Ledger CTO Questions 'Whitehat' Claim After Liquid Network's 4,000 BTC Peg-Out
Key Takeaways
- •Ledger CTO Charles Guillemet challenged the "whitehat" claim made by the actors who moved roughly 3,996 BTC, worth about $318.4 million, out of the Liquid Network.
- •The withdrawal represented approximately 95% of Liquid's Bitcoin reserves, yet corresponding LBTC was burned, so remaining LBTC remains fully backed.
- •Liquid stated the peg-out passed through SideSwap's Peg-out Authorization Key (PAK), while the PAK itself and other authorization keys were not compromised.
- •Liquid notified exchanges, which paused or prepared to pause LBTC deposits and withdrawals, and temporarily disabled bridge nodes during the investigation.
- •Blockstream sent an on-chain message asking the party controlling the funds to contact its security team, but no confirmed agreement or return of assets has been reported.

Key Facts at a Glance
- Ledger CTO Charles Guillemet has challenged the "whitehat" claim made by the actors behind a 3,996 BTC peg-out from the Liquid Network, valued at approximately $318.4 million.
- Liquid says the peg-out was executed through SideSwap's Peg-out Authorization Key (PAK), while the key itself and other authorization keys were not compromised.
- The transfer represented roughly 95% of Liquid's Bitcoin reserves, intensifying scrutiny of the network's controls.
- Liquid paused bridge activity, while most of the withdrawn BTC remained concentrated and LBTC backing stayed fully matched.
The Liquid Network, a Bitcoin sidechain developed by Blockstream used for faster settlement and asset issuance, is investigating an unusual peg-out involving roughly 4,000 BTC after the actors behind the withdrawal described themselves as "whitehats." Ledger CTO Charles Guillemet has publicly challenged that description, arguing that legitimate security researchers typically disclose vulnerabilities before moving substantial collateral.
Ledger CTO: 4,000 BTC Pegged Out of Liquid Bridge, "Whitehat" Claim Raises Doubts
Ledger CTO Charles Guillemet said about 4,000 BTC were pegged out of the Liquid bridge, with an OP_RETURN message stating, "we are whitehats. contact us on chain." He argued that white hats do not… pic.twitter.com/o0CHl4gyM4
— Wu Blockchain (@WuBlockchain) September 6, 2026
The September 6 transaction moved about 3,996 BTC from federation-controlled reserves while Bitcoin traded near $79,675, valuing the transfer at approximately $318.4 million. A subsequent transaction carried an OP_RETURN message stating, "we are whitehats. contact us on chain."
Ledger CTO Challenges Whitehat Claim After Liquid's $318M Peg-Out
Guillemet argued that withdrawing hundreds of millions of dollars before opening communication differs sharply from conventional vulnerability disclosure practices. His comments shifted attention away from the transfer itself toward the conduct of the actors now controlling the funds.
The Ledger CTO compared the situation to major bridge and protocol exploits in which attackers later communicated with affected projects, citing the 2022 Ronin bridge attack and the 2023 Euler Finance exploit. Ronin lost more than $600 million after stolen validator keys allowed unauthorized withdrawals. Euler Finance eventually recovered assets following negotiations, after an exploit initially drained approximately $197 million. Cross-chain bridges and sidechains have repeatedly ranked among the most targeted categories in crypto security incidents, and the Liquid case touches directly on that broader track record.
However, those historical comparisons do not establish malicious intent in the Liquid Network incident. The roughly 4,000 BTC has not been reported as rapidly dispersed or laundered; instead, most of the funds have remained concentrated following the peg-out. The actors also explicitly requested contact through the Bitcoin blockchain.
Blockstream later responded with an on-chain message asking the party controlling the funds to contact its security team. No confirmed agreement or asset return has been reported so far. The central unresolved question is whether the actors' whitehat description matches their actions — a claim that has not been independently verified.
Liquid Probes How 3,996 BTC Cleared Its Peg-Out Security Controls
The Liquid Network later confirmed a security incident, stating that the withdrawal passed through SideSwap's Peg-out Authorization Key, known as PAK, while SideSwap's key itself was not compromised.
Liquid Network confirmed a security incident, saying the funds were withdrawn via SideSwap's Peg-out Authorization Key (PAK), while the key itself and other keys were not compromised. Exchanges have been notified and have paused or will pause LBTC deposits and withdrawals. Other…
— Wu Blockchain (@WuBlockchain) September 6, 2026
Other authorization keys were also reported as uncompromised. That finding has intensified scrutiny over how the transaction satisfied Liquid's normal withdrawal requirements.
Liquid uses a federated security model: fifteen functionaries operate the network, while an 11-of-15 quorum controls the Bitcoin peg. Under normal operation, LBTC must be destroyed before matching BTC can leave federation-controlled reserves, and PAK restrictions add another layer by limiting peg-outs to authorized Bitcoin addresses. Unlike trust-minimized Bitcoin transactions, this federated design concentrates authorization power among a defined set of operators, which is where the current investigation is focused.
On-chain analysis indicated that corresponding LBTC was burned during the withdrawal, meaning the remaining LBTC supply continues to retain matching Bitcoin backing. That distinction reduced immediate concerns about uncovered LBTC liabilities. Nevertheless, the transaction represented roughly 95% of Liquid's Bitcoin reserves.
Liquid responded by notifying exchanges, which paused or prepared to pause LBTC deposits and withdrawals. Bridge nodes were also temporarily disabled while federation members continued their investigation. Assets including USDT, DePix, and tokenized real-world assets were not affected, according to the network.
The investigation now centers on two open questions: how the authorization process permitted the peg-out, and whether the withdrawn BTC will be returned. How Liquid and Blockstream explain the gap between the intact authorization keys and the cleared withdrawal is likely to shape confidence in the network's federated model going forward.
Source: Blockonomi