The address holding 598.5 bitcoin taken from Blockstream’s Liquid sidechain has been among the most closely watched strings of characters in Bitcoin this month. Since 03:05:37 Coordinated Universal Time on Saturday 12 September it has also been the destination of a 330-satoshi output in every single mint transaction of a brand-new token sale. Bitcoin Mastery pulled the full confirmed transaction list of bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte at 06:10 UTC on Sunday 13 September and recomputed it line by line. The address now carries 1,426 confirmed transactions. At 06:10 UTC on Friday 11 September it carried 296. Of the 1,130 transactions that arrived in those two days, 1,110 — 77.8% of every transaction the address has ever received — belong to a single token protocol, and every one of them pays the whitehats exactly 330 satoshis, or about a quarter of a US cent.

The token is called $leaf. Its transactions identify themselves in an OP_RETURN output with the JSON string {"p":"ico-20","op":"mint","tick":"LEAF"}. The project’s website describes it as “the first ICO built directly on Bitcoin L1” and says it “uses the BRC-20 standard to deploy assets under the ‘ICO-20’ protocol”. In the twenty-seven hours from its deploy transaction to the desk’s snapshot, the 1,109 mints have paid 1.37870546 bitcoin — roughly $106,532 at Saturday’s close of $77,269.22 — into a vanity address ending in the letters sypleaf, which has received 1.3790679 BTC in total including its own seed funding. Over the same window the people minting it have burned 1,311,938 satoshis in miner fees and sent the Liquid whitehats 366,300 satoshis. That is a fee-to-delivery ratio of 3.58 to one: for every satoshi that reached the address everyone is watching, three and a half went to miners instead.

Two things this article does not say, and the reader should hold on to both. It does not say the whitehats control, endorse, requested or benefit from the token sale — 330 satoshis is dust, and there is no statement from them, from Blockstream, from the Liquid federation or from the token’s operators about the pairing. And it does not say a published protocol specification requires the payment. What the desk verified is the chain: 1,109 mints out of 1,109, plus the deploy transaction that started them, all carry the same 330-satoshi output to the same address. That is consistent with the figure being hard-coded into whatever software is building these transactions. It is not proof of intent, and we are not going to dress it up as one.

The deploy transaction paid the whitehats first

The sequence is unusually legible because it is only three transactions deep. The deploy transactionf56a3044…, confirmed in block 966,606 at 03:05:37 UTC on Saturday 12 September — spent a single 6,244-satoshi input from the treasury address bc1pq43ahsfytunv…sypleaf. It paid 403 satoshis in fees across 241 virtual bytes and produced three outputs: a zero-value OP_RETURN carrying {"p":"ico-20","op":"deploy","tick":"LEAF","max":"1000000000","lim":"21347","btc":"7000","ordi":"1"}, then 330 satoshis to the Liquid whitehat address, then 5,511 satoshis of change to a third address.

That third address is worth reading character by character. It is bc1ql4mad6nxx43t79u7wadwqhtu0hx54ssg6mjlte. The whitehat address is bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte. Both are 42 characters long. They share a seven-character prefix, bc1ql4m, and a four-character suffix, jlte. The prefix bc1q is common to every native-segwit v0 address on Bitcoin, so four of those seven characters are free; l4m and jlte are not. Addresses do not collide on both ends by accident, and vanity-address generators are cheap. The operator is running an address built to resemble the one the whitehats use — which is exactly the pattern the desk warned about in Field Guide #45, and which today’s companion field guide makes its sixth and final check: the first and last four characters of an address are not enough to identify it.

Twenty-six minutes later, at 03:31:40 UTC, that look-alike address funded the first mint, dce19008… in block 966,607. Its output layout is close to the template later mints follow: a payment to the treasury, the OP_RETURN mint string, a 330-satoshi output back to the sender, a 330-satoshi output to the look-alike address, and a 330-satoshi output to the Liquid whitehats. It is one of only four mints with that five-output shape; the other 1,105 have six, adding a change output back to the funder. The last mint in the desk’s snapshot, 16855534… in block 966,779 at 05:26:00 UTC on Sunday 13 September, has that six-output layout and four inputs instead of one — and still carries the same 330 satoshis to the same address.

1,109 mints, 78 blocks, 872 funding addresses

Recomputed from the confirmed list at 06:10 UTC Sunday 13 September, the ico-20 footprint on the whitehat address is:

    • 1,110 ico-20 transactions — one deploy and 1,109 mints. All 1,109 mints carry a 330-satoshi output to the whitehat address. The count is 1,109 of 1,109, not most of them.
    • 322 mints on Saturday 12 September — plus the deploy that preceded them — and 787 on Sunday 13 September through 05:26 UTC. 322 plus 787 is 1,109; the Sunday figure is a partial day.
    • 78 distinct blocks. The heaviest was block 966,743 with 89 of them; then 966,740 with 64 and 966,742 with 61.
    • 872 distinct funding addresses. The busiest contributed 258 inputs, the second 222, then two at 117 and one at 114 — so the flow is broad but not evenly spread.
    • 755,139 virtual bytes across those 78 blocks, an average of roughly 9,681 vB per block, or about 0.97% of a one-million-vB block. This is not a blockspace crisis; fees on Sunday morning were 3 satoshis per vB for the fastest tier and 1 for everything slower.
    • 1,311,938 satoshis of miner fees (0.01311938 BTC, about $1,014 at Saturday’s close), of which 1,311,535 came from the mints and 403 from the deploy.
    • 366,300 satoshis delivered to the whitehat address (0.003663 BTC, about $283).
    • The full decomposition of the address: 1,426 confirmed transactions = 1,110 ico-20, plus 307 carrying some other OP_RETURN payload, plus 9 carrying none at all.

The commitment sizes say something about who is actually buying. Measured as satoshis paid into the treasury per mint, the median commitment was 30,000 satoshis — about $23. Thirty-two mints committed 0.01 BTC or more. Eighteen committed nothing at all beyond the 330-satoshi dust, which means eighteen people paid a miner fee to broadcast a mint that bought them, on the project’s own stated pricing curve, essentially nothing. The largest single commitment among the 1,109 mints confirmed by 05:26 UTC was 6,400,000 satoshis — 0.064 BTC, about $4,945 — in transaction ae71a6e6…, block 966,750, 01:30 UTC on Sunday. Second was 4,997,195 satoshis in block 966,749 seven minutes earlier; third was a round 3,000,000 satoshis in block 966,722 at 21:41 UTC on Saturday. Nobody in the snapshot has committed five figures of dollars — and with 9,491 blocks of the stated mint window still to run, that is a statement about the first day, not about the sale.

The rush has already stalled

The hourly distribution is the part a reader should not miss, because it is the part that will be stale fastest. Counting mints by the UTC hour of the block that confirmed them:

    • 18:00–19:00 UTC Saturday: 11 mints.
    • 19:00–20:00: 16. 20:00–21:00: 20. 21:00–22:00: 80. 22:00–23:00: 43. 23:00–00:00: 131.
    • 00:00–01:00 UTC Sunday: 381 mints — the peak hour.
    • 01:00–02:00: 233. 02:00–03:00: 131.
    • 03:00–04:00: 39. 04:00–05:00: 2. 05:00–06:00: 1.

From 381 in an hour to three in two hours is a collapse of roughly 99%, and it happened in the three hours before the desk took its snapshot. The desk is not going to guess the cause on the record. On the project’s own stated pricing rule — a “Golden Curve” whose marginal price follows P = m × S^1.618, so each unit of supply sold costs more than the last — a fast early rush would make later mints progressively more expensive, and that is one explanation among several. Mempool congestion is another; ordinary loss of interest at four in the morning UTC on a Sunday is a third. Anyone reading this article more than a few hours after publication should re-pull the address before treating the flood as ongoing.

What the project says about itself

The $leaf site makes a specific technical claim and a specific economic one. The technical claim is about covenants: it argues that Bitcoin script, ordinarily unable to constrain where coins go next, can be made to do so through transaction introspection, and it presents $LEAF as “the first live demonstration of this primitive on L1”. Covenants are a genuine and genuinely contested area of Bitcoin protocol research — proposals including OP_CAT, OP_CTV, OP_TEMPLATEHASH and CHECKSIGFROMSTACK have been debated for years and none is active on mainnet today. The desk has not verified that any covenant construction is doing work in the transactions it examined, and the transactions it examined do not require one: they are ordinary spends with an OP_RETURN and some dust outputs, which any wallet can build. Readers should treat “first live demonstration” as the project’s claim about itself, not as a finding.

The economic claims are these: a total supply of 1,000,000,000 tokens; minting open for 9,666 blocks from the deploy block, after which the remainder is said to be burned; the Golden Curve pricing rule above; and an exchange rate assigning 7,000 points to one bitcoin and one point to one ORDI, a 1-to-7,000 equivalence. Taking the stated window at face value and applying it to the verified deploy height, minting runs from block 966,606 to block 976,272. The chain tip at 06:10 UTC Sunday was 966,781, so 175 blocks have elapsed and 9,491 remain — about sixty-six days at ten-minute blocks. The site is served from a vercel.app subdomain while its canonical link and Open Graph URL both point at a different domain, hashrate.market. The desk notes the mismatch and draws no conclusion from it.

Meanwhile, on Liquid, nothing has happened

This matters mainly because of what it is drowning out. The desk re-pulled the Liquid chain and both relevant Bitcoin addresses at 06:10 UTC Sunday, and the negotiation the whitehat address exists to carry has produced nothing since Friday:

    • The whitehats have still not spent anything. Balance 598.50425429 BTC — about $46.25 million at Saturday’s close — across 1,426 confirmed transactions, with 46 more in the mempool worth 0.00022449 BTC between them. The balance is up 377,314 satoshis on Friday, all of it dust. There has been no outgoing spend since 16:09:25 UTC on Monday 7 September, when the coins were returned.
    • The peg address has not moved either.3,601.47207156 BTC across 597 transactions, up 3,384 satoshis on Friday — about $278.27 million, and 85.65% of the 4,205 bitcoin the federation is understood to have backed.
    • Liquid has not been rolled back a second time. Following Friday’s instruction to re-check stored heights rather than just the tip, the desk re-pulled four: block 4,050,335 is still hash aad24e4f… stamped 13:52:10 UTC on 6 September with 5 transactions; 4,050,336 is still d4eeaa11… at 21:05:10 UTC on 9 September with 4; 4,051,232 is still stamped 12:19:10 UTC on 10 September; 4,052,304 is still stamped 06:11:10 UTC on 11 September. All four match Friday’s record exactly. The tip was 4,055,183 at 06:10:10 UTC, and recent blocks carry one to three transactions.
    • Peg-outs are still suspended on the federation’s last published status, and no replayed-versus-discarded transaction accounting has been published.

So on the eighth day of an incident — the exploit block is stamped 6 September — in which roughly $278 million of somebody else’s reserves are sitting in a federation address and $46 million is sitting in a stranger’s, the newest development on the address at the centre of it is that a token sale has adopted it as a beacon. Readers who have been following this from the pause on 7 September through the bounty demand written into an OP_RETURN to Friday’s discovery that the restart was a rollback now have a practical problem: an address that produced a handful of meaningful messages a day is producing several hundred transactions a day, and 77.8% of its lifetime transaction count is now one token protocol. The desk has written a companion field guide on separating the three kinds of thing that arrive at an address like this — a payment, a message and a protocol marker — and it publishes alongside this article.

One further caution, stated once and not elaborated. Among the 307 non-ico-20 OP_RETURN transactions on the address are advertisements for unrelated tokens and a number of abusive messages about named real people. Bitcoin Mastery has read them in order to count them and will not quote, paraphrase or characterise their contents. Anyone opening the address in an explorer should expect to encounter them. That, too, is now part of the cost of using a public blockchain as a negotiating table.

What would change the reading

The desk sets a marker on this and will grade it. AE1: the cumulative count of ico-20 mint transactions carrying an output to bc1ql4mfu6au… reaches 2,000 by 00:00 UTC on Wednesday 16 September. The reading at 06:10 UTC on Sunday 13 September is 1,109. Given the hourly collapse described above, the desk’s expectation is that this fails, and saying so in advance is the point of writing it down.

Three other things would move this story. A statement from Blockstream, the Liquid federation or the whitehats acknowledging the flood would tell us whether anyone monitoring the address considers it a problem. A published ico-20 specification would settle whether the 330-satoshi output is mandated by the protocol or chosen by the client. And the first outgoing spend from the whitehat address — marker AA1, open until 00:00 UTC on Thursday 17 September — would immediately be the most important transaction on it, which is precisely why the noise is worth counting now rather than later.

Method: prices, funding, open interest, basis, mining and on-chain figures in this article are pulled directly by Bitcoin Mastery at the timestamp stated — Bitstamp BTC/USD daily candles for closes, Binance BTCUSDT spot and USDT-margined perpetual for intraday, open interest, funding and account ratios, Binance COIN-M quarterly contracts for basis, mempool.space for difficulty, hashrate, pool shares, fees, address balances and individual Bitcoin transactions, blockstream.info’s Liquid API for sidechain block heights, hashes, timestamps and transaction counts, alternative.me for the Fear & Greed series, CoinGecko for altcoin daily prices, Farside Investors’ table for ETF flows and US Treasury CMT par yields for rates. Transaction counts, fee totals, byte totals and OP_RETURN payloads are recomputed from the full confirmed transaction list of the address concerned, not read off a summary. Where a third-party figure is cited we name the source and its date; where two sources disagree we print both. Every streak or extreme figure is published with the first date of its series in the same sentence.

Disclaimer: This article is for informational purposes only and does not constitute investment advice. Cryptocurrencies are volatile and you can lose money. Nothing here is a recommendation to buy or sell any security, digital asset, token or exchange-traded fund, including MSTR, L-BTC, HYPE, ORDI or the LEAF token where discussed above. Token sales of the kind described in this article are unaudited, frequently anonymous and have no obligation to deliver anything in return for a payment; treat any coin sent to one as capable of going to zero. Do your own research and consult a licensed financial advisor before making investment decisions.