Liquid Network Breach: Nearly 4,000 BTC Moved in Unauthorized Peg-Out as 'White Hat' Actors Claim Responsibility
Key Takeaways
- •Nearly 3,996 BTC, valued at approximately $320 million, was withdrawn from the Liquid Federation's Bitcoin wallet, and the network confirmed the breach on September 6.
- •The actors behind the transfer embedded an OP_RETURN message claiming to be white hats, but the label remains unverified until the funds are returned.
- •Liquid stated the withdrawal used SideSwap's peg-out authorization key even though the key itself was not compromised, leaving open where the control path failed.
- •The Layered federation design requires more than a two-thirds watchman threshold to spend federation-held Bitcoin, which is why an unauthorized peg-out of this size raises questions.
- •Infrastructure and operations vulnerabilities accounted for roughly 76% of monetary losses from crypto hacks in the first half of 2026, according to TRM Labs.

The Liquid Network confirmed a security breach on Sunday, September 6, after nearly 4,000 BTC — valued at approximately $320 million — was taken from the Bitcoin wallet of the Liquid Federation.
A peg-out the federation says it did not authorize
The party behind the transfer left an on-chain message. An OP_RETURN reading "we are whitehats. contact us on chain" appears in Bitcoin transaction “c103de…e69a19”.
In its post on X, Liquid said "purported white-hat hackers" had withdrawn the coins and that Blockstream was attempting to contact them on-chain with a signed message. Blockstream is the company that developed Liquid, a Bitcoin sidechain whose federated members — including exchanges and financial institutions — collectively process peg-ins and peg-outs.
ErgoBTC identified the large Bitcoin payout as transaction “8db751…a7b140.” It sent roughly 3,996 BTC to “bc1qgs…c6wt7p” and was confirmed in Bitcoin block 965,783 at 14:28:56 UTC on September 6.
On the Liquid side, Blockstream’s explorer shows the associated transaction, “ce4cae…e988f2,” involving a 3,996.01834922-LBTC peg-out.
Liquid says the withdrawal employed SideSwap’s peg-out authorization key (PAK), even though the SideSwap PAK itself was not breached. This distinction is crucial to understanding what happened.
What a PAK is supposed to prevent
Liquid uses a two-way peg between Bitcoin and its sidechain. Users lock BTC to mint Liquid Bitcoin (LBTC), then burn LBTC to release the underlying Bitcoin, according to Liquid’s developer documentation.
Peg-outs are gated by a Peg-out Authorization Key. The documentation states the PAK is designed so that “even if a set of functionaries were compromised, they couldn’t redirect user funds to attacker-controlled addresses.”
If the valid SideSwap PAK was used and the key was not compromised, the main question becomes where exactly in the control path the error occurred. The present evidence gives no indication that anything went wrong with Bitcoin itself.
As shown in Liquid’s technical documentation, the Strong Federation concept requires a minimum of two-thirds of block signers to approve blocks, whereas spending Bitcoins held by the Federation requires a greater-than-two-thirds watchman threshold. That layered design is intended to make unauthorized peg-outs difficult, which is precisely why a peg-out of this size that the federation says it did not authorize raises questions about which safeguard failed.
“White hat” is a claim, not a verdict
Classifying the actors as white hats based solely on their assertion would be premature. It was previously reported that TAC, a protocol for decentralized cross-chain transactions, handled a hack of around $2.8 million as a white-hat operation — but only after the hacker accepted a 10% cut and returned the remainder.
Until Liquid’s BTC is sent back, “white hat” remains a claim rather than a fact.
The market impact is also more complicated than headline figures suggest. Moving BTC on-chain does not necessarily mean selling pressure is occurring. That depends on whether the funds reach exchanges, and there is currently no cited evidence that they have.
The bigger test: confidence in federated bridges
According to TRM Labs’ report, infrastructure- and operations-related vulnerabilities accounted for roughly 15% of incidents during the first half of 2026 but an overwhelming 76% of total losses in monetary terms. This indicates that custody- and bridge-related disruptions can outweigh the impact of months of smaller exploits.
A July 2026 paper by Heritage Falodun and Samson Ojo notes that only approximately 0.8% of circulating BTC is employed in DeFi, compared with up to 30% of Ethereum. The authors suggest that trust and institutional infrastructure are the major reasons capital does not flow into Bitcoin.
Additionally, Blockstream’s May roadmap emphasizes the need to reduce reliance on trust-based schemes across the industry. In particular, the company is developing a BitVM 1-of-n bridge model. If federated designs continue to produce incidents like this one, the significance of that work increases substantially.
It remains to be seen how the parties involved in the withdrawal respond to Blockstream, and whether the nearly 4,000 BTC will be returned, remain parked, or moved to exchanges.
For now, the situation represents not only a test of Liquid’s security, but a test of the level of trust Bitcoin users place in federated bridges.