Liquid wasn’t robbed of keys.

It was robbed of assumptions.

The federation multisig worked.

SideSwap’s PAK worked.

What failed was a cache that treated “this proof was already checked” as “this proof is valid here.” That one skipped check minted unbacked L-BTC, then the honest peg-out paid real Bitcoin
.

That’s why the white-hat vs hostage debate is the wrong frame.

The real story is consensus software that looked fine until someone reused a cached yes.

3,400 $BTC came back and ~598.5 $BTC did not.

The network is still paused.

The lesson isn’t hat color, it’s this: if your security model assumes every node re-verifies the expensive thing, a cache key that omits context is a money printer.