Liquid Network’s $47M White-Hat Question: Who Decided the Price of the Rescue?
0
0

A self-proclaimed white-hat hacker has returned 3,400 BTC to Liquid Network’s federation wallet after Blockstream confirmed its vulnerability had been patched. But nearly $47 million in Bitcoin remains in the actor’s hands — and no public bounty agreement explains why.
The 598.5 BTC still under the actor’s control represents about 15% of the roughly 4,000 BTC withdrawn from the federation wallet on September 6. No public statement from Blockstream or the Liquid Federation has confirmed that the retained Bitcoin was formally offered as a reward.
The return followed a series of on-chain messages between the hacker and Blockstream. The messages discussed fixing the vulnerability and patching the network’s nodes, but did not publicly specify a ransom or bounty amount.
The decision to keep 598.5 BTC has drawn scrutiny from industry observers. Charles Guilmet, CTO of Ledger, noted on X that the remaining funds were still under the control of the self-proclaimed white hat.
He suggested that if the funds were being withheld as leverage in an on-chain cryptographic arrangement, the conduct could resemble blackmail more than conventional white-hat security work.
Others in the crypto community have also questioned the “white hat” label. They argue that conventional security researchers typically disclose vulnerabilities or coordinate with affected projects before moving large amounts of funds. No formal bug-bounty agreement covering the retained 598.5 BTC has been publicly released by Blockstream or the Liquid Federation.
Bitcoin developer and open-source contributor Miguel Medeiros summed up the drama sarcastically, calling it the “Best telenovela of 2026” and saying, “It was better than Breaking Bad.”
Liquid’s bridge nodes remain disabled as of September 8, while deposits and withdrawals of L-BTC remain suspended across multiple exchanges.
Blockstream said updated software has been deployed and that Federation members are preparing for a coordinated network restart.
Liquid Network’s hack case is not without precedent in the crypto industry. In several high-profile incidents, hackers who returned most of the stolen funds were allowed to keep a portion as a so-called white-hat bounty.
In the 2022 Team Finance exploit, an attacker returned about $13.4 million of the $15.8 million stolen and kept roughly 10%, while in the 2023 SafeMoon hack, the attacker agreed to return 80% of nearly $9 million and retain the remaining 20% as a bounty.
Similar arrangements have also occurred in the Nomad bridge hack, where the project explicitly offered a 10% bounty to anyone returning at least 90% of the funds, and in a 2024 address-poisoning case involving roughly $72 million in wrapped Bitcoin, where the attacker agreed to return 90% while keeping 10%. More recently, GMX and Renegade have also used 10% white-hat bounty arrangements.
Crypto has precedent for white-hat hackers keeping part of recovered funds — but such arrangements are typically negotiated or explicitly offered as bounties.
Liquid Network’s case stands out because the hacker retained about 15% of the funds, or 598.5 BTC, with no publicly disclosed agreement specifying a bounty.
That leaves the central question: was the retained Bitcoin a negotiated reward — or simply Bitcoin the hacker chose to keep?
Explore DailyCoin’s top crypto news right now:
Zcash Price Surges 2,496% as Privacy Becomes the Trade of the Year
Cardano Bulls Brace Themselves For a Bounce To $0.50
0
0
Securely connect the portfolio you’re using to start.





