Crypto Security
Liquid Network Attacker Crossed Into Theft According to Immunefi CEO Mitchell Amador
Immunefi CEO Mitchell Amador stated that individuals who retained roughly 598.5 BTC after an exploit of the Liquid Network cannot claim white-hat status. The report, based on media reporting and not officially confirmed by an official or first-party source, highlights that coordinated disclosure ends when a researcher sets rescue terms without prior approval.

Incident Overview and Security Context
Recent media coverage details a contentious security incident involving the Liquid Network, where unauthorized actors withdrew approximately 4,000 BTC, representing a substantial financial magnitude at the time. According to the reporting by crypto.news and subsequent commentary by Immunefi chief executive Mitchell Amador, the situation evolved from an initial technical breach into a direct retention of user funds. The actors behind the operation later described their actions as responsible disclosure, returning 3,400 BTC after the relevant bridge nodes were successfully patched by Blockstream developers. However, the subsequent refusal to return the remaining funds triggered intense debate across the digital asset security community regarding the definition of ethical research.
Technical reviews of the underlying vulnerability pointed toward a cache-key collision within the confidential transaction verification logic of the affected codebase. This flaw enabled the unidentified actors to generate unbacked L-BTC tokens, which were subsequently routed through alternative federation peg-out services to obtain native Bitcoin from the reserve. Protocol maintainers clarified that the primary federation keys themselves remained uncompromised during the event, as the issue stemmed directly from verification logic rather than a direct key compromise. Nevertheless, the unauthorized movement and subsequent withholding of user capital prompted severe condemnation from prominent security figures who argue that such behavior violates the fundamental tenets of coordinated vulnerability disclosure.
Dispute Over White-Hat Status and Ransom Terms
The core controversy centers on whether individuals who extract user assets without permission can maintain ethical standing by returning a portion of the stolen funds while setting their own compensation terms. Immunefi CEO Mitchell Amador strongly rejected this premise, stating during interviews that coordinated vulnerability disclosure concludes the moment a researcher unilaterally dictates financial conditions. Emphasizing that user deposits were never intended for unauthorized custody, Amador argued that keeping any fraction of the extracted capital transforms the intervention into outright theft, regardless of the initial motivation or the eventual return of the majority balance.
Blockstream maintained an identical stance in its official communications, explicitly rejecting the attackers' demand for a ten percent bounty in exchange for the remaining Bitcoin. The development organization clarified that its prior communications with the unauthorized actors were strictly focused on facilitating the recovery of user assets and safeguarding the broader community rather than negotiating a commercial contract. By refusing to validate the bounty demand, the protocol operators drew a hard line against rewarding individuals who bypass established private reporting channels. This dynamic highlights the persistent vulnerability of decentralized networks to bad actors who exploit emergency situations to extract financial gains under the guise of security assistance.
The Necessity of Pre-Exploit Rescue Frameworks
To mitigate the risks associated with emergency interventions, security leaders advocate for the establishment of predetermined rescue frameworks before protocols deploy to production environments. Amador noted that serious projects should formalize clear guidelines defining permitted testing boundaries, authorized disclosure workflows, and predetermined bounty caps. Having these parameters in place prevents attackers from seizing control of the narrative during a live incident and protects projects from being coerced into paying exorbitant rewards while experiencing operational disruptions and intense public pressure.
Frameworks such as Immunefi’s Whitehat Safe Harbor initiative provide a structured mechanism for protocols to establish legal and operational boundaries ahead of time. By comparing emergency asset recovery to extinguishing a house fire, experts explain that the urgency of a situation does not automatically grant immunity or authorize unregulated intervention methods. Advance agreements create a transparent legal basis that allows project teams to distinguish genuine white-hat assistance from opportunistic coercion, ultimately fostering a more secure operational environment for decentralized finance participants worldwide.
Industry Bounties and Legal Consequences
Despite condemning the unauthorized actions of the Liquid Network actors, industry stakeholders continue to recognize the practical utility of the ten percent white-hat bounty convention when properly authorized. Amador defended the informal practice by explaining that a standardized reference point prevents negotiations from starting from zero, giving protocols a structured mechanism to recover exposed assets while offering researchers a legitimate financial incentive. Recent examples across the decentralized ecosystem, such as reward structures implemented by BTCPay Server and Cetus Protocol, demonstrate that clear bounty caps help maintain project solvency while discouraging malicious exploitation.
However, legal precedents underscore the severe dangers of conducting unauthorized exploits under the assumption that returning funds will exempt individuals from criminal prosecution. Federal cases, such as the prosecution of former security engineer Shakeeb Ahmed for decentralized exchange exploits, illustrate that U.S. authorities and law enforcement agencies treat unauthorized fund extraction as computer fraud regardless of subsequent negotiation attempts or partial restitutions. Prosecutors routinely seek substantial asset forfeitures and prison sentences, reinforcing the principle that security research must remain strictly authorized and confined to established private disclosure channels.
Conclusion, Findings, and Next Steps
In conclusion, media reporting indicates that the Liquid Network security incident has highlighted critical vulnerabilities in how protocols handle emergency interventions and asset recovery demands. Based on media reporting and not officially confirmed by an official or first-party source, Immunefi CEO Mitchell Amador concluded that the retention of 598.5 BTC by unidentified actors constitutes theft rather than responsible disclosure. The affected entity in this reported dispute is Blockstream, alongside the broader user community dependent on the Liquid Network infrastructure. What changes now is the heightened urgency for protocol developers across the cryptocurrency ecosystem to establish explicit pre-exploit rescue frameworks and robust bug bounty parameters to prevent similar controversies.
The next action for industry participants and developers is to conduct thorough audits of verification logic in their codebase while formally adopting secure harbor guidelines to protect against unauthorized extractions. Stakeholders must clearly separate what has been reported by media outlets regarding the attacker negotiations from what remains unconfirmed by official protocol disclosures. Protocol maintainers are strongly advised to review their existing emergency response protocols, ensure rigorous authorization controls are in place, and consult legal counsel to navigate potential security incidents effectively without compromising user trust.
Cexvia conclusion
Conclusion and Next Steps
According to media reporting, Immunefi CEO Mitchell Amador stated that retaining funds from the Liquid Network incident constitutes theft rather than ethical hacking. This claim, which remains not officially confirmed by the affected protocol team, affects Blockstream and participating users involved in the approximately 4,000 BTC exploit.
- Risk meaning
- Unauthorized asset extraction under the guise of rescue creates severe legal and security hazards for digital asset protocols, undermining trust in the ecosystem and blurring the line between security research and criminal behavior.
- User action
- Digital asset participants and stakeholders should review protocol security frameworks, verify whether emergency rescue procedures are pre-established, and exercise caution when interacting with cross-chain bridges.

