Liquid Network's $47M Mystery: Was It a White-Hat Bounty or Extortion?
A hacker who returned most of the Bitcoin stolen from Liquid Network is keeping nearly $47 million in funds without any publicly disclosed agreement explaining why, sparking debate over whether the arrangement qualifies as legitimate white-hat security work or something closer to extortion. On September 6, an attacker withdrew approximately 4,000 BTC (Bitcoin) from Liquid Network's federation wallet, a critical infrastructure component that manages the network's wrapped Bitcoin (L-BTC). The hacker then returned 3,400 BTC after Blockstream, the technical provider behind Liquid, confirmed it had patched the underlying vulnerability. However, the actor retained 598.5 BTC, roughly 15 percent of the total stolen amount, with no formal bounty agreement made public by Blockstream or the Liquid Federation.
What Exactly Happened During the Liquid Network Incident?
The sequence of events unfolded over approximately 27 hours. On September 6, the attacker exploited a vulnerability in Liquid's federation wallet and moved 4,000 BTC out of the network's control. What followed was an unusual back-and-forth: the hacker and Blockstream exchanged on-chain messages using PGP signatures and OP_RETURN transactions, a method of embedding data directly into the Bitcoin blockchain. These messages discussed fixing the vulnerability and patching the network's nodes, but they did not publicly specify a ransom or bounty amount. By September 7, the hacker had returned 3,400 BTC to Liquid's federation wallet, and Blockstream confirmed the network's software had been updated and deployed.
As of September 8, Liquid's bridge nodes remained disabled, and deposits and withdrawals of L-BTC were suspended across multiple exchanges. Blockstream stated that updated software had been deployed and that Federation members were preparing for a coordinated network restart. The 598.5 BTC still under the hacker's control represents the central puzzle: was this amount formally offered as a security researcher's reward, or did the attacker simply decide to keep it ?
Why Are Experts Questioning the "White-Hat" Label?
The term "white-hat hacker" typically refers to a security researcher who discovers vulnerabilities, discloses them responsibly, and works with affected projects to fix them. The Liquid incident has challenged that definition. Charles Guilmet, Chief Technology Officer at Ledger, raised concerns on social media about the arrangement's legitimacy. He noted that if the retained funds were being withheld as leverage in an on-chain cryptographic arrangement, the conduct could resemble blackmail more than conventional white-hat security work.
"If this was ever a negotiated reward under an encrypted contract signed on-chain, it looks more like extortion than white-hat hacking," stated Charles Guilmet, CTO at Ledger.
Charles Guilmet, CTO at Ledger
Other members of the crypto community have questioned the arrangement as well. They argue that conventional security researchers typically disclose vulnerabilities or coordinate with affected projects before moving large amounts of funds. The lack of a formal, publicly released bug-bounty agreement covering the retained 598.5 BTC stands out as unusual compared to how legitimate security programs typically operate.
How Do White-Hat Bounties Typically Work in Crypto?
- Nomad Bridge Model: The Nomad bridge hack explicitly offered a 10 percent bounty to anyone returning at least 90 percent of the stolen funds, creating a clear, transparent incentive structure.
- Team Finance Precedent: In the 2022 Team Finance exploit, an attacker returned approximately $13.4 million of the $15.8 million stolen and kept roughly 10 percent as a negotiated white-hat bounty.
- SafeMoon Agreement: During the 2023 SafeMoon hack, the attacker agreed to return 80 percent of nearly $9 million and retain the remaining 20 percent as a formal bounty arrangement.
- Recent Protocols: GMX and Renegade have also used 10 percent white-hat bounty arrangements with clear terms disclosed to the public.
- Address-Poisoning Case: In a 2024 incident involving roughly $72 million in wrapped Bitcoin, the attacker agreed to return 90 percent while keeping 10 percent, with the arrangement publicly documented.
What distinguishes the Liquid Network case is that the hacker retained approximately 15 percent of the funds with no publicly disclosed agreement specifying a bounty. In nearly every precedent cited in the crypto industry, the terms were either negotiated explicitly or offered as part of a formal bug-bounty program. The absence of such documentation in Liquid's case has left the central question unanswered: was the retained Bitcoin a negotiated reward, or simply Bitcoin the hacker chose to keep ?
What Does the Crypto Community Think About This Arrangement?
The incident has drawn commentary from developers and security observers. Bitcoin developer and open-source contributor Miguel Medeiros remarked on the dramatic nature of the unfolding events, calling it the "Best telenovela of 2026" and comparing it to the television series "Breaking Bad." His observation captured the unusual transparency of the on-chain negotiations, which played out in public view through blockchain transactions and cryptographic signatures.
The lack of clarity around the bounty arrangement has created uncertainty in the broader ecosystem. Blockstream and the Liquid Federation have not released a formal statement explaining whether the 598.5 BTC was formally offered as a reward or whether negotiations are still ongoing. This ambiguity stands in sharp contrast to how other major security incidents have been handled, where projects typically announce bounty terms publicly to maintain trust with users and stakeholders.
What Happens Next for Liquid Network?
Blockstream has indicated that Federation members are preparing for a coordinated network restart once all updated software has been deployed and tested. The suspension of L-BTC deposits and withdrawals across exchanges will likely remain in place until the network is fully operational again. The broader question of how Blockstream and the Liquid Federation will address the retained 598.5 BTC remains unresolved, and any public statement on the matter could significantly impact how the crypto community views the incident's resolution.
The Liquid Network incident serves as a reminder that even when a hacker returns the majority of stolen funds, the terms of such returns matter enormously to the legitimacy of the arrangement. In an industry where trust is paramount, the absence of a clear, publicly disclosed bounty agreement has transformed what might have been a positive security outcome into a source of ongoing controversy and speculation.