Liquid returned 85%, leaving 47 million dollars as a bounty—does that count as a white hat?
Over the past couple of days, the community has been arguing about this, and I’ll share my take.
First, let’s lay out the facts clearly: the attacker created 4,000 LBTC that were fabricated out of thin air, then followed the normal process to withdraw 3,996 real BTC. After Blockstream fixed the nodes, the attacker returned 3,400 more, leaving about 598.5 LBTC, which—at current prices—amounts to roughly 47 million USD.
The attacker claims to be a “white hat”: “I’m not here to steal money. I’m here to remind you there are vulnerabilities.”
But there’s a logic problem here. What’s the standard process for responsible disclosure? Discover a vulnerability → report it to the project → wait for a fix → collect the bounty. And this time it’s: drain 95% first → wait for the project to fix it → refund 85% → keep 15% as the bounty.
The order is reversed, and so is the nature of it. Once Blockstream confirms on-chain that the nodes are fixed and refunds are possible, this also makes things more complicated—in the attacker’s eyes, it effectively confirms a “pay back money equals a settlement” pathway.
Ledger’s CTO put it even more directly: this isn’t a white hat—it’s kidnapping first, then negotiating.
As the founder of FuturaKey—someone who also builds on-chain products—I understand why the community is split into two camps. One side argues: most of the money came back, so it turned out fine. The other side argues: if this kind of behavior is encouraged, next time attackers will be emboldened—empty the reserves first, and if they refund part later, they can wash themselves as “white hats.”
My position is the latter. The reason is simple: if “strike first, then refund” can still be called “white hat,” then the hacking industry has no failure cost—keep a portion when the attack succeeds, call yourself a white hat and ask for mercy when it fails. That is extremely unfair to researchers who do responsible security disclosure the right way.
What’s even more concerning is the industry signal: this month Liquid saw 320 million, and Cronos had a rollback—so the density of security incidents is rising. In bear markets, hackers are more active than in bull markets. Project defense budgets are being cut, but the returns from attacks haven’t changed.
For ordinary users, I have just one suggestion: anchor the security level of your assets and sidechain assets—always keep it lower than mainnet. Don’t put large positions there just because the yield is a bit higher.
Do you think “drain first, then refund 85%” counts as a white hat? Let’s discuss in the comments.
The above is only my personal observation and does not constitute investment advice.
#Liquid #BTC #Web3 #链上安全 #FuturaKey