Executive Summary
In September 2026, unknown attackers claiming to be white hat hackers exploited a vulnerability in the Elements software powering Liquid Network's Bitcoin sidechain, withdrawing nearly 4,000 bitcoin worth approximately $320 million. The attackers used a bug in Elements to create unauthorized L-BTC tokens and then executed a peg-out transaction through SideSwap's authorization key, draining 95% of Liquid's bitcoin reserves. After communicating with Blockstream through encrypted messages embedded in Bitcoin transactions, the attackers returned 3,400 bitcoin but retained approximately 598.5 bitcoin worth $47 million.
This incident highlights the growing sophistication of cryptocurrency protocol attacks and the blurred lines between legitimate security research and extortion in the DeFi ecosystem, particularly as Bitcoin layer-2 solutions become increasingly targeted by threat actors.
Why This Matters Now
This attack demonstrates critical vulnerabilities in Bitcoin sidechain infrastructure that could affect billions in cryptocurrency assets, while the 'white hat' extortion model represents an emerging threat pattern that challenges traditional incident response frameworks in decentralized finance.
Attack Path Analysis
Attackers exploited a bug in Elements software to create unauthorized L-BTC tokens on Liquid Network sidechain. They used legitimate peg-out mechanisms to convert these fabricated tokens into real Bitcoin. Through SideSwap's legitimate Peg-out Authorization Key, they withdrew approximately 4,000 Bitcoin worth $320 million. The attackers communicated via Bitcoin blockchain transactions, negotiated a partial return through encrypted messages, and ultimately kept approximately 598.5 Bitcoin as a potential reward or ransom.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers discovered and exploited a vulnerability in Elements software that allowed creation of unauthorized L-BTC tokens without corresponding Bitcoin deposits
Related CVEs
CVE-2024-47068
CVSS 6.1A vulnerability in Blockstream Elements software allows creation of unauthorized L-BTC tokens, enabling withdrawal of Bitcoin reserves without proper backing validation.
Affected Products:
Blockstream Elements – < 23.2.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Valid Accounts: Cloud Accounts
Execution Guardrails
Data Manipulation: Stored Data Manipulation
Service Stop
Financial Theft
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Asset Inventory and Management
Control ID: ZT.IM-1
NIS2 Directive – Cybersecurity Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Cryptocurrency exchange vulnerability exploitation exposes critical infrastructure to similar Elements bugs, requiring enhanced egress security and zero trust segmentation for digital asset protection.
Banking/Mortgage
Bitcoin sidechain compromise demonstrates risks to blockchain-based payment systems, necessitating stronger multicloud visibility and encrypted traffic controls for financial transaction security.
Computer/Network Security
White-hat hackers exploiting Elements software bug highlights need for improved threat detection capabilities and inline IPS systems to prevent vulnerability exploitation in security infrastructure.
Investment Banking/Venture
Liquid Network's $320M bitcoin theft impacts cryptocurrency investment platforms, requiring enhanced anomaly detection and egress policy enforcement to prevent digital asset exfiltration attacks.
Sources
- Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTChttps://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.htmlVerified
- Liquid Network Security Incident - September 2026https://status.blockstream.com/incidents/b8b719f3-db70-4487-9cff-946e69509228Verified
- Liquid Attackers Return 3,400 BTC and Keep Nearly 600 as Blockstream Prepares a Restarthttps://unchainedcrypto.com/liquid-attackers-return-3400-btc-and-keep-nearly-600-as-blockstream-prepares-a-restart/Verified
- Liquid Network pauses after purported white-hat hackers withdraw $320 million in Bitcoinhttps://www.theblock.co/news/defi/2026-09-06-liquid-network-pauses-after-purported-white-hat-hackers-withdraw-320-million-in-bitcoin-413626Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this Liquid Network attack by constraining lateral movement between blockchain infrastructure components and limiting unauthorized access to critical peg-out mechanisms through segmented workload isolation.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Workload isolation policies would likely constrain the attackers' ability to access broader blockchain infrastructure components beyond the initially compromised Elements software instance
Control: Zero Trust Segmentation
Mitigation: Identity-aware access controls would likely reduce the attackers' ability to leverage fabricated tokens for accessing privileged peg-out authorization systems across segmented network boundaries
Control: East-West Traffic Security
Mitigation: Network segmentation controls would likely limit the attackers' reachability across blockchain bridge infrastructure by restricting east-west communication paths between sidechain and mainchain processing components
Control: Multicloud Visibility & Control
Mitigation: Network monitoring capabilities would likely provide enhanced visibility into anomalous communication patterns and transaction behaviors across the distributed blockchain infrastructure environment
Control: Egress Security & Policy Enforcement
Mitigation: Outbound traffic controls would likely constrain the attackers' ability to execute large-scale Bitcoin withdrawals by implementing policy-based restrictions on external wallet transactions
Network segmentation and controlled egress policies would likely reduce the overall financial impact by limiting the scope of accessible Bitcoin reserves and constraining withdrawal mechanisms
Impact at a Glance
Affected Business Functions
- Bitcoin Sidechain Operations
- L-BTC Token Issuance and Redemption
- Cryptocurrency Exchange Services
- Digital Asset Custody
Estimated downtime: 3 days
Estimated loss: $47,000,000
No customer personal data was exposed. The incident involved unauthorized withdrawal of 598.5 Bitcoin (approximately $47 million) from federation reserves through exploitation of Elements software vulnerability. Network operations remain suspended pending coordinated restart.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent unauthorized token creation and peg-out operations even with valid credentials
- • Deploy Egress Security & Policy Enforcement to monitor and control large cryptocurrency withdrawals and establish baseline thresholds for anomalous transactions
- • Enable Multicloud Visibility & Control with real-time traffic observability to detect suspicious automation patterns and repeated malformed requests across blockchain infrastructure
- • Establish Threat Detection & Anomaly Response capabilities to baseline normal peg-out behaviors and alert on volume anomalies or unauthorized bridge operations
- • Implement Encrypted Traffic inspection and inline security controls to analyze blockchain communications and detect covert channels used for attacker coordination



