Crypto news report · source clearly identified
Immunefi CEO says Liquid Network attackers forfeited white‑hat claim after keeping 598.5 BTC
Immunefi CEO Mitchell Amador says the Liquid Network attackers lost any claim to white‑hat status by retaining 598.5 BTC after returning 3,400 BTC from the roughly 4,000 BTC exploit.

Immunefi founder and CEO Mitchell Amador told crypto.news that moving user assets without permission cannot be treated as a rescue, even if the actor later returns part of the funds. He said coordinated disclosure ends the moment a researcher sets rescue terms without prior approval.
Background of the Liquid Network incident
Unidentified actors withdrew roughly 4,000 BTC (about $320 million at the time) from the Liquid Network bridge. After Blockstream patched the vulnerable bridge nodes, the group returned 3,400 BTC but kept 598.5 BTC. Blockstream rejected the group’s demand for a 10 % bounty and stated that the remaining Bitcoin was not returned voluntarily.
Amador’s stance on rescue and bounty rules
Amador emphasized that a security researcher must use private disclosure channels, preferably through a defined bug‑bounty program, rather than taking assets and negotiating a reward afterward. He argued that keeping any portion of user funds constitutes theft, regardless of the actor’s stated intent.
He defended the industry’s informal practice of offering up to 10 % of the funds at risk as a bounty, provided the terms are established in advance. According to Amador, a pre‑agreed percentage gives researchers a legal payment route while allowing the protocol to recover most of the exposed assets.
Need for pre‑defined rescue terms
Amador urged protocols to set rescue conditions before an exploit occurs. Such rules would define:
- Which systems researchers may test
- How vulnerabilities must be disclosed
- What actions are permissible during an active incident
- The maximum bounty, payment conditions, and legal protections for approved researchers
Immunefi’s Whitehat Safe Harbor framework is intended to provide these pre‑emptive agreements.
Technical details of the exploit
The attack leveraged a cache‑key collision in the confidential transaction verification logic of the Elements codebase, allowing the actors to create unbacked L‑BTC. They then used SideSwap’s peg‑out service to obtain real Bitcoin from the federation reserve. Federation keys were not compromised; the flaw lay in verification logic, not in the federation nodes themselves.
Legal context
Amador noted that U.S. prosecutions show the risk of criminal liability for unauthorized exploits, even when the attacker attempts to return funds or negotiate a settlement.
Source & attribution
News Source
- Publisher
- crypto.news
- Original date
- September 21, 2026, 7:38 PM
- Original headline
- Liquid Network attacker crossed into theft: Immunefi CEO