Immunefi founder and CEO Mitchell Amador says the unidentified actors behind the Liquid Network drain crossed the line from rescue into theft when they retained 598.5 BTC after returning 3,400 BTC of the roughly 4,000 BTC they withdrew.
"Coordinated disclosure ends the moment you set the terms yourself," Amador told crypto.news. "The money was never yours to save, so moving it is not a rescue." His test is absolute: "Keep a dollar of user funds, and it is theft, whatever the intent was at the outset. The path for a researcher is private disclosure, ideally within a well-defined program."
The Incident, Recapped
In early September, actors withdrew roughly 4,000 BTC — about $319 million at the time, making it 2026's largest hack until the Bitget breach — from the Liquid Network federation, per TRM Labs. A technical review traced the attack to a cache-key collision in the confidential transaction verification logic of the Elements codebase, which allowed unbacked L-BTC to be created and converted to real Bitcoin through SideSwap's peg-out service. Federation keys were not compromised; the affected bridge nodes were running a release that predated the relevant fix.
The actors, who described themselves as white hats and communicated with Blockstream through messages embedded in Bitcoin transactions, returned 3,400 BTC on September 7 after Blockstream patched the affected nodes, per Bitcoin Magazine. About 598.5 BTC — near $47 million — remains at the holder address. The group demanded a 10% bounty; Blockstream rejected the demand and said it will not pay, restating its position on September 11 that taking assets without permission and refusing to return them is theft rather than white-hat work. Notably, 598.5 BTC is roughly 15% of the total withdrawn — above even the demanded 10% convention.
Why Authorization, Not Motive, Decides It
Amador's argument rests on authorization rather than stated intent: finding a real vulnerability does not grant the right to move user assets, hold them as collateral, or decide what compensation is owed. Under that reading, the Liquid actors' sequence — withdraw first, negotiate terms second — fails at the first step, whatever their motive.
The policy prescription he draws is that rescue terms must exist before an exploit, not be improvised during one. "Yes, rescue terms must exist ahead of an exploit," he said. "All serious protocols should set these in advance." Immunefi's Whitehat Safe Harbor framework is built for exactly that: pre-agreed rules defining what researchers may test, how they must disclose, what they may do during an active incident, and the maximum bounty and legal protections for those who stay within scope.
The 10% Convention Survives — With Conditions
Amador simultaneously defended the industry's informal convention of paying white hats up to 10% of funds at risk, provided the protocol — not the asset-holder — sets the terms. A known reference point prevents each settlement from being renegotiated under pressure, gives researchers a legal payment route, and lets the protocol recover most of the exposed assets. "Ten percent of a $100M exploit is $10M earned legally, with nobody hunting you afterwards," he said. "The alternative for them is moving nine figures onchain while every forensics firm watches."
The unresolved 598.5 BTC makes Liquid the clearest test case yet of where the industry's line sits. Blockstream's refusal to pay and Amador's framing both point in the same direction: disclosure channels and bounty ceilings agreed in advance, and self-appointed rescues priced by the rescuer treated as what they look like on-chain — unauthorized transfers.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.