Liquid Network hack: how Blockstream's Bitcoin sidechain lost 4,000 BTC
At 18:30 UTC on 6 September a Bitcoin tx carrying 3,996 BTC also carried a note: 'we are whitehats. contact us on chain'. Four hours earlier the Liquid federation had signed that bitcoin away in a single peg-out, every key intact. We traced the wallet back to two small peg-ins, through a day of practice on Liquid, and forward through more than twenty messages the two sides wrote into blocks, up to the moment 3,400 BTC went back. This piece is updated as new messages land.
| Update log (UTC) | What changed |
|---|---|
| 9 Sep, 12:15 UTC | The whitehat drops the code and names a price. In a tx sitting in the mempool it writes, in the clear, that Blockstream "allocated only $1.5M (maybe even 0) to secure $5B assets", calls that "a flagrant neglect of security", and says: "You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess." It ends: "Anyway we are going to publish the privatekey to decrypt our conversations afterwards." The 15 percent is the share it is holding. Read against that, the 10 percent is a demand for roughly 400 BTC, though the message does not say what it is 10 percent of. Yesterday it had already written "All messages will be in plaintext." Blockstream has kept answering in cipher, three more times, each signed and verified. Separately, 4 BTC reached the peg wallet at 08:13 on Wednesday, gathered from three coins that do not come from the whitehat's address. Nobody has said who sent it. |
| 9 Sep, 11:30 UTC | The patch is out, and it says what the bug was. Blockstream released Elements 23.3.4 at 03:14 UTC on Wednesday. It carries a second fix, merged the evening before, that rebuilds the range proof cache key so the values inside it cannot run together, with tests for "field-boundary collisions". Section 06 is rewritten around it. Meanwhile Liquid has now been stopped for more than two days, with 336 txs waiting in Blockstream's mempool. |
| 8 Sep, 04:15 UTC | The money came back, most of it. At 16:09 UTC on Monday the whitehat sent 3,400 BTC to the peg wallet in one tx and kept 598.5 BTC. Around it the two sides traded private notes: seven from Blockstream, each PGP-signed and verified by us, each from a fresh address, signed between 14:24 and 23:19; three from the whitehat, locked to Blockstream's key. Then, at 21:03, the whitehat wrote one plain message: ":(". Whether the 598.5 BTC is a bounty the company agreed to is not something either side has said in the open. Liquid has still not made a block since 04:49 Monday, and there is still no public Elements release. The Glance, the messages table, the balance chart and the closing sections are redone to match. Our watcher missed the return for several hours; the on-chain record did not. |
| 7 Sep, 14:35 UTC | A ninth message, genuine, from Blockstream. PGP clear-signed at 14:24 UTC with its published key; we verified it. Inside is a note encrypted to the whitehat's public key, with instructions on how to decrypt it in Electrum, so only the whitehat can read it. The timing says it is the answer to the 12:43 question about the return address. It came from the change address of Blockstream's earlier message, with the usual 1,000 sats to the whitehat. Unconfirmed as we write. The coin is unmoved. |
| 7 Sep, 14:05 UTC | A second hijack attempt, from the same wallet as the morning's fake reply. Unsigned, it tells the whitehat "Please do not send the coins back to bc1qdlld6…suhwxxr, instead we have a clean route address bc1q2fqggs…klrw7t. You may keep 98 bitcoins for finding the issue and aiding in finding the solution." The "clean route" address has never received a coin. Blockstream's real messages are PGP-signed, and its stated return address is the federation's peg wallet. Still no reply from Blockstream to the 12:43 question, and the coin is unmoved. |
| 7 Sep, 12:20 UTC | An eighth message, from the whitehat. "plz confirm again that we are sending the coins back to bc1qdlld6…suhwxxr", followed by "More details about the vuln fix" and a PGP message encrypted to Blockstream's key. The tx sweeps 74 inputs, the 3,998.5 BTC coin and every piece of dust that strangers had sent since 03:30, back to the same address, and pays the usual 1,000 sats to the federation. So the coin has moved, but only to itself. Confirmed in block 965,930 at 12:43 UTC. |
| 7 Sep, 11:25 UTC | Blockstream has now sent the same signed "Bridge nodes are patched" message a third time, byte for byte, this time from the address it used for its first three messages, with 1,000 sats to the whitehat. Nothing else has changed: the coin is unmoved, Liquid has had no block since 04:49, and there is no public Elements release. |
| 7 Sep, 09:35 UTC | A seventh message, and it is genuine. Blockstream wrote "Bridge nodes are patched, safe to return the funds." PGP clear-signed at 09:04:57 UTC with the same key as before; we verified it. It was written into Bitcoin twice: first in block 965,910 at 09:19, in a tx that paid nobody but a new address of its own, then again from that new address with the usual 1,000 sats to the whitehat, confirmed in block 965,912 at 09:41 UTC. Liquid has still produced no block since 04:49, and there is still no public Elements release. |
| 7 Sep, 09:05 UTC | A fake reply. A message reached the whitehat wallet reading "Thank you for finding the bug, we are working on a fix immediately, please send 3900 Bitcoin back to this address, you may keep the 98 BTC as Bounty reward." It did not come from Blockstream. It was sent from a taproot address with a small history going back to June and nothing bigger than a few hundredths of a bitcoin, it carries no PGP signature, and it asks for the coins to go to the sender rather than to the federation's peg wallet. Every genuine Blockstream message is signed with its published key. Treat this one as an attempt to hijack the return. |
| 7 Sep, 08:45 UTC | Liquid appears to have stopped producing blocks. Blockstream's node has had no block since 04:49 UTC, close to four hours, while its mempool holds 102 txs waiting to get in. A node that still takes txs but writes no blocks means the block signers have stopped; a stale explorer would show no fresh mempool traffic either. Still no message from either side since 03:30, and the whitehat coin is unmoved at block 965,904. |
| 7 Sep, 08:15 UTC | No new message from either side since 03:30; the whitehat coin is unmoved at block 965,898. Blockstream's own Liquid explorer has shown no block since 04:49 UTC. Dust and adverts keep landing on the wallet. |
| 7 Sep, 07:20 UTC | Audit pass. Corrected the day names (6 September was a Sunday) and the message count, which is six. No new message from either side; the balance is unmoved. Dust and memecoin spam keep arriving at the wallet. |
| 7 Sep, 06:30 UTC | First posting, checked at block 965,891. The last on-chain message from either side is Blockstream's "Yes, thank you." The whitehat balance is unmoved and nothing from it sits in the mempool. Liquid has carried no user txs since one in the morning. |
01 — The message"we are whitehats. contact us on chain"
Late on Sunday afternoon UTC a Bitcoin tx confirmed that spent two coins back to the same wallet, one of them the whole peg-out, and sent 1,000 sats to the federation's peg wallet. Wedged between those outputs was an OP_RETURN, the small field where anyone can write a note into a block. The note read: "we are whitehats. contact us on chain".
The on-chain sleuth ErgoBTC had already seen it in the mempool seven minutes earlier and posted the question everyone was about to ask: "Liquid got got?"
Four hours before that, the federation had signed away 3,996 BTC in a single peg-out, more than nine tenths of all it held. Nothing about the tx looked forced. Eleven of the fifteen functionaries signed it, the way they sign every peg-out. The request came through SideSwap, a Liquid member whose peg-out key is on the whitelist. Every key did exactly what it was built to do, and the bitcoin left anyway.
02 — The premiseWhat Liquid is, and what a peg-out means
Liquid is a Bitcoin sidechain built by Blockstream. You lock bitcoin in the federation's multisig on the main chain, a peg-in, and the same amount of L-BTC appears on Liquid, where blocks arrive every minute and amounts are hidden by confidential transactions. Send L-BTC back to the peg, a peg-out, and the federation releases the bitcoin. Fifteen companies run the functionary boxes that sign blocks and hold the keys, and any 11 of them can move the bitcoin. Exchanges use Liquid to settle with each other, Tether issues USDT on it, and a handful of firms run peg-in and peg-out desks for anyone who does not want to deal with the federation directly. SideSwap is one of those desks. It charges 0.1 percent.
The promise under all of that is short. There is never more L-BTC than there is bitcoin in the peg wallet. On Saturday the wallet was full. By Sunday evening it was nearly empty.
Bitquery indexes the whole Bitcoin chain, and the Liquid chain is public too, so we did not have to take anybody's word for what happened. We pulled every tx the whitehat wallets made on both chains, rebuilt the peg-out from the federation's side, and read the messages both parties wrote into blocks, checking Blockstream's PGP sigs against its own key. What follows is that record: where the L-BTC came from, how it left, what the two sides have said to each other, and what Liquid looks like while it waits. One limit belongs up front. Amounts on Liquid are hidden and Blockstream has not named the bug, so the mint itself can be found in the record but not fully explained by it.
03 — The rehearsalTwo bitcoin in, a day of practice
The wallet that would drain the peg started with about 2 BTC of its own. Two peg-ins on the Friday, a little over a bitcoin each, arrived on Liquid as L-BTC by Saturday morning. Both were funded from a pile of small taproot coins, 24 in one and 39 in the other, which reads like a wallet that had been stacking sats for a while rather than a fresh CEX withdrawal. None of the funding wallets carries a label in our database or in MetaSleuth's.
Then the wallet went to work. From Saturday lunchtime UTC until Sunday afternoon it hopped through dozens of fresh addresses, then settled on two and made 92 txs from them on Liquid. Most were tiny: one input, three outputs, a 41-sat fee. They came in bursts, with a lull over night and a final short run around noon on Sunday. Anyone watching the mempool would have seen a busy wallet doing nothing much.
Seventy of those txs had one thing in common that ordinary wallets never produce. Each carried an OP_RETURN output with the asset written in plain, L-BTC, but the amount hidden. And 68 of them carried the same hidden amount and the same range proof, byte for byte, dropped into blocks across 14 hours.
| The planted output, decoded | Value |
|---|---|
| Script | OP_RETURN with one zero byte. Unspendable by design. |
| Asset | L-BTC, written in the clear |
| Amount | Hidden. The commitment is the curve's base point, which is what you get when you commit to zero with the simplest possible blinding key. |
| Range proof | 4,166 bytes, identical in all 68 copies |
| Copies | 68, between Liquid blocks 4,049,384 and 4,050,246 |
| Cost | 41 sats per transaction |
Confidential transactions lean on range proofs. A hidden amount is fine as long as a proof shows it is not negative, because a negative output is how you print money. Nodes check thousands of these proofs and cache the ones they have already passed, so they do not do the work twice. Planting one proof 68 times over 14 hours looks like an effort to make sure every node on the network had that exact proof sitting in its cache. What the wallet then did with it is the one step the public record does not show.
04 — The exitOne transaction on Liquid, one on Bitcoin
The wallet ran three dry runs before the real thing: small peg-outs through SideSwap on Sunday morning UTC. Those were real L-BTC, or at least the federation treated them that way, and they proved the route worked end to end. SideSwap's payouts from all three were gathered into one coin of about 2.5 BTC and sent to a fresh Bitcoin address just after 14:00 UTC. That address is the one now holding all of it.
The mint came at 13:53 UTC, in a Liquid tx with one input, three outputs and a fee of 58 sats. It is the only tx in the wallet's whole history whose range proof is a different length from every other one it made. Both spendable outputs went to SideSwap within seven minutes. SideSwap swept them into its hot wallet, and its peg-out desk asked the federation for the full amount, plus a second, smaller peg-out for its own fee.
| The cash-out, minute by minute (UTC, 6 September) | What happened |
|---|---|
| 11:30 and 11:39, Liquid | Two dry-run peg-outs through SideSwap, 0.95 and 1.71 BTC |
| 11:48, Bitcoin block 965,764 | The federation pays both |
| 13:16, Bitcoin block 965,770 | A third dry run paid, 0.55 BTC |
| 13:53, Liquid block 4,050,336 | The mint. One input, three outputs, fee 58 sats, range proof 4,234 bytes against the usual 4,174 |
| 13:54 and 14:00, Liquid | Both spendable outputs reach SideSwap's hot wallet |
| 14:01, Bitcoin block 965,780 | Dry-run payouts gathered into 2.4975 BTC at the whitehat address |
| 14:06, Liquid block 4,050,349 | SideSwap requests a peg-out of 3,996.018 BTC, plus 3.996 BTC for its 0.1 percent fee |
| 14:28:56, Bitcoin block 965,783 | The federation pays. In the same block SideSwap forwards 3,995.99999857 BTC to the whitehat address |
Then the federation paid, in one big tx that pulled together most of the coins the peg wallet had. The fee was pocket change.
| The federation's peg-out, block 965,783 | BTC |
|---|---|
| 83 inputs, all from the peg wallet | 4,019.4443 |
| Size and fee | 122 kilobytes, 34,097 sats, about $27 to move $318 million |
| To SideSwap's payout address, the customer's peg-out | 3,996.0183 |
| To SideSwap, its 0.1 percent fee | 3.9960 |
| To a third address, an unrelated customer's peg-out | 2.6514 |
| Back to the peg wallet as change, in ten equal pieces | 16.7782 |
| Peg wallet before and after | 4,205.29 to 202.63 |
In the same block SideSwap forwarded the customer's bitcoin, less its fee, to the address that had taken the dry-run payout half an hour earlier. The federation processed two more small peg-outs that afternoon before the bridge was switched off. That is how the peg wallet arrived at the balance it holds now.
05 — The conversationTwenty-six messages, and counting
Most hackers who want to talk open a Telegram account. This one wrote into Bitcoin, and Blockstream, after one short public note, decided to answer there too. Every message is a tx that pays 1,000 sats to the other side and carries the text in an OP_RETURN. We decoded all of them from the raw blocks and checked every Blockstream signature against its published key; three of the 26 are copies of one message. From Monday the talk went private: Blockstream locks its notes to the key behind the whitehat's address and the whitehat locks its own to the PGP key. On Tuesday afternoon the whitehat announced it was going back to plain text, and on Wednesday it used it.
| Time (UTC) and sender | Message |
|---|---|
| 6 Sep 18:30 Whitehat | "we are whitehats. contact us on chain" |
| 6 Sep 19:31 Blockstream | "Please contact security@blockstream.com" |
| 7 Sep 01:49 Blockstream | A short ciphertext encrypted to the whitehat's public key, plus a detached PGP signature from security@blockstream.com. We verified it. Signed at 01:14 UTC. |
| 7 Sep 02:20 Whitehat | "sending most back to bc1qdlld6…suhwxxr, is that ok" |
| 7 Sep 03:30 Whitehat | "Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix." Followed by a PGP message encrypted to Blockstream's key, which only Blockstream can read, all in one OP_RETURN. |
| 7 Sep 03:30, same block Blockstream | "Yes, thank you." PGP clear-signed at 03:16 UTC, so it answers the 02:20 question and not the demand that landed in the same block. We verified it. |
| 7 Sep 09:19 and 09:41 Blockstream | "Bridge nodes are patched, safe to return the funds." PGP clear-signed at 09:04 UTC. We verified it. Written into block 965,910 once without paying the whitehat, then re-sent from a new address with the usual 1,000 sats in block 965,912, and sent a third time from its original address late in the morning. |
| 7 Sep 12:43, block 965,930 Whitehat | "plz confirm again that we are sending the coins back to bc1qdlld6…suhwxxr. More details about the vuln fix:" followed by a PGP message encrypted to Blockstream's key. 74 inputs, the big coin sent back to itself. |
| 7 Sep 14:24 to 17:35, block 965,956 Blockstream | Four notes locked to the whitehat's key, each wrapped in a PGP signature we verified, each from a fresh address, the first with a how-to for reading it in Electrum. Signed at 14:24, 15:25, 16:23 and 17:35, all landed together at 17:54. Only the whitehat can read them. |
| 7 Sep 15:31, block 965,948 Whitehat | A message locked to Blockstream's key, in a tx that gathers 34 inputs of dust. Unreadable to anyone else. |
| 7 Sep 16:09, block 965,950 Whitehat | No text. The return: 3,400 BTC to the peg wallet, 598.4996 BTC back to itself, in one tx with 15 inputs. |
| 7 Sep 18:31 to 18:35, blocks 965,962 and 965,967 Both | Two more coded notes from Blockstream, signed 18:31, verified, from two more fresh wallets. Two coded messages from the whitehat back to it in the same window. |
| 7 Sep 21:03, block 965,973 Whitehat | ":(" |
| 8 Sep 00:11 and 06:02 Blockstream | Two more coded notes, verified, from two more fresh wallets. |
| 8 Sep 09:41, block 966,052 Whitehat | Another coded message to Blockstream. |
| 8 Sep 12:59, block 966,079 Blockstream | Another coded note, verified. |
| 8 Sep 14:25, block 966,087 Whitehat | Two txs in the same block. One coded. The other in the clear: "All messages will be in plaintext." |
| 9 Sep, in the mempool Both | Blockstream sends a fourth coded note, still verified. The whitehat answers in the clear, at length, demanding a bounty of 10 percent paid by Blockstream and promising to publish the key that unlocks the whole coded exchange. |
Three details in the raw txs say more than the words. Blockstream's first reply came from a fresh address funded out of a two-key wallet with a long recovery timeout, the same form Blockstream's own Green wallet uses. Its second message was encrypted to the public key the whitehat had exposed by spending, in the Electrum ECIES format, and signed with the key whose fingerprint ends 6844 A2D6. We fetched that key from blockstream.com, imported it, and both sigs verify against "Blockstream Security Reporting". Change one character of either text and the check fails.
The whitehat's txs carry a tell of their own. Each sets a locktime just below the current height, the anti-fee-sniping habit of Bitcoin Core's wallet family, and each sweeps up every scrap of dust that others had sent to the address since the last message. That is why the second message has 15 inputs. By the time of the third, two dozen dust payments had arrived from outsiders wanting to be read: a Signal handle, a New York lawyer offering pro bono help with "a clean return", a wallet app plugging itself four times, a Monero swap desk promising no freezes, a second swap site openly pitching itself for laundering, and a memecoin. The whitehat spent all of it as fee change.
Not everyone reads the label the wallet gave itself. Charles Guillemet, Ledger's CTO, wrote on X that draining a bridge and then asking for on-chain contact "doesn't look like usual white hats practices". He added that criminal crews do not usually try to contact their victims either, and floated the idea of "people with good intentions that intensively played with recent LLMs and are not used to responsible disclosures".
06 — The bugTwo hashes that ran together
SideSwap said within hours that "the L-BTC came from an Elements bug, not from any SideSwap system", and Liquid said no key was compromised. Elements is the open-source software every Liquid node runs. Neither company has named the bug even now. But on Wednesday morning Blockstream shipped an emergency release, and what it changes is the same corner of the code the 68 planted outputs were aimed at.
| Elements, the range proof cache | When |
|---|---|
| First fix, by a Blockstream engineer: "range proof cache bind to asset and scriptpubkey" | 3 Aug |
| Merged to the main branch | 2 Sep |
| Backported to the 23.x line | 3 Sep |
| Release everyone was running, 23.3.3, without either fix | 13 Apr |
| The mint on Liquid | 6 Sep, 13:53 UTC |
| First fix merged into the release branch | 6 Sep, 17:21 UTC |
| The whitehat: "the chain is under risk at latest commit right now" | 7 Sep, 03:30 UTC |
| Second fix merged: "harden range proof cache keys" | 8 Sep, 19:06 UTC |
| Elements 23.3.4 released, with both | 9 Sep, 03:14 UTC |
Here is what the cache does. Checking a range proof is slow, so a node that has passed one writes a short key into a table and skips the work next time the same thing turns up. The key was built by gluing four values end to end and hashing the result: the proof, the hidden amount, the hidden asset, and the output script. Nothing marked where one value stopped and the next began. Two different sets of four can therefore glue into the same bytes, land on the same key, and the second set is waved through on the strength of the first. The new code writes the length of each value before the value, which ends that.
The whitehat had said on Sunday morning that the chain was "under risk at latest commit right now". That reads as a complaint that the August fix was not enough, and the August fix is the one that added the asset and the script to the key without separating them. The new tests in the release cover, in the words of the pull request, "field-boundary collisions". Blockstream has published no post-mortem and named no bug, so a patch is all there is to read. But a node that can be handed a proof it never checked is how you print money on a chain where amounts are hidden, and planting one proof 68 times is how you make sure every node holds the first half of the pair.
07 — Where it standsMost of the money is back, the chain is not
Liquid announced on Sunday evening that its bridge nodes were off and the chain was "effectively paused", and asked CEXs to stop L-BTC deposits and withdrawals. Blocks kept coming every minute at first, because the signers still made them, but nothing went in. User txs fell from about 190 an hour on Sunday afternoon to two in the hour after midnight, and none since one in the morning UTC on Monday. Then, at 04:49 on Monday, the blocks stopped too. They have not restarted since. More than two days later Blockstream's own node still shows block 4,051,232 as the tip, with 336 txs waiting in its mempool.
On Monday the bitcoin moved. One tx from the whitehat address, 15 inputs, two outputs: 3,400 BTC to the peg wallet and the rest back to itself. It landed at 16:09 UTC, nearly seven hours after Blockstream first wrote that its bridge nodes were patched, and in the middle of a run of coded notes between the two sides. What the whitehat kept, 598.5 BTC, is about 15 percent of what was taken and roughly $48 million at Monday's price. Neither side has said in the open whether that was agreed. The whitehat's only plain words afterwards were a sad face.
The peg wallet now holds about 3,601 BTC, the 3,597 from the return plus 4 BTC that arrived on Wednesday morning from coins we could not tie to either side. Set that against roughly 4,200 honest L-BTC still out in CEX accounts and wallets, so each L-BTC is backed by about 86 cents of bitcoin rather than a dollar. That gap is the 598.5 BTC the whitehat kept plus SideSwap's fee and the dry runs, and somebody will have to fill it before the peg is whole. Tether's USDT on Liquid and the other issued assets are not touched by this, because they were never backed by the peg wallet in the first place.
08 — What we are watchingOpen threads
"Most" turned out to mean 85 percent, and on Wednesday the whitehat said in the clear what the coded notes had been about. It wants Blockstream to pay a bounty of 10 percent out of its own pocket, which set against the 15 percent it holds reads as about 400 BTC. If not, it says, the 15 percent it is sitting on becomes a loss for everyone holding L-BTC. It has also promised to publish the key that unlocks the whole coded exchange, which would put both sides of a live negotiation in public. Blockstream has answered every message and said nothing in the open. Blockstream has now shipped the patched release and still said nothing in public about the bug itself. Liquid has not restarted. The three dry-run peg-outs and SideSwap's fee are real bitcoin paid for L-BTC that never existed, and they sit on the same side of the ledger as the 598.5. And Elements runs more than Liquid. Every sidechain on the same code had the same hole on Sunday, and each one now has a release to take.
We are re-reading both wallets as blocks arrive and will add each new message, and the restart of Liquid when it comes, to the log at the top of this piece.
Read the same blocks
Every figure here came from public blocks on Bitcoin and Liquid: raw txs, OP_RETURN outputs, the federation's inputs and change, and the whitehat wallet's full history. Bitquery's Bitcoin archive and the MCP server let you ask the same questions in plain English.
Anyone who wants to check a number here can pull the same records. We took the same route through the Coldcard theft, the Aquifer drain on Solana and the $120 million Tectonic exploit, and the OP_RETURN habit that carried this negotiation is the subject of what people write into Bitcoin blocks. Teams that do this work under a mandate use our crypto investigation services and the money flow tools behind them.
| The record | Address or transaction |
|---|---|
| The whitehat wallet, holding 598.5 BTC | bc1ql4mfu6…yqjlte |
| The return, 3,400 BTC to the peg wallet, 16:09 UTC 7 Sep | a6d697a2…49a46d |
| The Liquid federation's peg wallet | bc1qdlld6…suhwxxr |
| Blockstream's message address | bc1qn8mgsm…2mfqym |
| The federation's 3,996 BTC peg-out, 14:28:56 UTC 6 Sep | 8db751a6…a7b140 |
| SideSwap forwarding 3,995.99999857 BTC to the customer, same block | 85d2ca15…645043 |
| The 2.4975 BTC dry-run payout, 14:01 UTC | afff7f39…61443b |
| Peg-in one, 1.0825 BTC, 4 Sep 03:11 UTC | f156fc7e…1c9a52 |
| Peg-in two, 1.0660 BTC, 4 Sep 16:36 UTC | 4aa0ce4f…f2858e |
| Liquid: peg-in one claimed, 4 Sep 19:47 UTC | 3628cc2c…72b389 |
| Liquid: one of the 68 planted outputs, 6 Sep 12:21 UTC | 3d00b94c…6bd6e8 |
| Liquid: the mint, block 4,050,336, 13:53 UTC | f24a4b17…0a183f |
| Liquid: SideSwap's sweep, 14:00 UTC | c6ea588a…d72267 |
| Liquid: the 3,996.018 BTC peg-out request, 14:06 UTC | ce4caece…e988f2 |
| Liquid: SideSwap's 3.996 BTC fee peg-out, same block | 731f8fdf…e47d8a |
| Blockstream's PGP key | 1176 542D A98E 71E1 3372 2EF7 4AC8 CC88 6844 A2D6 |
This piece covers the Bitcoin wallets bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte, bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr and bc1qn8mgsmxx42j3fflqfkh0cqhdd6mj4h9q2mfqym, and the Liquid wallets ex1q7kgx4ptje7px48tn0nsmc6se5pngdp3smpqa2w and ex1qlh0wspc3m57h6rzm25f7z3qssskcqcghsg76hm, from 4 September 2026 to the time of the last update in the log above. Bitcoin figures come from Bitquery's archive and were cross-checked against a public block explorer. Liquid figures were decoded from raw blocks.
Amounts on Liquid are hidden by confidential transactions. Statements about which Liquid tx created the L-BTC rest on the wallet's tx structure, timing and proof sizes, and on where its outputs went, not on the amounts themselves. Blockstream has not named the bug, and the link drawn here between the planted outputs and the range proof cache fix is a fit, not a confirmation.
The word whitehat is the wallet's own description of itself. Its use here is not a judgement about the people behind it. Nothing in the record identifies them.
SideSwap is named because the peg-out passed through its service. Its own statement that its key was not compromised fits all we found. The dollar figure uses a bitcoin price of about $79,700 on 6 September.
Blockstream's messages were verified by importing the key published at blockstream.com/pgp.txt and running gpg against the exact bytes decoded from the OP_RETURN outputs. Others have reported the same result on their own.
Trace the next one on your own data
Every number here came from public blocks, pulled through Bitquery's archive of Bitcoin and 40+ other networks: txs, OP_RETURN outputs, address histories and the money flows between them. The same data powers exchange risk desks and on-chain investigators.