According to Unchained's report, approximately 4 000 BTC ended up at the attacker's address, notwithstanding Liquid's rule limiting withdrawals to addresses linked to registered authorization keys. Liquid's documentation describes this mechanism as protection against the redirection of user funds to malicious actors.

Alex Thorn, Head of Research at Galaxy, stated that this restriction did not apply to the individuals who withdrew the bitcoins. Consequently, the described incident raises questions about which specific part of the operation was covered by the authorized address rule.

The practical significance of this story depends on the details of the attack: from the available package, it is unclear which credentials or withdrawal stages were compromised and why the control failed. The next significant signal will be an explanation from Liquid and confirmation of the fund movement route.