The hackers who drained roughly 4,000 BTC from the Liquid Network have lost any claim to being “white hat” researchers, according to Immunefi CEO Mitchell Amador, because they kept 598.5 BTC for themselves after returning 3,400 BTC. In an interview with crypto.news on Sept. 21, the founder of the crypto industry’s largest bug bounty platform drew a hard line: once you set your own price for returning stolen money, you are no longer a rescuer.
By Marcus Johnson | September 21, 2026
The Hook: When Is a Hack Not a Hack?
Here is the strange situation Bitcoin investors found themselves in this month. Unidentified actors exploited a bug in the Liquid Network — a Bitcoin sidechain built by Blockstream — and withdrew roughly 4,000 BTC, worth about 320 million USD at the time. Then, instead of vanishing, they called themselves white hats: ethical hackers who find flaws and return funds. They even returned 3,400 BTC after Blockstream patched the affected bridge nodes. The catch? They kept 598.5 BTC and demanded a 10 percent bounty for the rest.
Blockstream has refused to pay and has rejected the group’s claim that the operation amounted to responsible disclosure. Now Amador, whose company Immunefi connects security researchers with crypto projects, has weighed in — and his verdict matters for anyone holding Bitcoin on sidechains or bridges.
On-Chain Evidence: How the Exploit Actually Worked
A technical review of the incident found the attackers abused a cache-key collision in the confidential transaction verification logic — a subtle software flaw that let them create unbacked L-BTC, the wrapped Bitcoin used on the Liquid Network. Think of it like forging a warehouse receipt for gold that was never deposited. They then used SideSwap’s peg-out service to exchange the fake receipts for real Bitcoin from the federation’s reserve.
Importantly, the federation’s security keys were never compromised. The bug lived in the verification logic of the Elements codebase, and some federation nodes were running a release that had not yet included the fix. The attackers communicated with Blockstream through messages embedded directly in Bitcoin transactions, telling the company to patch the flaw before they returned most of the funds.
- 4,000 BTC — total amount withdrawn in the exploit, worth about 320 million USD at the time
- 3,400 BTC — returned after Blockstream patched the affected bridge nodes
- 598.5 BTC — still held by the attackers, which exceeds 10 percent of the total involved
The Core Conflict: You Cannot Set Your Own Reward
“Coordinated disclosure ends the moment you set the terms yourself,” Amador told crypto.news. “The money was never yours to save, so moving it is not a rescue.”
Under this view, finding a real vulnerability does not give anyone the right to move user assets, hold them as collateral, and then decide what compensation is owed. “Keep a dollar of user funds, and it is theft, whatever the intent was at the outset,” Amador said. “The path for a researcher is private disclosure, ideally within a well-defined program.”
There is also a legal reality check. In December 2023, former security engineer Shakeeb Ahmed pleaded guilty to computer fraud after exploiting two decentralized exchanges for more than 12 million USD. He had offered to return the funds minus 1.5 million USD if the exchange agreed not to contact law enforcement. He was sentenced to prison anyway and agreed to forfeit more than 12.3 million USD. Returning the money did not erase the crime of taking it without permission.
Market Implications: Why a 10 Percent Bounty Still Makes Sense
Interestingly, Amador is not against paying hackers. He defended the crypto industry’s informal convention of offering up to 10 percent of funds at risk as a reward for responsible disclosure. Without a common reference point, every settlement would be negotiated under pressure, giving attackers more leverage while a project bleeds.
“Ten percent of a 100 million USD exploit is 10 million USD earned legally, with nobody hunting you afterwards,” Amador said. “The alternative for them is moving nine figures onchain while every forensics firm watches.”
The precedent exists. In August, BTCPay Server supporters backed a reward equal to 10 percent of recovered funds after attackers stole Bitcoin using leaked admin credentials, capped at 3 BTC. After its May 2025 exploit, Cetus Protocol announced a 5 million USD reward for information identifying the attacker. The pattern is consistent: rewards work when the project sets the terms in advance — not when an attacker demands payment after the fact.
The Verdict: What This Means for Your Bitcoin
For regular investors, the lesson is straightforward. Bitcoin itself was never touched — the exploit hit a sidechain’s verification software, not the main network. But if you hold wrapped or bridged versions of BTC, you are trusting extra layers of code beyond the base chain. Bitcoin trades around 86,511 USD at the time of writing, up more than 6 percent on the day, and the broader market has largely shrugged off the Liquid incident.
The deeper takeaway from Amador’s comments is for the industry itself: serious protocols should publish rescue terms before an emergency, not negotiate them during one. Immunefi’s Whitehat Safe Harbor framework exists for exactly this reason. Until that becomes standard practice, the line between hacker and hero will keep being decided after the money has already moved.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
They kept 598.5 BTC and still demanded a 10 percent bounty on the rest. That is a ransom with a press kit, not white hat work.
Exactly. A finder fee bigger than a decade of legit bug bounty payouts. Amador is right to draw a hard line here.
Amador has skin in this game, Immunefi lives off clean bounty flows. But forging L-BTC via a cache-key collision is counterfeiting, not research.
The SideSwap peg-out before returning funds is the detail that convinced me. They cashed out first, then played hero.
cashing out through SideSwap before returning the rest is the timeline that ends any white hat debate. sequencing tells you everything
counterfeiting is the right word. forging L-BTC via a cache key collision creates claims on bitcoin that never existed. that is not a finding, its minting
Amador draws the line exactly right: 598.5 BTC kept is a negotiation fee, plain and simple. white hats do not invoice 48 million dollars
^ exactly. the moment you set your own price for returning stolen money you are just a thief with a PR plan
48 million dollar negotiation fee is the framing that should stick. immunefi pays low seven figures at best for criticals on that scale. they left a 50x gap and called it generosity
the 50x gap versus standard bounty rates is the cleanest way to frame it. no legit researcher prices their own fee after the withdrawal
the 50x math is being generous tbh. keeping 598.5 BTC alone dwarfs any legit bounty, and the SideSwap cashout stop happened before any negotiation attempt. intent was clear from block one
the 50x math is being generous tbh. keeping 598.5 BTC alone dwarfs any legit bounty, and the SideSwap cashout stop happened before any negotiation attempt. intent was clear from block one
Blockstream got 3,400 BTC back and skipped a court battle that goes nowhere across jurisdictions. Ugly outcome but rational one.
they patched the bridge nodes after the 4,000 BTC was already gone. that is paying ransom with extra steps, zero heroics involved
the 10 percent bounty demand on top of keeping 598.5 BTC is the detail that kills the white hat story for me. real researchers negotiate before the withdrawal, not after