Mitchell Amador’s Stance on Liquid Network Attackers
Mitchell Amador, the CEO of Immunefi, has expressed strong views regarding the actions of the attackers of the Liquid Network. He stated that their retention of 598.5 BTC disqualifies them from being considered white-hat hackers. According to Amador, the attackers’ decision to return only 3,400 BTC out of approximately 4,000 BTC stolen while keeping a substantial portion of the funds undermines any claims to acting altruistically.
Unauthorized Movement of User Assets
In an interview with Crypto News, Amador emphasized that unauthorized movement of user assets cannot be construed as a rescue, especially when the individual involved later sets conditions for a reward or remains in possession of a share of the stolen funds. He articulated that the concept of coordinated disclosure—a common practice in the cybersecurity domain—ceases once one party dictates their terms. He stated:
“The money was never yours to save; thus, moving it is not an act of rescue.”
This reflects the significant controversies following the Liquid Network incident, where the unidentified assailants withdrew around 4,000 BTC, valued at approximately $320 million at the time, and then proclaimed themselves as ethical hackers.
Blockstream’s Response
After Blockstream, the company managing Liquid Network, addressed the issue by fixing the vulnerabilities in the affected nodes, it received 3,400 BTC in return but denied the attackers’ claim for a 10% bounty on the total amount stolen. Blockstream firmly rebuffed the notion that the operation was a case of responsible disclosure. Amador reiterated that true security researchers should utilize private reporting channels within a formal bug bounty program instead of taking user assets and later negotiating for rewards. He maintained that – regardless of intent – retaining any user money equates to theft.
“A security researcher should not move user assets, hold them as collateral, or dictate owed compensation just by identifying a genuine flaw in the system.”
Need for Predefined Rescue Terms
In response to this incident, Blockstream stated that their earlier communications with the alleged attackers were focused on recovering user funds and safeguarding the Bitcoin ecosystem. They clarified that engaging in discussions did not imply acceptance of the withdrawal or the subsequent demands for a bounty. In a technical analysis of the incident, it was discovered that a collision in the cache-key within the confidential transaction verification mechanism allowed the attackers to create unsupported L-BTC, which they successfully converted to real Bitcoin utilizing SideSwap’s peg-out service. Importantly, Blockstream confirmed that federation keys were not compromised, as the incident stemmed from a flaw in the Elements codebase while federation nodes ran an outdated version missing essential fixes.
Amador also voiced the necessity for protocols involved in cryptocurrency to establish predefined rescue terms prior to any hacking event, arguing that having such conditions prevents pressure-driven negotiations following a breach. He likened the procedure to fire rescue efforts—while the need for assistance may be apparent, it does not permit unregulated methods of resolution. Consequently, protocols should outline clear parameters for what constitutes authorized testing, how vulnerabilities should be disclosed, as well as the maximum bounty and legal protections for compliant researchers.
Immunefi’s Whitehat Safe Harbor Framework
Immunefi has introduced the Whitehat Safe Harbor framework to preemptively set these standards. Such measures ensure that protocol teams can differentiate between sanctioned interventions and coercive tactics deployed during a security crisis. Following the Liquid attack, the assailants initially conveyed their demands through Bitcoin transaction messages, instructing Blockstream to rectify the flaws prior to returning any funds. However, after the corrective actions were confirmed, the group returned 3,400 BTC but retained 598.5 BTC—a sum exceeding the 10% bounty they sought.
Industry Standards and Legal Accountability
Amador’s advocacy for a uniform standard offering up to a 10% bounty from recovered stolen funds is indicative of broader industry practices. Without established norms, he warned that each recovery offer could become a matter of individual negotiations, giving attackers undue advantage. This industry standard aims to provide a legal route for compensation while enhancing the likelihood of recovering the majority of at-risk assets. Drawing on parallels from various incidents, he cited that payments of up to 10% of stolen funds should remain feasible without jeopardizing the project’s sustainability following a crisis.
Additionally, he reminded researchers in the U.S. that returning stolen assets or negotiating with victims does not shield them from criminal accountability if the original appropriation lacked authorization. This was starkly illustrated by the case of Shakeeb Ahmed, a former security engineer who was sentenced for fraud after exploiting decentralized exchanges and negotiating terms to return part of the funds but still facing prosecution.
Conclusion
As Amador continues to shape the conversation around ethical practices in crypto security, the need for clear guidelines and legal protections has never been more evident. Overall, these events underscore the ongoing debate about the ethics of cryptocurrency security practices and the complex dynamics between risk, recovery, and the boundaries of hacker incentive structures.