
 |
September 06, 2026, 07:52:54 PM |
|
Well. There is at least one thing to note here. It would be a really good thing to see some positive outcome at least once every year after so many really bad Coldcard-like disasters.
|
|
|
|
|
Ashawowo(OS)
|
From my observation, they didn't steal the coins,, almost everything went back to the imput address as change, they were just sending a message across to inform them of their coins being vulnerable and maybe seeking an offer to fix it the bug for them when contacted. They're good guys. It's something positive as PrivacyG noted.
|
|
|
|
Ambatman
Legendary

Activity: 1120
Merit: 1441
Don't tell anyone
|
 |
September 06, 2026, 08:23:32 PM |
|
Well not a bad route imo It's better to at least have something Than move everything and still be unable to make use of them Like most major hacks In fear of compromising their identity. Hopefully this serves a precedence rather than stealing it's better to assist. Might to be much but it's better to play safe and have a good name.
|
|
|
|
FinneysTrueVision
Legendary

Activity: 2506
Merit: 1288
|
 |
September 06, 2026, 08:24:25 PM Last edit: September 06, 2026, 08:50:46 PM by FinneysTrueVision Merited by internetional (2) |
|
From my observation, they didn't steal the coins,, almost everything went back to the imput address as change, they were just sending a message across to inform them of their coins being vulnerable and maybe seeking an offer to fix it the bug for them when contacted. They're good guys. It's something positive as PrivacyG noted.
The input address might belong to the hacker. It was funded by an address that received 3,996 BTC from a Liquid peg-out in this transaction https://mempool.space/tx/8db751a650ae2f12006b7e8c69a75e4df360e8afd6b9e05ae0b9fa6458a7b140It only sent back 1,000 satoshis to the Liquid federation address along with the OP_RETURN message.
Here is more information, posted by the Liquid Network account on X. https://x.com/Liquid_BTC/status/2096696272447218108
|
| EARNBET | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ | ███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ |
▄▄▄ ▄▄▄███████▐███▌███████▄▄▄ █████████████████████████ ▀████▄▄▄███████▄▄▄████▀ █████████████████████ ▐███████████████████▌ ███████████████████ ███████████████████ ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
| King of The Castle $200,000 in prizes | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ | 62.5% | RAKEBACK BONUS |
|
|
|
|
sergiorus
|
 |
September 06, 2026, 08:38:28 PM |
|
From my observation, they didn't steal the coins,, almost everything went back to the imput address as change, they were just sending a message across to inform them of their coins being vulnerable and maybe seeking an offer to fix it the bug for them when contacted. They're good guys. It's something positive as PrivacyG noted.
The input address might belong to the hacker. It received 3,996 BTC from a Liquid peg-out in this transaction https://mempool.space/tx/8db751a650ae2f12006b7e8c69a75e4df360e8afd6b9e05ae0b9fa6458a7b140It only sent back 1,000 satoshis to the Liquid federation address along with the OP_RETURN message. Where did the remaining 2.497 BTC go? From what I see they went to the hacker too but in a separate transaction, please correct me if I'm wrong.
|
|
|
|
FinneysTrueVision
Legendary

Activity: 2506
Merit: 1288
|
 |
September 06, 2026, 09:00:31 PM |
|
Where did the remaining 2.497 BTC go?
From what I see they went to the hacker too but in a separate transaction, please correct me if I'm wrong.
The 2.497 BTC was already in the hacker’s address. The source of that BTC is currently unknown. Given the close timing of when they received it, it could be related to this same incident. They consolidated it with the 3,996 BTC that was drained from the Liquid Network and sent it back to their own address.
|
| EARNBET | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ | ███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ |
▄▄▄ ▄▄▄███████▐███▌███████▄▄▄ █████████████████████████ ▀████▄▄▄███████▄▄▄████▀ █████████████████████ ▐███████████████████▌ ███████████████████ ███████████████████ ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
| King of The Castle $200,000 in prizes | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ | 62.5% | RAKEBACK BONUS |
|
|
|
|
sergiorus
|
 |
September 06, 2026, 09:12:06 PM |
|
Ledger CTO Charles Guilleme on the matter: "White hats don't drain a bridge and then solicit an "on-chain" contact. This echoes the Ronin hack, where attackers compromised validator keys to steal ~$625M, and the "let's talk" framing is the same move Euler's attacker used to negotiate a return after the fact." Source: https://x.com/p3b7_/status/2096685528267592008
|
|
|
|
TheButterZone
Legendary

Activity: 3262
Merit: 1126
RIP Mommy
|
 |
Today at 02:58:15 AM |
|
I never got into Liquid. Could the hacker/s have pushed a TX that sent everyone's pegged Liquid coins to everyone's respective pkh addresses, aka a massive full refund minus TX fee?
|
|
|
|
arwin100
Legendary

Activity: 3570
Merit: 1106
Jack of all trades 💯
|
 |
Today at 03:16:49 AM |
|
Ledger CTO Charles Guilleme on the matter: "White hats don't drain a bridge and then solicit an "on-chain" contact. This echoes the Ronin hack, where attackers compromised validator keys to steal ~$625M, and the "let's talk" framing is the same move Euler's attacker used to negotiate a return after the fact." Source: https://x.com/p3b7_/status/2096685528267592008It seems they are trying to negotiate for a possible bounty on the exploit they have found. Also looks like this case is modern robbery on which the platform don't have a choice, but to give a reward to those claiming to be a white hat hackers. This one could possibly attract more exploits and after the hackers got trapped, next they claim to be a white hat. So they still have chance to withdraw their bounty funds, without getting bothered by investigators and the platform owner.
|
|
|
|
collardelay
Newbie

Activity: 29
Merit: 11
|
 |
Today at 03:38:33 AM |
|
Ledger CTO Charles Guilleme on the matter: "White hats don't drain a bridge and then solicit an "on-chain" contact. This echoes the Ronin hack, where attackers compromised validator keys to steal ~$625M, and the "let's talk" framing is the same move Euler's attacker used to negotiate a return after the fact." Source: https://x.com/p3b7_/status/2096685528267592008It seems they are trying to negotiate for a possible bounty on the exploit they have found. Also looks like this case is modern robbery on which the platform don't have a choice, but to give a reward to those claiming to be a white hat hackers. This one could possibly attract more exploits and after the hackers got trapped, next they claim to be a white hat. So they still have chance to withdraw their bounty funds, without getting bothered by investigators and the platform owner. That's an interesting way to demand for a bounty from the network. They will likely have to get in touch with them, and negotiate some form of settlement. Let's just wait and see as the situation evolves.
|
|
|
|
|
greysonz (OP)
Member


Activity: 70
Merit: 28
gz
|
 |
Today at 04:42:09 AM Last edit: Today at 07:47:58 AM by greysonz |
|
From my observation, they didn't steal the coins,, almost everything went back to the imput address as change, they were just sending a message across to inform them of their coins being vulnerable and maybe seeking an offer to fix it the bug for them when contacted. They're good guys. It's something positive as PrivacyG noted.
The input address might belong to the hacker. It was funded by an address that received 3,996 BTC from a Liquid peg-out in this transaction https://mempool.space/tx/8db751a650ae2f12006b7e8c69a75e4df360e8afd6b9e05ae0b9fa6458a7b140It was obvious that this wasn’t white hackers, even though some guys here were hoping the situation wasn’t negative. I believe that white hackers would never sign a transaction in op_return, since such a large transaction would be noticed by on‑chain analysts anyway. And white hackers always end up sharing information about their victories over hackers on social media. In our case, this signature was a naive attempt to dispel suspicion. Meanwhile, the Liquid white hats claim they will return most of the 4,000 BTC as soon as the Liquid network bug is fixed. A real chat began on the blockchain between the hacker and Blockstream: The hackers were negotiating with Blockstream via OP_RETURN messages and encrypted PGP text - block 965,822: the Blockstream address sent 1,000 satoshis with the text “Please contact security at blockstream dot com”. - block 965,865: an encrypted message addressed to the holder’s own key, with a detached PGP signature. This signature is verified using the key published at blockstream.com/pgp.txt- block 965,869: the hacker responded by spending the funds on themselves, but sending 1,000 satoshis to the federation’s wallet for linking, along with the text: “sending most back to [the federation address], is that ok”. - Block 965,875: substantive response. Another self‑transaction, with 1,000 satoshis sent to the federation, and OP_RETURN: “Please fix the bug first. The chain is at risk at the latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.” The technical details follow in the form of a PGP message encrypted with the published Blockstream key, so only Blockstream can read it. What a way to comunicate.... 
|
|
|
|
|
Cookdata
Legendary

Activity: 1792
Merit: 1479
Not Your Keys, Not Your Bitcoin
|
 |
Today at 09:43:31 AM |
|
 Oh yea!
|
|
|
|
|
Sticky Bomb
|
 |
Today at 11:12:29 AM |
|
Blockstream has responded to the white hats with the message "Please contact security@blockstream.com" let's keep watching how it unfolds. If they're really white hats, they'll reach out for a negotiation and possible return of stolen assets.  Img source: X
|
|
|
|
|
Lida93
|
 |
Today at 11:16:53 AM |
|
It seems they are trying to negotiate for a possible bounty on the exploit they have found.
Also looks like this case is modern robbery on which the platform don't have a choice, but to give a reward to those claiming to be a white hat hackers.
This one could possibly attract more exploits and after the hackers got trapped, next they claim to be a white hat. So they still have chance to withdraw their bounty funds, without getting bothered by investigators and the platform owner.
Should this pattern be something to raise fears about hackers now using this plot as means to get away with stealing and getting rewarded for it just because they offered to return the stolen funds in disguise of intent to expose a vulnerability and at same time giving a "technical support" to the security situation. This story reminds me of the 2022 Mango Markets hack which drained about $117 million, and despite how they proposed to return the stolen funds he still got arrested regardless of the cut in deal.
|
|
|
|
cryptoaddictchie
Legendary

Activity: 2926
Merit: 1630
Crypto Exchange Aggregator
|
 |
Today at 11:30:22 AM |
|
From my observation, they didn't steal the coins,, almost everything went back to the imput address as change, they were just sending a message across to inform them of their coins being vulnerable and maybe seeking an offer to fix it the bug for them when contacted. They're good guys. It's something positive as PrivacyG noted.
Thats right, I admire whitehats hacker like them that able to say that the user or company has a vulnerable status of their security. Probably asking some % of bounty or compensation for finding some bugs which is a very decent for any developers today. However if ever the greedy hackers came at them surely the owner can kiss goodbye on that 4k btc.
|
|
|
|
Thalez
Newbie

Activity: 1
Merit: 0
|
 |
Today at 12:03:16 PM |
|
Should this pattern be something to raise fears about hackers now using this plot as means to get away with stealing and getting rewarded for it just because they offered to return the stolen funds in disguise of intent to expose a vulnerability and at same time giving a "technical support" to the security situation.
So you prefer something similar to another CC event ? This same vulnerabilities can be exploited by other groups and lost forever even if they never spend it. Nothing related to bouty for now, even if it looks like they are trying to create one out of It but still not as worse as having it stolen completely.
|
|
|
|
|
ryzaadit
Legendary

Activity: 3318
Merit: 1466
|
 |
Today at 12:08:57 PM |
|
I add more the current following discussion between White Hacker x Blockchair & Team Liquid. [1] Blockstream send a message with encryption by using Electrum BIE1 ECIES to White Hackers. Hash TX: https://mempool.space/tx/bd81219691eb1e22475c5985d847fa888c38f1b6d2cb2b7193f54d0cfa72394c [2] The White Hacker Respoding is fine to send the BTC into these following address: bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr jika tidak masalah sama sekali dari pihak Team Liquid/Blockchair. Hash TX: https://mempool.space/tx/3a3eac4a26395b8c2563aaf1eb8b1b77798c81c7d6337f51321827a244a480aa [3] The White Hacker telling to Liquid Network / Blockchair to try fix the current bugs and make sure everything is safe. After that's he can started to send back the fund to them. Hash TX: https://mempool.space/tx/83825b2135dd0abac12c9dfe17f29ab81b3427e1ae864947b0bebce5e47c3c4b [4] Blockhair responded the request "Yes thank you". Hash TX: https://mempool.space/tx/8a444eed65c4584f138e08ee138f61490ef73e84f71e14dac3ca66c230cf7e97 Should this pattern be something to raise fears about hackers now using this plot as means to get away with stealing and getting rewarded for it just because they offered to return the stolen funds in disguise of intent to expose a vulnerability and at same time giving a "technical support" to the security situation. This story reminds me of the 2022 Mango Markets hack which drained about $117 million, and despite how they proposed to return the stolen funds he still got arrested regardless of the cut in deal. Trying to read about the case you mentioned, there are also allegation for Market Manipulation from the hackers. Could those be used as turning points for him? And this is a bit different exploited. FYI, these typical hacking activities will require less work for the victim, rather than needing to track and wait for the hackers to be arrested. Another reason why these kinds of bugs are pretty dangerous to share, even if you're trying to contact the team project? who knows there will be some insider who shares these to outside and makes some arrangement to use the exploited bug report for other hacker group.
|
| EARNBET | | | ⚽ 🏀 🏈 🏓 🎯 🥊 |
| ⚾ 🎾 ⛳ 🏐 🏏 🏎️ | | |
███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | ....HIGHEST.... VIP REWARDS ✔ G U A R A N T E E D
| | | 🜲 | KING OF THE CASTLE $200K in prizes | | | ..PLAY NOW.. |
|
|
|
|
Satofan44
|
 |
Today at 12:12:43 PM |
|
Ledger CTO Charles Guilleme on the matter: "White hats don't drain a bridge and then solicit an "on-chain" contact. This echoes the Ronin hack, where attackers compromised validator keys to steal ~$625M, and the "let's talk" framing is the same move Euler's attacker used to negotiate a return after the fact." Source: https://x.com/p3b7_/status/2096685528267592008Perhaps next time they would hire attentive people to look at the relevant communication channels. What do they think that someone is going to beg them to write a response to their reports? If they don't listen the normal way, then the entity is going to make them listen the hard way. If the coins end up being returned then they should be happy that this was not another repeat of Coldcard rather than attacking those that found issues with their implementation. Another justifiable reason for the upset of those that do this kind of exploitation is that often companies tend to underpay, delay payment or outright refuse to acknowledge the bug at all with some kind of nonsense. Extremely critical bugs like this should be rewarded quite nicely, but this is rarely the case. The examples that I write about come from stories of individuals dealing with large tech companies as well. Another reason why these kinds of bugs are pretty dangerous to share, even if you're trying to contact the team project? who knows there will be some insider who shares these to outside and makes some arrangement to use the exploited bug report for other hacker group.
No. If you are not able to find exploits yourself, don't imagine that it comes from an insider sharing knowledge with an external actor.  Oh yea! Bitcoin had its own fair share of issues, just because they weren't exploited on time in recent history that does not mean that it is significantly different from this. Liquid is great for what it does.
|
|
|
|
zark89
Newbie

Activity: 60
Merit: 0
|
 |
Today at 01:28:35 PM |
|
I'm really curious to know what the exact bug was that allowed this to happen.
What surprises me even more is the withdrawal process itself. If roughly 4,000 BTC represented around 95% of the federation's BTC reserves, was there really no additional human approval or emergency circuit breaker before such a massive amount could leave?
I understand that the federation uses automated validation and multiple signers/HSMs, but if all of them are running the same flawed logic, they can all agree on the same wrong result.
For normal withdrawals, automation makes sense. But when a single withdrawal represents something like 30%, 50%, or in this case potentially ~95% of total reserves, I would expect the system to stop automatically and require additional independent/human verification.
I'm very interested to see the technical post-mortem, especially what kind of Elements/Liquid bug could make all of the automated checks consider such a huge peg-out valid.
|
|
|
|
|
|