Highlights
- Roughly 3,998.5 BTC, worth about $320 million, left Liquid Network’s federation reserve in a single September 6 transaction.
- The funds moved through SideSwap’s Peg-out Authorization Key even though Liquid says that key and all others remain uncompromised.
- An on-chain message reading “we are whitehats. contact us on chain” accompanied the transfer, but Ledger CTO Charles Guillemet says genuine white hats don’t behave this way.
- Exchanges paused LBTC deposits and withdrawals, and Liquid says the sidechain is effectively halted until the mechanism is understood.
- The withdrawal ranks among the three largest bridge-related incidents in crypto history, comparable in size to the 2022 Wormhole hack.
A $320 Million Withdrawal With No Clear Explanation
On September 6, 2026, roughly 3,998.5 BTC — worth close to $320 million — drained out of Liquid Network’s federation reserve wallet in a single transaction, leaving just 207.275 BTC behind from a prior balance near 4,200 BTC. The funds moved through SideSwap’s Peg-out Authorization Key (PAK), one of the credentials Liquid’s federation uses to release mainchain bitcoin once LBTC is burned on the sidechain. Liquid confirmed the withdrawal but said the SideSwap key itself, along with every other federation key, had not been compromised — an assertion that leaves the actual mechanism unexplained. An on-chain message attached to a follow-up transaction read “we are whitehats. contact us on chain,” but the claim has done little to settle who moved the money or why.
How Liquid’s Peg-Out Mechanism Is Supposed to Work
Liquid’s peg-out process is designed around three sequential checks: LBTC must be destroyed on the sidechain, an 11-of-15 federation multisignature must approve the release, and the withdrawing address must already sit on the PAK whitelist. All three exist to make a rogue withdrawal effectively impossible without several federation members colluding or a whitelisted key being misused — which is exactly why Liquid’s insistence that no keys were compromised has drawn skepticism rather than reassurance. The Block reported that Blockstream, which operates Liquid, said it was working to contact the responsible party through a signed on-chain message and that the sidechain would remain “effectively paused” until the issue is resolved. Other assets settled on Liquid — including Tether’s USDT, the Brazilian stablecoin DePix, and various tokenized real-world assets — were not affected, since those balances sit outside the BTC federation reserve. At roughly $320 million, the withdrawal lands in the same range as the February 2022 Wormhole exploit ($321 million) and just behind the record-setting Ronin Bridge hack ($625 million), making it one of the three largest bridge-related fund movements recorded in crypto history — a notable outcome for a federated Bitcoin sidechain that has operated since 2018 without a comparable incident.
Related: Coldcard Firmware Bug Enabled $116M Bitcoin Wallet Heist
Why a Federated Bridge’s Trust Model Matters
The incident reopens a debate that Bitcoin sidechain and bridge models have never fully settled: LBTC holders never held a direct claim on bitcoin itself, only an obligation from Liquid’s fifteen-member federation of exchanges and infrastructure firms. When that consortium’s control mechanism produces a $320 million outflow it cannot immediately explain, the exposure looks less like a technical bug and more like a trust failure in the custodial layer wrapped around an otherwise immutable asset. Several exchanges reacted within hours by suspending LBTC deposits and withdrawals, a standard containment step that nonetheless shows how quickly liquidity for a wrapped asset can freeze once its backing is in question. For Bitcoin DeFi more broadly — a category that has been growing as Lightning, Liquid, and newer sidechains compete to bring programmability to BTC without touching the base layer — the episode is a reminder that convenience features like PAK whitelisting add attack surface that plain custody does not have. It also complicates the “whitehat” framing some crypto incidents lean on to soften the blow of a hack: Guillemet’s objection, that a genuine white hat does not silently move an entire reserve and then demand contact rather than returning funds first, echoes a pattern seen in other 2026 incidents where issuers similarly said no keys were compromised despite large unexplained fund movements, including at BounceBit and MANTRA.
What Comes Next
Blockstream has not published a technical post-mortem explaining how a peg-out could clear the PAK whitelist and the 11-of-15 multisig without a confirmed key compromise, and until it does, LBTC will likely stay constrained on the exchanges that paused it. The next concrete marker to watch is whether the party behind the “whitehat” message actually opens a communication channel on-chain, as Blockstream has requested, or whether the 3,998.5 BTC simply moves again — a transfer that would be visible in real time on Liquid’s block explorer and would settle the whitehat question one way or the other. A formal incident report, along with any decision on reimbursing affected parties, would mark the point at which exchanges can consider restoring LBTC deposits and withdrawals.
FAQ
What is Liquid Network’s Peg-out Authorization Key (PAK)?
The PAK is a whitelisting mechanism Liquid uses to control which addresses can receive bitcoin when LBTC is redeemed; on September 6, roughly 3,998.5 BTC moved through SideSwap’s PAK even though Liquid says the key itself was not compromised.
How much BTC was withdrawn from Liquid Network?
About 3,998.5 BTC, worth close to $320 million, left the federation’s reserve, dropping its remaining balance to 207.275 BTC from a prior balance near 4,200 BTC.
Is LBTC still safe to hold?
Several exchanges have paused LBTC deposits and withdrawals and Liquid has effectively halted the sidechain, so LBTC liquidity is constrained until Blockstream explains how the withdrawal happened.
Does this compare to other major bridge hacks?
At roughly $320 million, the withdrawal is close in size to the 2022 Wormhole hack ($321 million) and ranks among the three largest bridge-related incidents recorded in crypto history.
