Liquid Network: $320M BTC Breach via Elements Protocol Vulnerability in Blockstream’s Liquid Network
A critical logic flaw within the Elements Protocol, the foundational architecture of Blockstream’s Liquid Network, has resulted in the unauthorized withdrawal of approximately 4,000 BTC (~$320M) from the Liquid Federation wallet. The exploit bypasses standard withdrawal controls by targeting vulnerabilities in the underlying Elements codebase, specifically within the federated sidechain model. Unlike traditional ransomware, the threat actors claim "white hat" status, demanding a permanent architectural remediation of the protocol rather than a direct monetary ransom. This incident has forced a total suspension of Liquid Network transaction processing, exposing systemic vulnerabilities in federated sidechain architectures utilized by cryptocurrency exchanges for high-speed settlement.
ClickFix Malware Campaign: Decentralized Payload Hosting via WordPress Exploitation
A widespread cyberattack campaign has compromised over 5,400 WordPress websites to distribute multi-stage malware using the "ClickFix" social engineering technique. Attackers leverage critical RCE vulnerabilities in plugins—including CVE-2026-14894 (Super Forms) and CVE-2026-32475 (Elementor Pro)—to inject scripts that display deceptive Cloudflare CAPTCHAs or browser error prompts. These lures trick users into manually executing malicious PowerShell or Terminal commands. To ensure resilience, the campaign utilizes "EtherHiding," hosting payloads and C2 resolution on the Polygon and BNB Smart Chain blockchains. Impacted systems are infected with diverse payloads, including DeepLoad, KongTuke (ModeloRAT), and ACR Stealer, targeting both Windows and macOS environments for enterprise credential theft and network intrusion.
Tectonics: Price Manipulation Exploit via Collateral Control Failure
The Tectonics protocol on the Cronos network suffered a critical liquidity drain estimated between $75 million and $120 million due to a price manipulation exploit targeting the TONICs token. Attackers artificially inflated the token's price 100-fold within a 20-minute window, exploiting a failure in Tectonics' internal collateralization controls that permitted low-liquidity assets to serve as high-value collateral. While the RedStone oracle accurately reported the manipulated market price, the lack of price-deviation safeguards enabled unauthorized borrows and asset withdrawals. The exploit's scale forced an emergency halt of block production across the entire Cronos network to prevent further asset depletion.