Liquid Network Pauses After a $320 Million Bitcoin Withdrawal

Almost all bitcoin held in Liquid’s federation wallet moved without authorisation, forcing the sidechain to halt while the destination’s operators call the action a white-hat intervention.

By Elena Novak • • Blockchain

A dark geometric custody vault releases amber digital particles while a ring of validator pylons stands under a stormy sky.

Liquid Network has paused its Bitcoin sidechain after about 4,000 bitcoin, worth roughly $320 million, left its federation wallet without authorisation. The amount represented almost all of the approximately 4,200 bitcoin held by the wallet, making the incident a direct test of the custody and governance model behind one of Bitcoin’s best-known federated networks.

Liquid stopped new transactions and disabled the bridge nodes used to move assets between Bitcoin and the sidechain. Exchanges also suspended deposits and withdrawals of Liquid Bitcoin, or L-BTC. Those controls limit further movement but interrupt legitimate users, traders and issuers that rely on the network for faster settlement and confidential transactions.

The bitcoins moved to an address associated with SideSwap, a Liquid-focused exchange whose operators described the action as a “purported white-hat” intervention. That claim is not proof that the funds are safe or will be returned. No completed recovery, signed undertaking or independently verified explanation had been published when this article was prepared.

The distinction between a compromised key and a protocol flaw is crucial. Liquid uses a federation of functionaries rather than Bitcoin’s proof-of-work miners to secure the two-way peg. A large withdrawal can therefore arise from several classes of failure: compromised signing authority, a defect in transaction validation, misuse of emergency controls or a flaw in software connected to the federation. Public reporting did not establish the final mechanism. Assertions about a specific inflation bug or unaffected keys remain unconfirmed until the network publishes a technical account.

Liquid was launched by Blockstream to support faster and more private transfers between exchanges and institutions. Users lock bitcoin on the main chain and receive L-BTC on Liquid. The arrangement offers speed and functionality, but it also concentrates operational trust in the federation and the systems surrounding the peg. The $320 million movement exposes the consequences when that boundary fails.

For exchanges, the immediate priority is reconciliation. Operators must identify which L-BTC balances remain backed, stop automated deposits from crediting potentially impaired assets and preserve records for any recovery process. Market makers face basis risk if L-BTC diverges from bitcoin while conversion is unavailable. Issuers using Liquid for securities or stable assets must assess whether settlement finality and treasury operations are affected.

For users, the network pause prevents ordinary exit at the moment confidence matters most. That does not by itself mean every L-BTC holder has lost money. It means redemption depends on the investigation, control of the withdrawn bitcoin and the federation’s recovery plan. Any restart should explain the backing status, the exact block or transaction boundary, and how invalid or disputed transfers will be handled.

The incident also raises a governance question. A federation can coordinate a rapid halt, which is useful during an emergency. The same power demonstrates that the system is not equivalent to Bitcoin’s base layer. Institutions selecting a sidechain should price that trade-off explicitly: faster, richer functionality in exchange for reliance on a smaller operating set and emergency decision process.

The market value of the transferred bitcoin is also a moving estimate, not the same as a verified loss. Bitcoin’s price can change while the coins remain at the destination, and recovery could range from a complete return to a negotiated settlement or permanent impairment. Accounting teams should avoid recognising a final outcome from the headline value alone. They need evidence about legal control, redemption rights and the likelihood and timing of recovery.

Insurance may provide only partial protection. Digital-asset policies commonly distinguish theft, software defects, insider actions and failures at third-party infrastructure. Coverage limits can be far below aggregate network exposure, while exclusions and notification duties become critical after an incident. Participants should preserve logs and communications and review policies before making public assumptions about reimbursement.

The response will matter for regulation as well. A federated peg serving institutions resembles shared market infrastructure even when it is not a conventional clearing house. Supervisors may ask whether operational resilience, recovery planning and concentration disclosures match the economic function. That scrutiny could extend to other bridges and sidechains whose security assumptions differ from the assets they represent.

Why it matters

The value at risk is large, but the more durable issue is credibility. A bitcoin-backed network depends on a simple promise: each sidechain unit can be redeemed for bitcoin under defined rules. Moving almost the entire federation balance without authorisation challenges that promise, even if the actor ultimately returns every coin.

The event will influence how custodians, exchanges and token issuers evaluate federated infrastructure. They will want evidence about key separation, signing thresholds, software supply chains, monitoring and incident authority. Audits that focus only on code may be insufficient if the failure involved operational systems or governance.

Liquid can materially reduce the damage by publishing verifiable transaction identifiers, a precise timeline, the affected software versions and an independent post-mortem. It should also separate confirmed facts from the white-hat claim. Until custody of the bitcoin and the exploit path are independently established, the appropriate conclusion is that the network contained activity after an unauthorised withdrawal; it has not yet demonstrated full recovery.

Sources