• The white hat hackers responsible for the Liquid Network exploit returned only 85% of the stolen Bitcoin to Blockstream, retaining 598.5 BTC valued at approximately $47 million.
  • Members of the cryptocurrency community strongly criticized the exorbitant fee demanded by the attackers, comparing the tactic to extortion.

The dispute between the self-proclaimed “white hat” group and Blockstream, the operator of the recently compromised Liquid Network, has reached its conclusion. The attackers, who exploited the network resulting in a loss of 4,000 Bitcoin (BTC), have returned the majority of the stolen funds.

The perpetrators, identifying themselves as ethical hackers, retained approximately 15% of the stolen funds as a bug bounty. This amounted to 598.5 BTC, translating to over $47 million at current cryptocurrency exchange rates.

Red Flags Surrounding the White Hat Hackers’ Demands

Collecting a white hat bounty is a widely accepted industry practice, particularly within the cryptocurrency sector. It rewards independent security researchers who uncover critical protocol vulnerabilities, enabling them to collaborate with core developers to remediate system flaws before malicious actors can exploit them, thereby preventing larger losses and reputational damage.

However, many viewed the Liquid Network hackers’ approach as unorthodox and problematic, as they effectively forced Blockstream to patch the compromised protocol before agreeing to return the stolen funds. Critics likened this to extortion, noting that the perpetrators refused to return the funds unless provided with proof that Blockstream had already addressed the vulnerability.

Critics also condemned the culprits for retaining an excessive portion of the stolen funds. Standard white-hat bounty practices typically range from 5% to 10% for disclosing a vulnerability and returning stolen assets, and are usually capped at around $10 million. The Liquid Network hackers’ demand far exceeded these standard thresholds.

Furthermore, observers noted issues with the apparent lack of proper negotiation between Blockstream and the hackers. It seemed the attackers unilaterally dictated the terms, controlling communication via Bitcoin’s OP_RETURN function, which allowed them to assign the 15% bounty without Blockstream’s prior approval.

The exorbitant fee could create a significant deficit in the Liquid Network’s reserve backing relative to its tokenized Bitcoin circulating supply, potentially undermining Liquid Bitcoin’s (LBTC) ability to maintain its 1:1 peg with Bitcoin.

A Potential Legal Battle

While it is premature to speculate, the situation strongly suggests a potential lawsuit. However, pursuing legal action could prove detrimental to future white-hat security collaborations.

Source link

Exit mobile version