The claim, reported by Unchained from remarks Thorn made on its Uneasy Money podcast, reframes the September 2026 Liquid incident around a specific design question: whether the network’s peg-out authorization control ever constrained where funds ultimately landed. Thorn’s critique targets the gap between how the rule works in protocol documentation and how it operates once an exchange stands between the user and the Bitcoin base layer.
Alex Thorn Says Liquid’s Approved-Address Rule Didn’t Stop Bitcoin Thieves
Unchained identifies Thorn as Galaxy Digital’s head of firmwide research and reports that he criticized Liquid’s approved-address restriction directly, in its account of the Uneasy Money interview. The remarks are attributed commentary, not a formal statement issued by Galaxy Digital.
What Thorn Says About the Rule
Thorn noted that SideSwap accepts a customer-supplied Bitcoin address and forwards withdrawals to it, allowing the ultimate recipient to sit outside the peg-out allowlist. This is Unchained’s paraphrase of his criticism rather than a direct quotation or independent verification of SideSwap’s implementation.
The distinction matters because it separates the unauthorized creation of L-BTC from the authorized peg-out process that moved value out afterward. Thorn’s argument is that the allowlist did not bind the destination once an intermediary handled the peg-out on the user’s behalf.
What Liquid’s Approved-Address Rule Was Intended to Do
Liquid’s own documentation states that direct peg-outs require a registered Peg-out Authorization Key entry and must prove that the Bitcoin destination derives from a registered entry, according to its advanced peg-in and peg-out reference. The control is described as protection against compromised functionaries redirecting user funds to attacker-controlled addresses.
The Rule’s Scope and Enforcement
The relevant entity is Blockstream’s Liquid Network, a Bitcoin sidechain built on the Elements codebase and operated by a federation. The PAK restriction governs direct peg-outs, tying the destination to a registered key entry rather than screening for sanctions, KYC, or any government-mandated whitelist.
The same documentation says the general public typically withdraws indirectly through a federation member or exchange, naming Bitfinex and SideSwap, with the exchange handling the PAK and executing the peg-out. In that documented exchange workflow, a user withdrawing BTC via peg-out receives BTC to any Bitcoin address.
That workflow is where Thorn’s criticism lands: the documentation describes an intermediary process, not a cryptographic bypass of PAK validation. Liquid and SideSwap have said no authorization key was compromised, and that SideSwap could not distinguish the incident-derived L-BTC from other L-BTC, according to Unchained’s account; their complete original responses were not published, so the company attribution should be read as their position rather than settled fact.
What Remains Unverified About the Reported Bitcoin Theft
CertiK reports that the September 6, 2026 exploit affected approximately 3,998.5 L-BTC, valued at $318.7 million at the time, with the assets subsequently pegged out into native Bitcoin. The firm attributes the inflation to ambiguous cache-key encoding in Elements’ rangeproof-verification cache, where distinct validation inputs could reuse one cached result and bypass a fresh rangeproof check.
L-BTC affected, according to CertiK
Approximately 3,998.5 L-BTC
The self-described white hat returned 3,400 BTC and retained 598.5 BTC, per CertiK’s account. Those amounts are source-reported, and the transactions and white-hat status were not independently verified.
Bitcoin returned, according to CertiK
3,400 BTC
Evidence Needed to Assess the Claim
Liquid Network’s September 6 public statement acknowledged that purported white-hat hackers withdrew about 4,000 BTC from the federation wallet. The network said Blockstream was working to contact them on-chain with a signed message.
We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.
What we know so far is that the funds…
— Liquid Network 🌊 (@Liquid_BTC) September 6, 2026
Source: @Liquid_BTC on X
Key forensic details remain open. CertiK explicitly says the live cache-primer transaction ID and raw bytes remain unknown, and that the exact binaries deployed on individual functionaries have not been published, so the observed inflation and peg-outs should not be read as a complete forensic reconstruction.
The evidence still needed to fully assess Thorn’s claim includes his original podcast audio, the complete responses from Liquid and SideSwap, and block-explorer records tracing the return. What is absent from current reporting is not the same as what is unavailable publicly, and the case for the allowlist’s failure rests on an authorization distinction rather than a proven cryptographic bypass.
The critique should not be generalized into a verdict that approved-address controls cannot deter theft. It is a narrower point about intermediary peg-outs, and it arrives against a broader market backdrop in which Bitcoin traded near $76,950, down roughly 2.9% on the day, with the Crypto Fear & Greed Index at 69, or “Greed” — readings that describe the wider market, not sentiment toward Liquid specifically.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
