Hackers Drain $320 Million from Liquid Network via Elements Bug, Return Most Funds
What Happened – On September 6 2026 attackers exploited a software bug in the open‑source Elements code that powers the Liquid Network sidechain. The flaw allowed the creation of unbacked L‑BTC tokens, which were then redeemed through SideSwap’s authorized peg‑out mechanism, draining roughly 4,000 BTC (≈ $320 M) from the federation wallet. The hackers later returned about 3,400 BTC (≈ $263 M) after Blockstream patched the vulnerable bridge nodes.
Why It Matters for Trust & Control Assurance
- Demonstrates how a missing control in secure software development and change‑management can lead to massive financial loss, a scenario continuous‑control‑assurance programs are built to detect and document.
- Highlights the need for ongoing evidence that third‑party code (open‑source components) is vetted, monitored, and patched promptly – a core control that satisfies multiple framework objectives.
- Shows the value of a verifiable audit trail (transaction logs, patch records) to prove due diligence to regulators and partners.
Who Is Affected – Crypto exchanges and custodians that rely on the Liquid Network, blockchain infrastructure providers, and any financial‑services firms using sidechain bridges for faster settlement.
Recommended Actions
- Map the incident to the control area “Secure Software Development & Change Management” and verify that your organization maintains continuous evidence of code reviews, vulnerability scanning, and patch deployment for all third‑party components.
- Collect and retain immutable logs of bridge‑node authorizations, peg‑out requests, and on‑chain transaction metadata to support audit readiness.
- Conduct a rapid gap analysis of your open‑source supply‑chain governance and implement automated monitoring for critical bugs.
Technical Notes – The exploit leveraged a flaw in Elements that permitted the issuance of more L‑BTC than the underlying Bitcoin reserves could back. Attackers used SideSwap’s authorized peg‑out key (which was not compromised) to convert the phantom tokens into real BTC. No private keys or credential theft occurred. Source: Security Affairs