BITCOIN

Alex Thorn: Liquid Address Rule Didn’t Stop Bitcoin Thieves

Alex Thorn, Galaxy Digital's head of firmwide research, has argued that Liquid Network's approved-address rule failed to stop the thieves behind a roughly $318.

Share:

The claim, reported by Unchained from remarks Thorn made on its Uneasy Money podcast, reframes the September 2026 Liquid incident around a specific design question: whether the network’s peg-out authorization control ever constrained where funds ultimately landed. Thorn’s critique targets the gap between how the rule works in protocol documentation and how it operates once an exchange stands between the user and the Bitcoin base layer.

Alex Thorn Says Liquid’s Approved-Address Rule Didn’t Stop Bitcoin Thieves

Unchained identifies Thorn as Galaxy Digital’s head of firmwide research and reports that he criticized Liquid’s approved-address restriction directly, in its account of the Uneasy Money interview. The remarks are attributed commentary, not a formal statement issued by Galaxy Digital.

What Thorn Says About the Rule

Thorn noted that SideSwap accepts a customer-supplied Bitcoin address and forwards withdrawals to it, allowing the ultimate recipient to sit outside the peg-out allowlist. This is Unchained’s paraphrase of his criticism rather than a direct quotation or independent verification of SideSwap’s implementation.

The distinction matters because it separates the unauthorized creation of L-BTC from the authorized peg-out process that moved value out afterward. Thorn’s argument is that the allowlist did not bind the destination once an intermediary handled the peg-out on the user’s behalf.

What Liquid’s Approved-Address Rule Was Intended to Do

Liquid’s own documentation states that direct peg-outs require a registered Peg-out Authorization Key entry and must prove that the Bitcoin destination derives from a registered entry, according to its advanced peg-in and peg-out reference. The control is described as protection against compromised functionaries redirecting user funds to attacker-controlled addresses.

The Rule’s Scope and Enforcement

The relevant entity is Blockstream’s Liquid Network, a Bitcoin sidechain built on the Elements codebase and operated by a federation. The PAK restriction governs direct peg-outs, tying the destination to a registered key entry rather than screening for sanctions, KYC, or any government-mandated whitelist.

The same documentation says the general public typically withdraws indirectly through a federation member or exchange, naming Bitfinex and SideSwap, with the exchange handling the PAK and executing the peg-out. In that documented exchange workflow, a user withdrawing BTC via peg-out receives BTC to any Bitcoin address.

That workflow is where Thorn’s criticism lands: the documentation describes an intermediary process, not a cryptographic bypass of PAK validation. Liquid and SideSwap have said no authorization key was compromised, and that SideSwap could not distinguish the incident-derived L-BTC from other L-BTC, according to Unchained’s account; their complete original responses were not published, so the company attribution should be read as their position rather than settled fact.

What Remains Unverified About the Reported Bitcoin Theft

CertiK reports that the September 6, 2026 exploit affected approximately 3,998.5 L-BTC, valued at $318.7 million at the time, with the assets subsequently pegged out into native Bitcoin. The firm attributes the inflation to ambiguous cache-key encoding in Elements’ rangeproof-verification cache, where distinct validation inputs could reuse one cached result and bypass a fresh rangeproof check.

L-BTC affected, according to CertiK

Approximately 3,998.5 L-BTC

CertiK reports that the September 6, 2026 exploit affected approximately 3,998.5 L-BTC, subsequently pegged out into native Bitcoin. The amount is source-reported and was not independently verified on-chain in this run.

The self-described white hat returned 3,400 BTC and retained 598.5 BTC, per CertiK’s account. Those amounts are source-reported, and the transactions and white-hat status were not independently verified.

Bitcoin returned, according to CertiK

3,400 BTC

CertiK reports that the self-described white hat returned 3,400 BTC and retained 598.5 BTC. These amounts are source-reported; the transactions and white-hat status were not independently verified in this run.

Evidence Needed to Assess the Claim

Liquid Network’s September 6 public statement acknowledged that purported white-hat hackers withdrew about 4,000 BTC from the federation wallet. The network said Blockstream was working to contact them on-chain with a signed message.

Source: @Liquid_BTC on X

Key forensic details remain open. CertiK explicitly says the live cache-primer transaction ID and raw bytes remain unknown, and that the exact binaries deployed on individual functionaries have not been published, so the observed inflation and peg-outs should not be read as a complete forensic reconstruction.

The evidence still needed to fully assess Thorn’s claim includes his original podcast audio, the complete responses from Liquid and SideSwap, and block-explorer records tracing the return. What is absent from current reporting is not the same as what is unavailable publicly, and the case for the allowlist’s failure rests on an authorization distinction rather than a proven cryptographic bypass.

The critique should not be generalized into a verdict that approved-address controls cannot deter theft. It is a narrower point about intermediary peg-outs, and it arrives against a broader market backdrop in which Bitcoin traded near $76,950, down roughly 2.9% on the day, with the Crypto Fear & Greed Index at 69, or “Greed” — readings that describe the wider market, not sentiment toward Liquid specifically.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Stay ahead of the market

Get daily crypto insights delivered to your inbox.

Related Articles

View all →