Skip to main content
Home » Cryptocurrency » News » Liquid’s Bitcoin Crisis: White-Hat Heroes or Extortionists With a PR Strategy?

Liquid’s Bitcoin Crisis: White-Hat Heroes or Extortionists With a PR Strategy?

5 min read
Liquid’s Bitcoin Crisis: White-Hat Heroes or Extortionists With a PR Strategy?

Stay connected with KayaToday, follow us on Instagram and Facebook for the latest news and reviews delivered straight to you.


When hackers drain 95% of a blockchain network’s reserves and then hand most of it back, the natural instinct is relief. But the fine print of what actually happened to Liquid Network over the weekend raises a harder question: at what point does a self-described white-hat rescue become leverage?

On Monday, JAN3 CEO and former Blockstream executive Samson Mow confirmed that 3,400 Bitcoin, worth approximately $270 million, had been returned to the Liquid Federation wallet. The funds came back after hackers had withdrawn roughly 4,000 BTC from the sidechain’s reserves on Sunday, representing nearly the entire holdings of approximately 4,200 BTC. Onchain records confirm the exact 3,400 BTC transfer back to the federation’s wallet address. About 598 BTC, worth roughly $47 million at current prices, remains outstanding.

How a Bug in the Foundations Unlocked the Vault

The incident did not stem from a compromised private key, which would have been the most obvious attack vector. Instead, Liquid and SideSwap confirmed that the original withdrawal was processed through SideSwap’s Peg-out Authorization Key, and that the key itself was not breached. The actual vulnerability traced back to Elements, the open-source software that underpins Liquid’s entire architecture. SideSwap said the L-BTC involved in the withdrawal originated from a bug within that codebase.

This distinction matters. Liquid is a federated Bitcoin sidechain, meaning it issues its own token called L-BTC against actual Bitcoin held collectively by its federation of member institutions. The security model depends on that federation maintaining custody of the underlying BTC. When roughly 4,000 BTC left the federation wallet, it effectively stripped most of the backing from every unit of L-BTC in circulation, freezing the network and leaving users unable to transact or exit.

Blockstream moved quickly. The company deployed updated software, patched the affected bridge nodes, and coordinated with federation members to prepare a controlled restart. The actors behind the withdrawal communicated with Blockstream through signed messages embedded directly in Bitcoin transactions, an unconventional but technically elegant negotiation channel. They identified themselves as white hats and stated they would return the majority of the funds once the vulnerability was confirmed fixed and every node had installed the patch. Mow confirmed that the return followed Blockstream’s verification that the patched nodes were in place.

The 598 BTC That Changes the Narrative

The unresolved portion of the incident is where the story becomes genuinely contested. Ledger’s chief technology officer, Charles Guillemet, publicly questioned the white-hat framing after the partial return. His argument was direct: if the approximately 600 BTC still held by the actors represented a reward negotiated through encrypted onchain communications, then the arrangement looked, in his words, “more like extortion than white-hat hacking.”

It is a fair challenge. Legitimate white-hat disclosures typically involve responsible reporting to a vendor, a coordinated patch, and either a formal bug bounty paid by the organisation or a voluntary reward offered after the fact. What happened here followed a different sequence. The actors took the funds first, retained a portion, and returned the rest only after the fix was deployed. Whether that retained 598 BTC represents an agreed bounty, an ongoing negotiation, or simply funds the actors chose to keep has not been publicly clarified by either Blockstream or Liquid. Cointelegraph reported that it reached out to both companies for comment and received no response before publication.

Mow’s public statements did not describe the outstanding Bitcoin as a bounty or disclose any repayment terms. He focused instead on the operational picture, telling users not to send Bitcoin to Liquid peg-in addresses until the network’s restart is formally confirmed, and noting that no other user action was required in the meantime. Blockstream and federation members are also working through a chain split that occurred during the incident before they can safely bring the network back online.

Why This Matters Beyond Liquid’s Own Ecosystem

For investors and businesses in Malaysia and Singapore who use Liquid as a settlement or custody layer, the immediate concern is operational. The network remains paused, and any Bitcoin sent to peg-in addresses during this period would be at risk. The restart timeline has not been publicly confirmed.

The broader significance, though, is structural. Liquid is not a small or obscure project. It is Blockstream’s flagship Bitcoin sidechain, used by exchanges and institutions precisely because its federated model was supposed to offer stronger security guarantees than fully trustless alternatives. The fact that a bug in the underlying Elements software could expose nearly the entire reserve to a single withdrawal event will prompt serious reassessment of federated sidechain risk models across the industry.

The ethical ambiguity around the actors’ identity also sets an uncomfortable precedent. If retaining a portion of drained funds becomes an accepted informal bounty mechanism, it creates a template that is difficult to distinguish from coercion. Regulators in jurisdictions with clear digital asset frameworks, including the Monetary Authority of Singapore, will be watching how Blockstream resolves the outstanding 598 BTC and whether any formal disclosure follows. The difference between a white hat and an extortionist, in this case, may ultimately come down to what Blockstream chooses to say publicly once the network is back online.

Read More: A $7 Million Custody Gap Has Ended Tether-Backed Orionx, and the Questions Are Only Beginning

Aryad Satriawan is an Investment Storyteller with a professional career in the crypto (web3) and stock market industry. Aryad has been actively trading and writing analysis/research on crypto, stock and forex markets since 2016, currently an educator at one of the largest stock broker in Indonesia.
519 articles
More from Aryad Satriawan →
We follow strict editorial standards to ensure accuracy and transparency.