Liquid Network attacker crossed into theft: Immunefi CEO


Immunefi CEO Mitchell Amador has said the Liquid Network attackers lost any claim to white-hat status by retaining 598.5 BTC after returning 3,400 BTC from the roughly 4,000 BTC exploit.
Summary
- Roughly 598.5 BTC remains with the attackers after they returned 3,400 BTC.
- Amador said coordinated disclosure ends when a researcher sets rescue terms without prior approval.
- Protocols should establish rescue rules and bounty limits before an exploit occurs.
- Immunefi’s CEO defended the 10% bounty convention when teams approve it in advance.
Immunefi founder and CEO Mitchell Amador told crypto.news that moving user assets without permission cannot be treated as a rescue when the researcher later keeps part of the funds or sets payment terms.
“Coordinated disclosure ends the moment you set the terms yourself,” Amador said. “The money was never yours to save, so moving it is not a rescue.”
His comments address the dispute left by the Liquid Network incident, in which unidentified actors withdrew roughly 4,000 BTC, valued at about $320 million at the time, before describing themselves as whitehats. They returned 3,400 BTC after Blockstream patched the affected bridge nodes but retained 598.5 BTC.
Blockstream has rejected the group’s demand for a 10% bounty and has said it will not pay for the return of the remaining Bitcoin. The company also rejected the attackers’ claim that the operation amounted to responsible disclosure.
Liquid Network attackers could not set their own terms
Amador said a security researcher must use private disclosure channels, preferably through a defined bug bounty program, instead of taking assets and negotiating a reward afterward.
“Keep a dollar of user funds, and it is theft, whatever the intent was at the outset. The path for a researcher is private disclosure, ideally within a well-defined program.”
The distinction rests on authorization rather than the researcher’s stated motive. Under Amador’s view, finding a real vulnerability does not give someone the right to move user assets, hold them as collateral, or decide what compensation is owed.
Blockstream took a similar position in its Sept. 11 response. As previously reported by crypto.news, the company said taking assets without permission and refusing to return them constituted theft rather than whitehat work.
The company said its earlier discussions with the actors were intended to recover user funds and protect the Bitcoin community. According to Blockstream, engaging in those talks did not mean it had accepted either the withdrawal or the later bounty demand.
A technical review of the exploit found that a cache-key collision in the confidential transaction verification logic allowed the actors to create unbacked L-BTC. They then used SideSwap’s peg-out service to obtain real Bitcoin from the federation reserve.
Federation keys were not compromised, according to Blockstream. The incident instead involved verification logic in the Elements codebase, while the federation nodes were running a release that did not contain the relevant fix.
Rescue terms should exist before an exploit
Rather than negotiating under pressure after funds have moved, Amador said serious protocols should decide their rescue conditions before an emergency occurs.
“Yes, rescue terms must exist ahead of an exploit,” he said. “All serious protocols should set these in advance.”
Predetermined rules can define which systems researchers may test, how they must disclose a vulnerability, and what actions they can take during an active incident. They can also state the maximum bounty, payment conditions, and legal protections available to researchers who remain within the approved scope.
Immunefi developed the Whitehat Safe Harbor framework to establish such conditions before a protocol faces an attack. Amador, who helped shape the framework and has participated in live exploit response teams, compared emergency action with saving a house from a fire: the need for help does not authorize every possible rescue method.
Advance agreements also give protocol teams a basis for distinguishing approved intervention from coercion. Without prior terms, an actor who controls user funds can demand payment while the project faces losses, service disruptions, and pressure from token holders.
Liquid’s actors initially communicated through messages placed in Bitcoin transactions and told Blockstream to patch the flaw before they returned the funds. After Blockstream confirmed that affected bridge nodes had been patched, the group sent 3,400 BTC back to the federation wallet.
No publicly disclosed agreement had allowed the group to retain the remaining 598.5 BTC. The amount also exceeds 10% of the approximately 4,000 BTC involved, although the reported demand centered on a 10% reward.
The 10% crypto bounty convention still has a role
While rejecting the Liquid actors’ attempt to impose their own terms, Amador defended the crypto industry’s informal practice of offering up to 10% of funds at risk as a whitehat bounty.
Without a common reference point, he said, each settlement would need to be negotiated from the beginning, giving an attacker more leverage during an active incident. A defined percentage gives researchers a legal payment route while allowing a protocol to recover most of the exposed assets.
“Ten percent of a $100M exploit is $10M earned legally, with nobody hunting you afterwards,” Amador said. “The alternative for them is moving nine figures onchain while every forensics firm watches.”
The 10% figure has appeared in several recovery offers, but projects usually state the terms themselves. In August, BTCPay Server supporters backed a reward equal to 10% of recovered funds after attackers obtained LND admin macaroon credentials. The proposed payout was capped at 3 BTC if all stolen assets were returned.
Cetus Protocol followed a different formula after its May 2025 exploit. A flaw in its automated market maker logic caused losses of more than $223 million, while the Sui Foundation coordinated with validators to freeze about $163 million. Cetus later announced a $5 million reward for information leading to the identification of the attacker, according to its post-exploit review.
Amador said the reward should generally reach up to 10% of funds at risk while remaining subject to a cap the protocol can afford. Setting the amount too low could make theft more attractive than disclosure, he said, while an excessive payout could leave the rescued project unable to continue operating.
“Price it too high, and paying out can kill the protocol you just saved, which helps nobody,” he said.
Projects may still pay above their stated cap when a report warrants a larger reward, Amador added. Under his proposed model, the protocol retains control over that decision instead of allowing a researcher to establish the fee after taking custody of user assets.
U.S. prosecutions show the risk of unauthorized exploits
For U.S.-based researchers, returning funds or offering to negotiate does not necessarily prevent criminal charges when the original access was unauthorized.
In December 2023, former security engineer Shakeeb Ahmed pleaded guilty to computer fraud after exploiting two decentralized exchanges and obtaining more than $12 million. According to the U.S. Justice Department, Ahmed negotiated with one platform and proposed returning the stolen funds except for $1.5 million if the exchange agreed not to contact law enforcement.
Federal prosecutors said Ahmed later agreed to forfeit more than $12.3 million, including about $5.6 million in fraudulently obtained cryptocurrency. In April 2024, a federal judge sentenced him to three years in prison and ordered the forfeiture of the stolen assets.
Source link



