Ledger CTO Questions White Hat Label After Liquid Network Drain

Liquid Network's bridge was drained of ~4,000 BTC by attackers claiming to be white hats. Ledger's CTO doubts the claim, comparing it to the Ronin hack.

07/09/2026 04:2714 min read

Ledger's top technology executive has voiced skepticism about the white hat label applied to the $320 million that was taken from the Liquid Network.

He did not go as far as to label it a theft. Liquid referred to the parties as alleged white hat hackers, and Blockstream is attempting to contact them on the blockchain.

Liquid Network Suspends Bridge Operations as Self-Proclaimed White Hats Seize 4,000 BTC

Liquid, a Bitcoin (BTC) layer-2 network, functions as a separate blockchain. It uses a two-way peg to connect Bitcoin with its native Liquid Bitcoin (L-BTC) asset.

On the main network, users lock Bitcoin to obtain an equal amount of L-BTC on Liquid. Redeeming L-BTC for Bitcoin is done via the network's peg-out process.

The team announced on X that approximately 4,000 Bitcoin were moved out of the Liquid Federation wallet. According to Liquid, the transaction employed the SideSwap Peg-out Authorization Key, which the company maintains was not compromised.

SideSwap stated that a customer transferred 4,000 LBTC to its peg-out service at 14:05 UTC, and the federation then disbursed 3,996 BTC 23 minutes afterward. Blockstream has subsequently traced that LBTC to a flaw in the Elements software, the company said.

The Bitcoin address bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte received the consolidated funds. An on-chain message within that address asserted that the actors were white hats.

The message additionally requested that Liquid reach out on-chain. Galaxy Research estimated that the funds accounted for roughly 95% of all Bitcoin locked to Liquid.

~4k BTC siphoned from Liquid Network, a Bitcoin sidechain. This was 95% of all BTC that had been pegged on Liquid.

Liquid has been halted since ~9am EST this morning.

The hacker(s) consolidated funds into a holding address with message “we are whitehats. contact us on chain” pic.twitter.com/K3cY0ca9YI

— Galaxy Research (@glxyresearch) September 6, 2026

In reaction, the network deactivated bridge nodes, blocking new transactions from entering the blockchain.

Additionally, Liquid informed exchanges, which have either halted or are ready to halt L-BTC deposits and withdrawals. Other assets on Liquid, such as USDT, DePix, and real-world assets, are not impacted by this event.

“Liquid wallets will be impacted, and we’re sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity,” the team noted.

Ledger’s Technology Chief Skeptical of Self-Proclaimed White Hats

Charles Guillemet, Ledger's CTO, cast doubt on the designation. He drew a parallel to the Ronin hack, where approximately $625 million was taken by attackers who gained access to validator keys. He also associated the request for communication with the Euler incident.

4,000 BTC just pegged out of the Liquid bridge. The OP_RETURN says "we are whitehats. contact us on chain."

White hats don't drain a bridge and then solicit an "on-chain" contact. This echoes the Ronin hack, where attackers compromised validator keys to steal ~$625M, and the
 pic.twitter.com/gPZmM13lXM

— Charles Guillemet (@P3b7_) September 6, 2026

Guillemet subsequently tempered his interpretation. He noted that the behavior does not align with typical white hat procedures, but also acknowledged that criminal organizations generally do not attempt to reach out to their victims.

“There’s hope. This could be people with good intentions that intensively played with recent LLMs and are not used to responsible disclosures
,” the executive noted.

Where the Coins Remain

At the time of writing, the coins remain in the address that initially received them. According to public records, that address still contains approximately 3,998 BTC, and the federation wallet holds about 197 BTC.

On early Monday, the same address produced a new signed message. It inquired whether returning the majority of the funds to the federation wallet would be considered acceptable.

The validity of Guillemet's skepticism hinges on the address's subsequent actions, not on its messages.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles