Nearly 4,000 BTC Drained From Liquid Network Federation Wallet
Nearly 3,998.5 BTC left Blockstream's Liquid federation wallet on September 6, dropping the reserve from ~4,200 BTC to 207.275 BTC. An unidentified party left an onchain message claiming 'we are whitehats.' Blockstream has not responded.

An unidentified party pulled reported ~$319M in bitcoin from Blockstream's Liquid sidechain reserve on Sunday. Blockstream has not said a word.
Key takeaways
- ~3,998.5 BTC left Liquid's federation wallet on September 6, dropping the reserve from ~4,200 BTC to 207.275 BTC, per the Blockstream Liquid explorer.
- A follow-up transaction reportedly embedded a message claiming to be from "whitehats." The claim is unverified and Blockstream, the Liquid team, and Adam Back had not publicly addressed the incident as of ~3:00 p.m. EDT.
- The movement should not be possible under normal Liquid mechanics, which require LBTC to be burned on the sidechain, an 11-of-15 federation multisig, and PAK whitelist authorization before any BTC is released.
Onchain researcher @ErgoBTC flagged two linked transactions on September 6 showing a massive Liquid peg-out: roughly 3,998.5 BTC leaving a pool that had held approximately 4,200 BTC. The Blockstream Liquid explorer confirmed the post-event federation balance at 207.275 BTC. First reported by Bitcoin.com News.
The drained BTC, as of initial reporting, had not been mixed or obviously dispersed on the Bitcoin mainchain.
How This Was Supposed to Be Impossible
Liquid's peg-out mechanism exists precisely to prevent this kind of event. Under the protocol, LBTC must be destroyed on the sidechain before federation functionaries process a corresponding bitcoin withdrawal. That withdrawal then requires an 11-of-15 federation multisig and authorization through the Peg-out Authorization Key (PAK) system, which restricts payments to approved member wallets, per Blockstream's own documentation.
Three scenarios could explain what happened: a compromised PAK-whitelisted wallet, abuse of Liquid's authorization mechanisms, or a coordinated emergency extraction by federation members who discovered a critical vulnerability. None has been confirmed. A follow-up transaction reportedly embedded a message claiming "whitehats" responsibility, per Bitcoin.com News; that message text has not been independently confirmed in the raw transaction data, and the claim is, at best, an assertion by an unidentified party.
A genuine whitehat scenario has a tell: Blockstream would confirm it quickly, identify the responding member, and publish a return path for the funds. Sustained silence is not consistent with that outcome.
What LBTC Holders Actually Held
This is the part that matters for anyone who touched the Liquid ecosystem. Every satoshi pegged into Liquid became a liability of the federation the moment it crossed the bridge. LBTC holders had no direct claim on the underlying BTC, their exposure was to a consortium of companies, not to the Bitcoin protocol itself. The Blockstream Liquid explorer now shows 207.275 BTC backing whatever LBTC remains outstanding.
This is the custodial risk argument made concrete at reported ~$319M. Any yield, speed, or feature Liquid offers comes attached to a trust dependency that does not exist on the base layer or on Lightning, which is non-custodial by design. Builders, exchanges, and institutions that issued LBTC or held it as a reserve instrument now have a live event to price.
The falsifiable thesis: Liquid's 11-of-15 multisig and PAK whitelist, marketed as making custodial risk "manageable," failed to prevent reported ~$319M in bitcoin from leaving the peg in a single event. That framing is wrong only if Blockstream can publicly demonstrate that (a) this was a fully authorized, internally coordinated emergency extraction, and (b) all 3,998.5 BTC sits in provably federation-controlled keys with a transparent return path. That evidence has not appeared.
What to Watch
The next meaningful development is a statement or its continued absence. If Blockstream confirms an authorized emergency extraction with a named federation member and a public return timeline, the story shifts from security failure to stress-test-survived. If silence holds, or if the BTC begins moving into mixers or dispersed addresses, the "trusted federation" model faces a reckoning with no clean exit. LBTC holders in either case have learned what "counterparty risk at the infrastructure layer" actually costs.
Sources
- Blockstream Liquid Explorer (live federation balance)
- @ErgoBTC on X (original flag)
- Blockstream: What is a Liquid peg-out?
- Blockstream: Advanced peg-in / peg-out documentation
- First reported by Bitcoin.com News (Jamie Redman, September 6, 2026, 3:17 p.m. EDT)
Frequently Asked Questions
Liquid's peg-in/peg-out system routes BTC into a multisig wallet controlled by federation members, exchanges, brokers, and infrastructure firms. Users receive LBTC on the sidechain, but the underlying BTC is held by the consortium, not by individual users. That custody arrangement is the trust dependency this event exposes.
Conceivably. If a federation member or researcher discovered a critical vulnerability, a compromised PAK key or a functionary HSM flaw, a coordinated emergency drain to known-safe addresses is a plausible response. The signal that it is legitimate: a rapid public statement from Blockstream naming the actor and the return path. Silence cuts the other way.
LBTC becomes unbacked, worthless as a 1:1 BTC peg. There is no base-layer recourse for individual LBTC holders. Their claim is against the federation as a legal entity, not against the Bitcoin protocol. That is the custodial risk that has always lived inside the Liquid model, now priced in real time.


