Immunefi founder and CEO Mitchell Amador says the actors behind the Liquid Network incident crossed from any possible white-hat claim into theft by retaining part of the Bitcoin taken during the exploit. His comments come after the group returned 3,400 BTC but kept 598.5 BTC from the roughly 4,000 BTC withdrawn.
Amador told crypto.news that a researcher does not gain the right to move user assets, hold them as leverage, or set compensation terms after the fact. In his view, coordinated disclosure ends once an actor takes funds without authorization and then tries to dictate the conditions for their return.
Dispute over the remaining Bitcoin
The Liquid Network case centers on unidentified actors who withdrew about 4,000 BTC, worth roughly $320 million at the time, and later described themselves as white hats. After Blockstream said the affected bridge nodes had been patched, the group sent 3,400 BTC back to the federation wallet, leaving 598.5 BTC in their control.
Blockstream has rejected the group’s demand for a 10% bounty and said it will not pay for the return of the remaining Bitcoin. The company has also disputed the claim that the operation amounted to responsible disclosure, saying that taking assets without permission and refusing to return them is theft rather than security work.
Why Amador says white-hat status no longer applies
Amador argued that the key issue is authorization, not the stated motive of the people involved. Under that standard, discovering a genuine vulnerability does not entitle a researcher to move customer funds, use them as collateral, or decide what reward is owed.
He said researchers should use private disclosure channels and, ideally, work within a defined bug bounty program. In his framing, the moment a person sets rescue terms on their own, coordinated disclosure is over. Keeping even a small portion of user assets, he said, cannot be treated as part of a legitimate rescue.
Blockstream took a similar position in its Sept. 11 response, saying its communications with the actors were aimed at recovering funds and protecting the Bitcoin community, not at accepting the withdrawal or agreeing to a later bounty claim.
How the exploit worked and what rules should exist beforehand
A technical review found that the exploit relied on a cache-key collision in confidential transaction verification logic. According to the review, that flaw let the actors create unbacked L-BTC, which they then used through SideSwap’s peg-out service to obtain real Bitcoin from the federation reserve.
Amador said serious protocols should define emergency rescue terms before any incident takes place, rather than negotiating while assets are already under someone else’s control. Those advance terms can specify what systems may be tested, how vulnerabilities must be reported, what actions are allowed during a live incident, and what bounty limits or legal protections are available.
He pointed to prearranged frameworks such as Immunefi’s Whitehat Safe Harbor as a way to separate approved intervention from coercive bargaining. In the Liquid case, no publicly disclosed agreement allowed the actors to keep the remaining 598.5 BTC, and that amount is also larger than 10% of the roughly 4,000 BTC involved.
The 10% bounty norm and the legal risk of going outside it
Amador nevertheless defended the crypto industry’s informal practice of offering up to 10% of funds at risk as a white-hat reward when the protocol itself sets those terms in advance. He said a shared benchmark can reduce haggling during a crisis, give researchers a legal route to payment, and still leave most assets with the project.
He said that benchmark should still be capped at a level a protocol can afford, because a reward set too low may fail to discourage theft while one set too high can damage the project it is meant to save. Projects can still choose to pay more than a stated cap, he added, but that decision should remain with the protocol rather than with an actor who has already taken control of funds.
Amador also pointed to U.S. enforcement risk for researchers who act without authorization. The article cites the case of former security engineer Shakeeb Ahmed, who pleaded guilty in December 2023 to computer fraud after exploiting two decentralized exchanges and obtaining more than $12 million. He was later sentenced in April 2024 to three years in prison and ordered to forfeit the stolen assets, underscoring that later negotiations do not necessarily erase criminal exposure.
What comes next
The immediate unresolved issue is the return, or non-return, of the remaining 598.5 BTC. Blockstream has publicly rejected the attackers’ 10% bounty demand and says no accepted arrangement permits them to keep any of the funds.
More broadly, the dispute has become a test case for how crypto projects distinguish between authorized white-hat intervention and unauthorized seizure of user assets. Based on Amador’s comments and Blockstream’s position, the next confirmed lesson for protocols is clear: rescue rules, disclosure channels, and bounty caps need to be established before an exploit begins, not after funds have already moved.
Source: crypto.news