• CONTACT
  • MARKETCAP
Coin  Deskk
  • BOOKMARKS
  • What’s New
  • Cryptocurrency
  • Pages
    • Contact Us
    • Search Page
    • Customize Interests
    • My Bookmarks
  • Home Coin
  • Home Coin
Reading: Liquid Network attacker crossed into theft: Immunefi CEO
Share
Coin  DeskkCoin  Deskk
Font ResizerAa
  • Home
  • Crypto
  • Market
  • Blockchain
  • Contact
Search
© 2026 Coindeskk News Network. All Rights Reserved.
What's New

Liquid Network attacker crossed into theft: Immunefi CEO

Crypto
Last updated: September 22, 2026 2:08 am
Crypto
Published: September 22, 2026
Share
Liquid Network attacker crossed into theft: Immunefi CEO

Immunefi CEO Mitchell Amador has said the Liquid Network attackers lost any claim to white-hat status by retaining 598.5 BTC after returning 3,400 BTC from the roughly 4,000 BTC exploit. Summary Roughly 598.5 BTC remains with the attackers after they returned 3,400 BTC. Amador said coordinated disclosure ends when a researcher sets rescue terms without prior approval. Protocols should establish rescue rules and bounty limits before an exploit occurs. Immunefi’s CEO defended the 10% bounty convention when teams approve it in advance. Immunefi founder and CEO Mitchell Amador told crypto.news that moving user assets without permission cannot be treated as a rescue when the researcher later keeps part of the funds or sets payment terms. “Coordinated disclosure ends the moment you set the terms yourself,” Amador said. “The money was never yours to save, so moving it is not a rescue.” His comments address the dispute left by the Liquid Network incident, in which unidentified actors withdrew roughly 4,000 BTC, valued at about $320 million at the time, before describing themselves as whitehats. They returned 3,400 BTC after Blockstream patched the affected bridge nodes but retained 598.5 BTC. Blockstream has rejected the group’s demand for a 10% bounty and has said it will not pay for the return of the remaining Bitcoin. The company also rejected the attackers’ claim that the operation amounted to responsible disclosure. Liquid Network attackers could not set their own terms Amador said a security researcher must use private disclosure channels, preferably through a defined bug bounty program, instead of taking assets and negotiating a reward afterward. “Keep a dollar of user funds, and it is theft, whatever the intent was at the outset. The path for a researcher is private disclosure, ideally within a well-defined program.” The distinction rests on authorization rather than the researcher’s stated motive. Under Amador’s view, finding a real vulnerability does not give someone the right to move user assets, hold them as collateral, or decide what compensation is owed. Blockstream took a similar position in its Sept. 11 response. As previously reported by crypto.news, the company said taking assets without permission and refusing to return them constituted theft rather than whitehat work. The company said its earlier discussions with the actors were intended to recover user funds and protect the Bitcoin community. According to Blockstream, engaging in those talks did not mean it had accepted either the withdrawal or the later bounty demand. A technical review of the exploit found that a cache-key collision in the confidential transaction verification logic allowed the actors to create unbacked L-BTC. They then used SideSwap’s peg-out service to obtain real Bitcoin from the federation reserve. Federation keys were not compromised, according to Blockstream. The incident instead involved verification logic in the Elements codebase, while the federation nodes were running a release that did not contain the relevant fix. Rescue terms should exist before an exploit Rather than negotiating under pressure after funds have moved, Amador said serious protocols should decide their rescue conditions before an emergency occurs. “Yes, rescue terms must exist ahead of an exploit,” he said. “All serious protocols should set these in advance.” Predetermined rules can define which systems researchers may test, how they must disclose a vulnerability, and what actions they can take during an active incident. They can also state the maximum bounty, payment conditions, and legal protections available to researchers who remain within the approved scope. Immunefi developed the Whitehat Safe Harbor framework to establish such conditions before a protocol faces an attack. Amador, who helped shape the framework and has participated in live exploit response teams, compared emergency action with saving a house from a fire: the need for help does not authorize every possible rescue method. Advance agreements also give protocol teams a basis for distinguishing approved intervention from coercion. Without prior terms, an actor who controls user funds can demand payment while the project faces losses, service disruptions, and pressure from token holders. Liquid’s actors initially communicated through messages placed in Bitcoin transactions and told Blockstream to patch the flaw before they returned the funds. After Blockstream confirmed that affected bridge nodes had been patched, the group sent 3,400 BTC back to the federation wallet. No publicly disclosed agreement had allowed the group to retain the remaining 598.5 BTC. The amount also exceeds 10% of the approximately 4,000 BTC involved, although the reported demand centered on a 10% reward. The 10% crypto bounty convention still has a role While rejecting the Liquid actors’ attempt to impose their own terms, Amador defended the crypto industry’s informal practice of offering up to 10% of funds at risk as a whitehat bounty. Without a common reference point, he said, each settlement would need to be negotiated from the beginning, giving an attacker more leverage during an active incident. A defined percentage gives researchers a legal payment route while allowing a protocol to recover most of the exposed assets. “Ten percent of a $100M exploit is $10M earned legally, with nobody hunting you afterwards,” Amador said. “The alternative for them is moving nine figures onchain while every forensics firm watches.” The 10% figure has appeared in several recovery offers, but projects usually state the terms themselves. In August, BTCPay Server supporters backed a reward equal to 10% of recovered funds after attackers obtained LND admin macaroon credentials. The proposed payout was capped at 3 BTC if all stolen assets were returned. Cetus Protocol followed a different formula after its May 2025 exploit. A flaw in its automated market maker logic caused losses of more than $223 million, while the Sui Foundation coordinated with validators to freeze about $163 million. Cetus later announced a $5 million reward for information leading to the identification of the attacker, according to its post-exploit review. Amador said the reward should generally reach up to 10% of funds at risk while remaining subject to a cap the protocol can afford. Setting the amount too low could make theft more attractive than disclosure, he said, while an excessive payout could leave the rescued project unable to continue operating. “Price it too high, and paying out can kill the protocol you just saved, which helps nobody,” he said. Projects may still pay above their stated cap when a report warrants a larger reward, Amador added. Under his proposed model, the protocol retains control over that decision instead of allowing a researcher to establish the fee after taking custody of user assets. U.S. prosecutions show the risk of unauthorized exploits For U.S.-based researchers, returning funds or offering to negotiate does not necessarily prevent criminal charges when the original access was unauthorized. In December 2023, former security engineer Shakeeb Ahmed pleaded guilty to computer fraud after exploiting two decentralized exchanges and obtaining more than $12 million. According to the U.S. Justice Department, Ahmed negotiated with one platform and proposed returning the stolen funds except for $1.5 million if the exchange agreed not to contact law enforcement. Federal prosecutors said Ahmed later agreed to forfeit more than $12.3 million, including about $5.6 million in fraudulently obtained cryptocurrency. In April 2024, a federal judge sentenced him to three years in prison and ordered the forfeiture of the stolen assets.

Google and PayPal back crypto rails for AI agents
There's still time for an altcoin rally in 2025: Sygnum
Ethereum price struggles near $2,200 as downside risks grow
StablecoinX holds 20% of ENA supply as shares jump 12%
Unlock Insider Secrets: Coinbase Reveals Shocking Truth Behind Token Listings Now!

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Tokenized stocks may see limited U.S. demand: TD Cowen Tokenized stocks may see limited U.S. demand: TD Cowen
Next Article 0G launches liquid staking gateway for AI compute credits 0G launches liquid staking gateway for AI compute credits

Follow US

Find US on Socials
FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
A16z Delves Deep: $70m Bet on EigenLayer Before EigenCloud Takes Off
A16z Delves Deep: $70m Bet on EigenLayer Before EigenCloud Takes Off
Shiba Inu Plunges: Will It Survive This Critical Test?
Shiba Inu Plunges: Will It Survive This Critical Test?
Solana Breaks Limits: Prepare for Unstoppable Blockchain Revolution Ahead
Solana Breaks Limits: Prepare for Unstoppable Blockchain Revolution Ahead

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin  Deskk

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

© Coindeskk News Network. All Rights Reserved.