A single peg-out transaction moved roughly 4,200 BTC, worth about $320 million, off the Liquid Network on September 6. An embedded on-chain message claims white hat involvement, but Blockstream has not confirmed whether the move was an authorized rescue or an exploit.
Someone moved roughly 4,200 BTC off the Liquid Network in a single peg-out transaction, leaving an OP_RETURN message claiming to be from "white hats" and inviting contact. Neither Liquid Network nor its parent company Blockstream has said a word.
What actually happened
On September 6, the peg-out transaction moved approximately 4,200 BTC back to the Bitcoin mainchain, worth around $320 million at current Bitcoin prices near $80,000.
Around 4,000 BTC transferred simultaneously in what appears to be a coordinated operation.
The transaction carried an OP_RETURN message identifying the parties as "white hats" and inviting further communication on-chain. But it remains genuinely unclear whether this was an exploit of the network's security model, an authorized operation by insiders, or something else. Liquid Network typically processes peg-outs in batches taking 11 to 35 minutes, and this volume moved through without apparent interruption.
How Liquid Network is supposed to work
Liquid Network is a Bitcoin sidechain built by Blockstream, operating under a Strong Federation model in which a consortium of vetted entities collectively manages the Bitcoin reserves backing the sidechain's L-BTC tokens. Its security architecture relies on an 11-of-15 multisig arrangement, meaning at least eleven of fifteen designated functionaries must sign off on any movement of the underlying Bitcoin.
The system also requires Peg-out Authorization Keys, or PAKs, for any withdrawal back to the mainchain, designed to reduce the risk posed by compromised functionaries. The 4,200 BTC movement means either this layered security model was bypassed, or the transaction was authorized through legitimate channels.
The white hat question
Self-identifying as a white hat hacker via on-chain message is not unprecedented. In past DeFi incidents, attackers have used similar tactics to negotiate returning funds, often keeping a percentage as a "bounty" for identifying the vulnerability — the Euler Finance exploit in 2023 and the Poly Network hack in 2021 both followed this playbook. Blockstream has not released any statement confirming unauthorized access, denying an exploit, or acknowledging the transaction at all.
What this means for sidechain security
Federated sidechain models like Liquid sit between the trustless Bitcoin base layer and fully centralized systems, trading speed and functionality for trust in a known set of validators. If eleven of fifteen functionaries can be compromised, or the PAK system circumvented, the security assumptions underpinning Liquid need serious re-examination — and $320 million just walked out the door.
For Bitcoin holders who use Liquid for faster transactions, confidential transfers, or access to Liquid-native assets, the practical concern is whether the remaining reserves are safe. Without transparency from Blockstream, that question hangs in the air.
Source: Crypto Briefing
Trading involves risk.