Roughly 4,000 BTC pulled from Liquid bridge under contested “whitehat” label
Security & Exploits ·
Ledger's chief technology officer says an on-chain message accompanying the withdrawal does little to prove benign intent.
About 4,000 BTC left the Liquid bridge in a withdrawal that has drawn scrutiny rather than reassurance, according to wublockchain.xyz. The party behind the move attached an OP_RETURN note reading "we are whitehats. contact us on chain," a message meant to signal the funds were taken for protective rather than malicious reasons.
Ledger CTO Charles Guillemet pushed back on that framing, arguing that genuine white hats do not typically drain a bridge first and only afterward invite contact through the blockchain itself. He pointed to two prior incidents as counterexamples of how such claims can mask something else: the Ronin bridge breach, where attackers compromised validator keys to take roughly $625 million, and the Euler exploit, in which the attacker later tried to negotiate a return of the stolen funds only after the damage was done.
Blockstream has not accepted the on-chain explanation at face value either. The company responded with its own on-chain message asking whoever moved the funds to reach out through an official security channel instead of continuing communication via blockchain notes, per the same report.
A separate post circulating on x.com frames the episode as an exploit of Blockstream's Liquid Network carried out by parties describing themselves as whitehats, aligning with the roughly 4,000 BTC figure cited elsewhere. That characterization mirrors the skepticism already raised by Guillemet, since a stated whitehat motive alone does not resolve whether the withdrawal was authorized or simply asserted after the fact.
What remains unclear is whether the party that moved the funds will respond to Blockstream's request for direct contact, and whether the 4,000 BTC will be returned or retained. Also unresolved is the technical means by which the bridge was drained, and whether the incident reflects a vulnerability in the Liquid bridge itself or a compromise of access credentials, details not yet addressed in the available reporting.