On September 6, approximately 4,200 BTC were transferred off the Liquid Network back to the Bitcoin mainchain through a single peg-out transaction. The movement, worth roughly $320 million at Bitcoin prices near $80,000, included an embedded on-chain message in which the operator identified themselves as a white hat and invited further communication.
Blockstream, the parent company of Liquid Network, has not released any statement about the transaction, leaving the nature of the event unclear. It remains unknown whether the movement represents an authorized operation, an exploit of the network's security model, or something else entirely.
How Liquid Network Operates
Liquid Network is a Bitcoin sidechain managed by Blockstream using a Strong Federation model. The system relies on an 11-of-15 multisig arrangement, meaning at least 11 of 15 designated functionaries must authorize any movement of underlying Bitcoin reserves. Additionally, the network requires Peg-out Authorization Keys (PAKs) for any withdrawal back to the Bitcoin mainchain.
Security Implications
The 4,200 BTC transfer either bypassed the layered security model or was authorized through legitimate channels. Liquid Network typically processes peg-outs in batches taking 11 to 35 minutes. The fact that this volume moved through without apparent interruption raises questions about how authorization was obtained.
If the transaction represents a compromise of the federation model or the PAK system, the security assumptions underpinning Liquid require re-examination. The federation model depends on the security of its validators. The event has prompted questions from Bitcoin holders who use Liquid for faster transactions and access to Liquid-native assets regarding the safety of remaining reserves.
Historical Parallels
Self-identifying as a white hat hacker through on-chain messages is not unprecedented in the cryptocurrency industry. The Euler Finance exploit in 2023 and the Poly Network incident in 2021 followed similar patterns, with operators using on-chain communication to negotiate fund returns, sometimes retaining a percentage as a bounty for identifying vulnerabilities.


