Immunefi CEO Mitchell Amador highlighted the loss of white-hat status for the perpetrator of the Liquid Network breach. The attacker’s decision to withhold 598.5 BTC out of roughly 4,000 exploited BTC turns the maneuver from security research into pure theft.
The initial exploit allowed the attacker to move around 4,000 BTC, worth approximately $320 million at the time of the incident. The perpetrator subsequently returned 3,400 BTC to the network, but only after Blockstream successfully patched the affected bridge nodes.
The attacker deliberately held back the remaining 598.5 BTC, demanding a 10% bounty payment from the total discovered funds. This unilateral demand prompted Amador to draw a hard line regarding ethical hacker standards.
Authorization Is the Key Differentiator
According to Amador, any initial intent to secure the network is immediately voided when the asset owner’s consent is ignored. Even the discovery of a genuine system vulnerability does not give anyone the right to move user assets, hold them as collateral, or dictate compensation amounts.
“Coordinated disclosure ends the moment you set your own terms. That money was never yours to save, so moving it was never a rescue,” Amador said.
Standard protocol for security researchers requires vulnerability reports to be resolved through private channels. This process is ideally carried out entirely within the scope of a well-defined bug bounty program established before any exploit occurs, not mid-stride.
Blockstream Refuses Compromise
Blockstream responded to the situation with an outright rejection of the attacker’s 10% demand, confirming it will not pay any compensation for the remaining withheld Bitcoin.
The Bitcoin infrastructure developer also officially dismissed the perpetrator’s claim labeling the exploit as responsible disclosure. Blockstream emphasized that taking assets without authorization and refusing to return them fully meets the definition of theft, not a security practice.
A Strict Line on Asset Rescue
The Liquid Network exploit establishes a concrete boundary for network vulnerability disclosure methods. The asset rescue defense is automatically invalidated when the person who discovered the flaw uses user funds to leverage developers.
“Hold back one dollar of user funds, and it is theft, regardless of the original intent. The researcher’s path is private disclosure, ideally within a defined program,” Amador concluded.
Source: crypto.news.
Read also: French Crypto Worker Held Hostage for 3 Hours at Home - Child Injured over โฌ40,000 Access Code
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




