Close Menu

    Subscribe to Updates

    What's Hot

    Aurora Intents routed $19M into Zcash NFT auction

    September 22, 2026

    Goerli Shapella Announcement | Ethereum Foundation Blog

    September 22, 2026

    Liquid Network attacker crossed into theft: Immunefi CEO

    September 22, 2026
    Facebook X (Twitter) Instagram
    laicryptolaicrypto
    Demo
    • Ethereum
    • Crypto
    • Altcoins
    • Blockchain
    • Bitcoin
    • Lithosphere News Releases
    laicryptolaicrypto
    Home Liquid Network attacker crossed into theft: Immunefi CEO
    Crypto

    Liquid Network attacker crossed into theft: Immunefi CEO

    John SmithBy John SmithSeptember 22, 2026No Comments7 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Immunefi CEO Mitchell Amador has said the Liquid Network attackers lost any claim to white-hat status by retaining 598.5 BTC after returning 3,400 BTC from the roughly 4,000 BTC exploit.

    Summary

    • Roughly 598.5 BTC remains with the attackers after they returned 3,400 BTC.
    • Amador said coordinated disclosure ends when a researcher sets rescue terms without prior approval.
    • Protocols should establish rescue rules and bounty limits before an exploit occurs.
    • Immunefi’s CEO defended the 10% bounty convention when teams approve it in advance.

    Immunefi founder and CEO Mitchell Amador told crypto.news that moving user assets without permission cannot be treated as a rescue when the researcher later keeps part of the funds or sets payment terms.

    “Coordinated disclosure ends the moment you set the terms yourself,” Amador said. “The money was never yours to save, so moving it is not a rescue.”

    His comments address the dispute left by the Liquid Network incident, in which unidentified actors withdrew roughly 4,000 BTC, valued at about $320 million at the time, before describing themselves as whitehats. They returned 3,400 BTC after Blockstream patched the affected bridge nodes but retained 598.5 BTC.

    Blockstream has rejected the group’s demand for a 10% bounty and has said it will not pay for the return of the remaining Bitcoin. The company also rejected the attackers’ claim that the operation amounted to responsible disclosure.

    Liquid Network attackers could not set their own terms

    Amador said a security researcher must use private disclosure channels, preferably through a defined bug bounty program, instead of taking assets and negotiating a reward afterward.

    “Keep a dollar of user funds, and it is theft, whatever the intent was at the outset. The path for a researcher is private disclosure, ideally within a well-defined program.”

    The distinction rests on authorization rather than the researcher’s stated motive. Under Amador’s view, finding a real vulnerability does not give someone the right to move user assets, hold them as collateral, or decide what compensation is owed.

    Blockstream took a similar position in its Sept. 11 response. As previously reported by crypto.news, the company said taking assets without permission and refusing to return them constituted theft rather than whitehat work.

    The company said its earlier discussions with the actors were intended to recover user funds and protect the Bitcoin community. According to Blockstream, engaging in those talks did not mean it had accepted either the withdrawal or the later bounty demand.

    A technical review of the exploit found that a cache-key collision in the confidential transaction verification logic allowed the actors to create unbacked L-BTC. They then used SideSwap’s peg-out service to obtain real Bitcoin from the federation reserve.

    Federation keys were not compromised, according to Blockstream. The incident instead involved verification logic in the Elements codebase, while the federation nodes were running a release that did not contain the relevant fix.

    Rescue terms should exist before an exploit

    Rather than negotiating under pressure after funds have moved, Amador said serious protocols should decide their rescue conditions before an emergency occurs.

    “Yes, rescue terms must exist ahead of an exploit,” he said. “All serious protocols should set these in advance.”

    Predetermined rules can define which systems researchers may test, how they must disclose a vulnerability, and what actions they can take during an active incident. They can also state the maximum bounty, payment conditions, and legal protections available to researchers who remain within the approved scope.

    Immunefi developed the Whitehat Safe Harbor framework to establish such conditions before a protocol faces an attack. Amador, who helped shape the framework and has participated in live exploit response teams, compared emergency action with saving a house from a fire: the need for help does not authorize every possible rescue method.

    Advance agreements also give protocol teams a basis for distinguishing approved intervention from coercion. Without prior terms, an actor who controls user funds can demand payment while the project faces losses, service disruptions, and pressure from token holders.

    Liquid’s actors initially communicated through messages placed in Bitcoin transactions and told Blockstream to patch the flaw before they returned the funds. After Blockstream confirmed that affected bridge nodes had been patched, the group sent 3,400 BTC back to the federation wallet.

    No publicly disclosed agreement had allowed the group to retain the remaining 598.5 BTC. The amount also exceeds 10% of the approximately 4,000 BTC involved, although the reported demand centered on a 10% reward.

    The 10% crypto bounty convention still has a role

    While rejecting the Liquid actors’ attempt to impose their own terms, Amador defended the crypto industry’s informal practice of offering up to 10% of funds at risk as a whitehat bounty.

    Without a common reference point, he said, each settlement would need to be negotiated from the beginning, giving an attacker more leverage during an active incident. A defined percentage gives researchers a legal payment route while allowing a protocol to recover most of the exposed assets.

    “Ten percent of a $100M exploit is $10M earned legally, with nobody hunting you afterwards,” Amador said. “The alternative for them is moving nine figures onchain while every forensics firm watches.”

    The 10% figure has appeared in several recovery offers, but projects usually state the terms themselves. In August, BTCPay Server supporters backed a reward equal to 10% of recovered funds after attackers obtained LND admin macaroon credentials. The proposed payout was capped at 3 BTC if all stolen assets were returned.

    Cetus Protocol followed a different formula after its May 2025 exploit. A flaw in its automated market maker logic caused losses of more than $223 million, while the Sui Foundation coordinated with validators to freeze about $163 million. Cetus later announced a $5 million reward for information leading to the identification of the attacker, according to its post-exploit review.

    Amador said the reward should generally reach up to 10% of funds at risk while remaining subject to a cap the protocol can afford. Setting the amount too low could make theft more attractive than disclosure, he said, while an excessive payout could leave the rescued project unable to continue operating.

    “Price it too high, and paying out can kill the protocol you just saved, which helps nobody,” he said.

    Projects may still pay above their stated cap when a report warrants a larger reward, Amador added. Under his proposed model, the protocol retains control over that decision instead of allowing a researcher to establish the fee after taking custody of user assets.

    U.S. prosecutions show the risk of unauthorized exploits

    For U.S.-based researchers, returning funds or offering to negotiate does not necessarily prevent criminal charges when the original access was unauthorized.

    In December 2023, former security engineer Shakeeb Ahmed pleaded guilty to computer fraud after exploiting two decentralized exchanges and obtaining more than $12 million. According to the U.S. Justice Department, Ahmed negotiated with one platform and proposed returning the stolen funds except for $1.5 million if the exchange agreed not to contact law enforcement.

    Federal prosecutors said Ahmed later agreed to forfeit more than $12.3 million, including about $5.6 million in fraudulently obtained cryptocurrency. In April 2024, a federal judge sentenced him to three years in prison and ordered the forfeiture of the stolen assets.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    John Smith

    Related Posts

    Aurora Intents routed $19M into Zcash NFT auction

    September 22, 2026

    Tokenized stocks may see limited U.S. demand: TD Cowen

    September 21, 2026

    SlowMist warns Darksword may target wallets on iOS 26.5

    September 21, 2026
    Leave A Reply Cancel Reply

    Demo
    Don't Miss
    Crypto

    Aurora Intents routed $19M into Zcash NFT auction

    By John SmithSeptember 22, 20260

    Aurora Intents has processed more than $19 million across 1,718 swaps for the zkSNARKS auction,…

    Goerli Shapella Announcement | Ethereum Foundation Blog

    September 22, 2026

    Liquid Network attacker crossed into theft: Immunefi CEO

    September 22, 2026

    Next Billion Fellowship Cohort 3 – Call for applications

    September 22, 2026

    LAI Crypto is a user-friendly platform that empowers individuals to navigate the world of cryptocurrency trading and investment with ease and confidence.

    Our Posts
    • Altcoins (23)
    • Bitcoin (11)
    • Blockchain (15)
    • Crypto (722)
    • Ethereum (456)

    Subscribe to Updates

    • Twitter
    • Instagram
    • YouTube
    • LinkedIn

    Type above and press Enter to search. Press Esc to cancel.