BTCBTC$85,372-0.84%|
ETHETH$2,715.75-1.63%|
USDTUSDT$0.99970-0.00%|
BNBBNB$777.9900-1.66%|
XRPXRP$1.5600+1.28%|
USDCUSDC$0.99978-0.00%|
SOLSOL$116.6700-0.78%|
TRXTRX$0.34157-1.17%|
ZECZEC$1,629.33+6.91%|
FIGR_HELOCFIGR_HELOC$1.0310+1.75%|
HYPEHYPE$94.6700-1.27%|
DOGEDOGE$0.09900-1.14%|
XMRXMR$564.4100-2.89%|
WBTWBT$85.7500-1.09%|
USDSUSDS$0.99982-0.01%|
LINKLINK$12.6600-3.55%|
ADAADA$0.24859-0.79%|
RAINRAIN$0.01272-5.88%|
LEOLEO$8.9800-0.06%|
XLMXLM$0.21222-0.28%|
BCHBCH$354.6400+11.35%|
NEARNEAR$4.6800+1.62%|
UNIUNI$9.6000+0.02%|
USDEUSDE$0.99967+0.01%|
LTCLTC$61.9100+0.29%|
AVAXAVAX$10.6800-2.01%|
DAIDAI$0.99973-0.02%|
CCCC$0.11227-5.55%|
USD1USD1$0.99921+0.00%|
HBARHBAR$0.09424-1.09%|
BTCBTC$85,372-0.84%|
ETHETH$2,715.75-1.63%|
USDTUSDT$0.99970-0.00%|
BNBBNB$777.9900-1.66%|
XRPXRP$1.5600+1.28%|
USDCUSDC$0.99978-0.00%|
SOLSOL$116.6700-0.78%|
TRXTRX$0.34157-1.17%|
ZECZEC$1,629.33+6.91%|
FIGR_HELOCFIGR_HELOC$1.0310+1.75%|
HYPEHYPE$94.6700-1.27%|
DOGEDOGE$0.09900-1.14%|
XMRXMR$564.4100-2.89%|
WBTWBT$85.7500-1.09%|
USDSUSDS$0.99982-0.01%|
LINKLINK$12.6600-3.55%|
ADAADA$0.24859-0.79%|
RAINRAIN$0.01272-5.88%|
LEOLEO$8.9800-0.06%|
XLMXLM$0.21222-0.28%|
BCHBCH$354.6400+11.35%|
NEARNEAR$4.6800+1.62%|
UNIUNI$9.6000+0.02%|
USDEUSDE$0.99967+0.01%|
LTCLTC$61.9100+0.29%|
AVAXAVAX$10.6800-2.01%|
DAIDAI$0.99973-0.02%|
CCCC$0.11227-5.55%|
USD1USD1$0.99921+0.00%|
HBARHBAR$0.09424-1.09%|
News/Security
Security

They Returned 3,400 BTC and Kept 598.5. That's the Whole Case.

Bitnxt TeamWritten by : Bitnxt Team
September 21, 20265 min read
Bitcoin vault showing 3,400 BTC returned and 598.5 BTC kept in a crypto case.

Summary :

  • Immunefi CEO Mitchell Amador says the Liquid Network attackers became thieves the moment they kept 598.5 BTC after returning 3,400 BTC.

  • Amador: "Coordinated disclosure ends the moment you set the terms yourself."

  • He says protocols should define rescue terms and bounty caps before an exploit happens, not during one.

  • The 10% bounty convention still has a role, but only when the protocol sets it in advance.

  • Blockstream has rejected the 10% demand and refuses to pay for the remaining Bitcoin.

The Liquid Network attackers returned 3,400 BTC and kept 598.5, and Immunefi's CEO has now drawn the line the industry has been circling for two weeks: that second number converts the whole operation from rescue into theft. Mitchell Amador, founder and CEO of the bug bounty platform, told Bitnxt's news desk the attackers' white-hat claim collapsed the moment they set their own terms. "Coordinated disclosure ends the moment you set the terms yourself," Amador said. "The money was never yours to save, so moving it is not a rescue." His framing matters beyond one incident, because it arrives as crypto's biggest exploit of the year has hardened into a standoff: unidentified actors withdrew roughly 4,000 BTC, worth about $320 million at the time, called themselves whitehats, returned most of it, and are demanding a 10% bounty on the rest that Blockstream has refused to pay.

Why the Liquid Network case turned on the kept Bitcoin

The technical record is settled. A cache-key collision in the confidential transaction verification logic let the actors create unbacked L-BTC, which they converted into real Bitcoin through SideSwap's peg-out service from the federation reserve. Federation keys were never compromised; the flaw lived in the Elements codebase's verification logic, on federation nodes running a release without the relevant fix. The moral question is what happened afterward. The actors communicated through messages embedded in Bitcoin transactions, told Blockstream to patch the flaw, and returned 3,400 BTC once the bridge nodes were patched. No agreement allowed them to keep anything, and the retained 598.5 BTC exceeds even the 10% of roughly 400 BTC a bounty convention would imply on the amount returned. Blockstream's Sept. 11 position was categorical: taking assets without permission and refusing to return them is theft, whatever the label, and its earlier talks with the actors were recovery efforts, not acceptance of their terms.

Amador's standard is authorization, not motive. Finding a real vulnerability grants no right to move user assets, hold them as collateral, or decide the compensation owed, and the path for a researcher is private disclosure, ideally within a defined program. "Keep a dollar of user funds, and it is theft, whatever the intent was at the outset," he said. The U.S. legal system agrees, which is why the attackers' retained haul is so costly for them: Shakeeb Ahmed exploited two decentralized exchanges, negotiated to return funds minus $1.5 million, and still pleaded guilty to computer fraud, forfeited more than $12.3 million and received a three-year federal sentence. Returning money does not launder the access, and forensics firms are already tracing the kind of onchain movements that previously unraveled multi-country laundering networks.

Rescue terms belong before the emergency

Amador's constructive argument is that this standoff was structurally avoidable. "Yes, rescue terms must exist ahead of an exploit," he said. "All serious protocols should set these in advance." Predetermined rules define which systems researchers may test, how they must disclose, what actions are allowed during an active incident, and the maximum bounty, payment conditions and legal protections for researchers who stay within scope. Immunefi built its Whitehat Safe Harbor framework for exactly this, and Amador compares it to saving a house from a fire: the need for help does not authorize every possible rescue method. Without prior terms, an actor holding user funds can demand payment while the project bleeds, which is the negotiating position the Liquid actors constructed for themselves by withdrawing first and discussing ethics later.

Notably, Amador defended the informal 10% convention itself, provided the protocol sets it. Without a reference point, every settlement is negotiated from zero with an attacker holding leverage; with one, a researcher has a legal payment route and the protocol recovers most of its assets. "Ten percent of a $100M exploit is $10M earned legally, with nobody hunting you afterwards," he said. "The alternative for them is moving nine figures onchain while every forensics firm watches." The precedent is consistent: BTCPay Server's supporters backed a 10% reward capped at 3 BTC after an August credential theft, and Cetus froze about $163 million with validators and offered $5 million for attacker identification rather than let a thief dictate terms. Price the bounty too low and theft beats disclosure, Amador noted; too high and the payout kills the protocol it saved.

What the standoff decides

Watch two things now. First, whether the 598.5 BTC ever moves, because each transfer creates forensic surface, and the trail from a $320 million exploit is the most watched set of addresses in the industry right now, infrastructure whose cross-chain settlement surface researchers already scrutinize for single points of failure. Second, whether serious protocols actually adopt pre-agreed rescue terms, because Amador's framework only helps the teams that sign up before the fire. The Liquid incident's lasting lesson cuts both ways: the attackers proved a patched bug and returned funds do not erase unauthorized access, and the industry proved it still has no standard answer when someone takes first and negotiates second. The 598.5 BTC is the tuition for writing that standard now.

#Liquid Network#Immunefi#Blockstream#Whitehat#Bug Bounty#Exploit#Bitcoin
Bitnxt Team

Author

Bitnxt Team

Crypto News Writer · Bitnxt

Covering the latest developments in cryptocurrency, blockchain technology, and digital asset markets.

Share: