HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Hackers Drain $320 Million from Liquid Network via Elements Bug, Return Most Funds

Attackers exploited a software bug in the Elements code that powers the Liquid Network sidechain, draining roughly 4,000 BTC (≈ $320 M). The incident underscores the importance of secure software development, continuous monitoring of third‑party code, and maintaining auditable evidence of patching.

Verisq™ Intelligence · 📅 September 09, 2026 · 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
2 recommended
📰
Source
securityaffairs.com

Hackers Drain $320 Million from Liquid Network via Elements Bug, Return Most Funds

What Happened – On September 6 2026 attackers exploited a software bug in the open‑source Elements code that powers the Liquid Network sidechain. The flaw allowed the creation of unbacked L‑BTC tokens, which were then redeemed through SideSwap’s authorized peg‑out mechanism, draining roughly 4,000 BTC (≈ $320 M) from the federation wallet. The hackers later returned about 3,400 BTC (≈ $263 M) after Blockstream patched the vulnerable bridge nodes.

Why It Matters for Trust & Control Assurance

  • Demonstrates how a missing control in secure software development and change‑management can lead to massive financial loss, a scenario continuous‑control‑assurance programs are built to detect and document.
  • Highlights the need for ongoing evidence that third‑party code (open‑source components) is vetted, monitored, and patched promptly – a core control that satisfies multiple framework objectives.
  • Shows the value of a verifiable audit trail (transaction logs, patch records) to prove due diligence to regulators and partners.

Who Is Affected – Crypto exchanges and custodians that rely on the Liquid Network, blockchain infrastructure providers, and any financial‑services firms using sidechain bridges for faster settlement.

Recommended Actions

  • Map the incident to the control area “Secure Software Development & Change Management” and verify that your organization maintains continuous evidence of code reviews, vulnerability scanning, and patch deployment for all third‑party components.
  • Collect and retain immutable logs of bridge‑node authorizations, peg‑out requests, and on‑chain transaction metadata to support audit readiness.
  • Conduct a rapid gap analysis of your open‑source supply‑chain governance and implement automated monitoring for critical bugs.

Technical Notes – The exploit leveraged a flaw in Elements that permitted the issuance of more L‑BTC than the underlying Bitcoin reserves could back. Attackers used SideSwap’s authorized peg‑out key (which was not compromised) to convert the phantom tokens into real BTC. No private keys or credential theft occurred. Source: Security Affairs

📰 Original Source
https://securityaffairs.com/198697/cyber-crime/hackers-drain-320-million-from-liquid-network-then-return-most-of-it.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →