
Author: Nancy, PANews
The alarm bells for security in the crypto industry have been sounded once again.
Recently, approximately 4000 BTC from the Bitcoin sidechain Liquid Network were transferred unusually, prompting the project team to urgently suspend operations and publicly negotiate with the attacker on-chain. Ultimately, this white-hat hacker returned most of the funds after the project vulnerability was patched, while keeping approximately $47 million as a bounty.
This might become the most expensive white-hat operation in crypto history to date, but it has also sparked considerable controversy. Some mock that this time the white-hat hacker did not just receive a thank-you email and a hoodie; however, others question whether taking the funds away first and then extracting a massive reward feels more like high-priced extortion dressed in the guise of security.
4000 BTC Nearly Emptied, Liquid Attacker Leaves $47 Million Bounty
Last weekend, while on-chain trading markets were bustling, Blockstream's Liquid Network encountered a significant security incident.
On September 6, an attacker exploited a range-proof vulnerability in Elements software to fraudulently mint approximately 4000 L-BTC that were not backed by real BTC reserves. Subsequently, the attacker withdrew about 3996 BTC through the SideSwap settlement platform via a normal peg-out authorization key channel, valued at around $320 million at the time. This amount represented about 95% of the total reserve, leaving only about 197 BTC remaining in the federal wallet after the transfer.

Liquid subsequently paused network activities and stopped L-BTC deposits and withdrawals. However, this incident did not involve a compromise of the federal wallet's private keys, nor did it involve a breach of the SideSwap system or peg-out authorization keys. Blockstream confirmed that the L-BTC used for this withdrawal actually originated from the Elements software vulnerability.
From the attack flow, before the large-scale fund transfer, the attacker conducted a test transaction of about 2.5 BTC. They then sent approximately 3996 L-BTC to SideSwap's peg-out service. SideSwap destroyed the L-BTC as per normal process and initiated the withdrawal request, while Liquid's federation transferred the corresponding BTC to the designated address based on an effective authorization process.
After the incident, the attacker communicated with Blockstream through an on-chain signed message and sent 1000 satoshis to the federal wallet as a signal, indicating, "We are white-hat hackers; please contact us on-chain." Subsequently, the attacker explicitly requested Blockstream to prioritize patching the vulnerability and ensure all nodes completed the update, promising to safely return most of the funds once the vulnerability was confirmed to be fixed.
Blockstream then responded through an on-chain signed message, "Confirming that the bridging nodes have been patched, and funds can be safely returned."
On September 7, this white-hat hacker ultimately returned 3400 BTC to the Liquid federal wallet, which was equivalent to about 85% of the previously withdrawn funds, while retaining 598.5 BTC as a bounty for the vulnerability. Calculated at market prices at the time, this portion of BTC was worth over $47 million.

For Liquid, the return of 3400 BTC undoubtedly significantly alleviated the crisis of massive withdrawals from the federal wallet reserves. However, since L-BTC is backed 1:1 by real BTC held by the Liquid federation, Liquid still needs to make up for the remaining reserve gap and also address the impact the attack has had on market confidence.
White Hat or Extortion? High Bounty for Vulnerability Sparks Controversy
Bounty programs are typically conventional means to incentivize white-hat hackers to intercept vulnerabilities before they can be exploited. The key controversy regarding Liquid this time is not whether a bounty should be given but rather that the funds had already been transferred, the bounty percentage was determined by the attacker, and the final amount was so high that it could even alter the industry's expectations for vulnerability bounties.
On one hand, many believe the attacker's actions do not conform to the traditional norms of white-hat behavior. Typically, security researchers report vulnerabilities privately to the project team, allowing a certain repair window before receiving the bounty according to platform or project-defined rules. However, in Liquid's case, the attacker first transferred the funds to an address they controlled and then requested Blockstream to patch the vulnerability, demanding that all nodes complete updates; only after confirming the vulnerability was fixed did they return most of the funds.
Of course, some argue that this approach is not entirely unreasonable. The rationale being that once a vulnerability is discovered, there is a risk of it being exploited by other attackers, especially given the accelerated attack pace driven by AI. The attacker transferring the funds to an address they control could, to some extent, be to ensure those funds were not further stolen by others before the vulnerability was patched.
Moreover, compared to previous instances where project teams negotiated bounties with attackers after cryptographic attacks, in the Liquid incident, the bounty size was essentially determined by the attacker themselves. Ledger CTO Charles Guillemet pointed out that if both parties negotiated the bounty through an on-chain signed encrypted agreement, this practice resembled extortion rather than white-hat behavior.
In fact, the issue of the scale of white-hat hackers has existed for quite some time. For instance, in 2024, the crypto security company CertiK discovered a serious vulnerability in the deposit system of the crypto exchange Kraken, where attackers could exploit the incomplete deposit operation to increase account balances and withdraw funds. Kraken subsequently fixed the vulnerability, but during this period, they discovered that relevant CertiK personnel had repeatedly exploited the vulnerability, collectively withdrawing nearly $3 million. Kraken accused the other party of failing to disclose according to white-hat norms and refused refunds regarding fund disposal, claiming their behavior had evolved from security testing into "extortion", and they stated they had contacted law enforcement. CertiK later admitted that the relevant tests were conducted by them and stated that this action aimed to validate whether the vulnerability could facilitate fraudulent deposits and withdrawals and whether it would trigger Kraken’s risk control mechanisms, urging Kraken to cease any threats against white-hat hackers.
On the other hand, the bounty amount in Liquid has also attracted attention. In terms of ratio alone, 15% is not particularly extreme. The crypto industry often offers bounties significantly higher than traditional industry standards, for example, the decentralized stablecoin protocol Usual previously launched a $16 million bounty program, one of the largest in crypto history. However, Liquid's problem lies in that 15% equates to a massive bounty exceeding $47 million, far surpassing the bounty levels in previous cases like Wormhole, GMX, and Cetus.
Of course, some support such a large bounty. The anonymous owner of Bitcoin.org, Cøbra, believes white-hat hackers should receive every penny. He hopes that in the future, such large bounty amounts will become industry standards, ensuring greater safety for all of us. Yu Xuan, the founder of Slow Mist, also believes that in the future, large theft incidents can default to starting at 15%, while smaller incidents can default to 20%, providing immunity and gradually forming industry consensus.
Reflecting on the past, many crypto protocols have offered relatively limited vulnerability bounties, even leading to dissatisfaction among security researchers.
For example, white-hat hacker f4lc0n disclosed in a post on platform X that he found a "serious" level vulnerability in the Injective protocol that could allow over $500 million worth of assets on-chain to be directly withdrawn, but the project team only offered him a $50,000 reward, far below the $500,000 maximum planned for that level. After submitting the report, the Injective team initiated a mainnet upgrade vote the next day, patching the vulnerability. However, f4lc0n stated that the team had been "unreachable" for three months afterward, and the $50,000 bounty had yet to be paid. Injective's engineering lead Bojan Angjelkoski responded that the vulnerability did not cause actual financial loss or address theft, and multiple suspicious transactions had to be executed in the actual exploitation, limit the impact. Thus, it was not classified as a serious security level in the blockchain field, with the highest bounty set at $50,000; the blockchain security company Decurity found that a smart contract of DxSale presented a security vulnerability, potentially impacting at least $5.2 million of user funds, but the project tried to downplay the potential impact of the vulnerability and only offered a $500 bounty.
Co-founder of blockchain security company Halborn, Steven Walbroehl, disclosed that some projects providing vulnerability bounties often have the incentive to pay as little as possible or avoid paying bounties altogether. There are direct economic costs involved, and some project teams may intentionally downplay the severity of vulnerabilities reported by researchers to protect their reputation, allowing users to remain at risk.
He believes this experience is very discouraging for a security researcher, investing a lot of time finding vulnerabilities, ultimately being ignored by the project team or even blamed in return. In such circumstances, some destructive actions, such as directly stealing large funds, might even appear to researchers as a "reasonable way to compel the project party to take action."
From a longer-term perspective, establishing a sound mechanism for vulnerability discovery, response, and bounties, while providing reasonable, transparent, and trustworthy incentives for security researchers, is an important part of reducing the likelihood of such events occurring again. However, at the same time, security cannot rely solely on bounty hunters; project teams themselves must also establish a more robust security defense mechanism.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。