Nearly 4,000 BTC Moved After a Liquid Network Incident: How Can KYT Track Funds After an Abnormal Mint?

Liquid NetworkBTCKYTAbnormal MintingFund TrackingCross-Chain RiskOn-chain MonitoringCrypto SecurityAsset RecoveryAML

What Happened to the Nearly 4,000 BTC After the Liquid Network Incident?

On September 9, 2026, Liquid Network experienced an incident involving anomalous LBTC minting and approximately 4,000 BTC in related fund movements. Trustformer reported that around 3,400 BTC had been returned, while approximately 598.5 BTC remained unresolved. From a blockchain risk perspective, these figures should not simply be interpreted as a final loss amount and a completed recovery amount. Abnormal issuance, BTC transfers, peg-out requests, Federation payments and ordinary wallet activity may appear within the same transaction history. A reliable investigation therefore needs to reconstruct the complete timeline surrounding the event, establish how the abnormal assets were created, identify the wallets that received them and determine whether subsequent funds moved into exchanges, custodians, bridge infrastructure or other intermediary addresses.

The primary value of KYT in this type of incident is turning a technical security event into a traceable financial event. A traditional security investigation may focus on the underlying vulnerability, abnormal minting mechanism or network recovery, while a compliance and fund-tracing investigation needs to answer additional questions: Where did the funds go? Which addresses still control relevant assets? Which transfers have been confirmed? Which balances remain unresolved? When multiple asset representations such as BTC and LBTC are involved, balance changes alone are not sufficient to establish that assets have actually been recovered. Investigators should validate individual transactions through transaction hashes, timestamps, source addresses and receiving addresses.

The reported return of approximately 3,400 BTC should also be recorded separately. A transfer back to a designated wallet can establish that an on-chain movement occurred, but “funds were returned” and “the case has been resolved” are not necessarily the same conclusion. If the control relationship, ownership or final disposition of the receiving wallet has not been independently established, the KYT case should remain under monitoring. This prevents the investigation from being prematurely closed and losing visibility if the returned assets move again.

How Can KYT Trace BTC After an Abnormal Mint?

For abnormal-minting incidents, the first objective should not simply be to identify the largest wallets. Instead, investigators should establish the relationship between asset creation, subsequent transfers and eventual disposition. The process can begin with the transaction associated with the abnormal event, recording the initial address, timestamp, asset quantity and transaction hash. Investigators can then follow downstream movements to determine whether the funds were split, consolidated or transferred into newly created wallets. When funds pass through multiple addresses within a short period, analysts should determine whether the sequence represents normal operational activity, custody arrangements or a potentially complex movement pattern. The existence of transfers between several wallets alone does not prove that those wallets are controlled by the same entity.

Cross-chain environments create another layer of complexity. BTC, LBTC and other assets representing related economic value may rely on different mechanisms for issuance, redemption or cross-chain movement. Looking at the balance on only one network may therefore provide an incomplete picture of the overall asset position. A more complete investigation can connect source-chain transactions, activity on Liquid Network, peg-out behavior and subsequent BTC receiving addresses while preserving timestamps and transaction evidence for every stage.

Monitoring should also continue after funds reach a centralized exchange. An exchange deposit address may represent only the first stage of an asset’s movement into the platform. The exchange may subsequently consolidate the funds, process trades, make withdrawals or transfer the assets to another operational wallet. If BTC connected to the incident reaches an exchange, KYT should therefore continue monitoring subsequent movements instead of treating the deposit as the final disposition. Similarly, if funds move into a wallet that becomes inactive, the absence of further transactions does not prove that the assets have disappeared. It only means that no new on-chain movement has been observed and that the address should remain under observation.

The approximately 3,400 BTC reported as returned can also remain associated with the original case under a separate “returned” status rather than simply being removed from the original risk amount. This preserves the historical scale of the incident while allowing investigators to monitor how the returned assets are subsequently used. If those assets move again, the new transactions can be linked back to the original case and incorporated into the asset lifecycle record.

Why Should the 598.5 BTC of Unresolved Assets Remain Under Continuous KYT Monitoring?

The approximately 598.5 BTC that remained unresolved represents one of the most important areas for continued monitoring. Unresolved does not necessarily mean confirmed stolen, nor does it mean that the assets have permanently disappeared. It more accurately indicates that, within the available evidence, the final status of the assets has not yet been sufficiently established. Enterprise risk databases should therefore distinguish between confirmed transfers, returned assets, restricted assets and unresolved exposure, while retaining the relevant transaction evidence and update timestamps for each state.

Continuous monitoring should focus on more than whether the balance changes. Investigators should also watch for new transaction paths. Unresolved assets may remain dormant for an extended period before being split across multiple wallets, deposited to an exchange or moved through another blockchain service. A one-time screening process can easily miss these later developments. Continuous KYT rules can create alerts for new transfers, new counterparties, large movements and cross-chain activity involving known addresses. When a new transaction occurs, it can then be compared against the original incident timeline and evidence.

Enterprises should also keep three separate questions apart during incident analysis: the technical failure, the movement of funds and the identity or control of the parties involved. An abnormal minting mechanism does not automatically mean every related wallet belongs to an attacker. A wallet receiving abnormal assets does not independently establish that its controller knew where those assets came from. Likewise, the return of some funds does not automatically mean that the entire incident has been resolved. KYT provides verifiable evidence about financial relationships and transaction paths; it should not substitute unsupported identity conclusions for investigative evidence.

A complete case record should therefore preserve the incident timestamp, relevant asset quantities, source addresses, destination addresses, transaction hashes, asset-status changes, return transactions and subsequent monitoring results. New blockchain activity should be recorded as an update rather than overwriting earlier evidence. This versioned approach is particularly important in cross-chain incidents because transactions on different networks can occur at different times, while the same asset may have different technical and operational statuses at different stages.

By combining abnormal-transaction detection, wallet risk screening, fund tracing and continuous monitoring, KYT can help organizations maintain visibility over an asset network long after the initial incident. For events involving cross-chain assets and abnormal minting, this approach not only documents confirmed fund movements but also keeps unresolved exposure under observation and allows compliance teams to update the case when new evidence becomes available.

About Trustformer

Trustformer is a leading blockchain security and compliance technology company specializing in providing professional risk management and compliance solutions for the global cryptocurrency ecosystem. We have developed the cutting-edge Trustformer KYT (Know Your Transaction) platform, which integrates artificial intelligence, blockchain analytics, and regulatory technology to deliver comprehensive, accurate real-time transaction monitoring, risk assessment, and suspicious activity reporting services.

With deep industry expertise and technological innovation, Trustformer is dedicated to helping Virtual Asset Service Providers (VASPs), crypto financial institutions, and investors build a safer and more transparent crypto financial environment. We believe that driving compliance and trust through technology can contribute to the thriving growth of the global digital economy.