Mitchell Amador, CEO of the security platform Immunefi, argues that coordinated disclosure requires prior authorization. According to Amador, a researcher who moves user funds without explicit permission and demands payment afterward is not a savior, but a perpetrator. The Liquid Network incident, which involved the initial withdrawal of roughly 4,000 BTC, highlights the dangers of ad-hoc "rescues" where the intermediary holds assets as leverage.
Blockstream, the entity behind the network, has consistently rejected the group’s demand for a 10% bounty, maintaining that the unauthorized seizure of funds constitutes criminal activity. The company successfully recovered 3,400 BTC after patching the affected bridge nodes, yet the remaining 598.5 BTC remains unreturned. This dispute underscores a fundamental disconnect: legitimate white-hat work relies on established bug bounty programs and transparent communication channels, not on the forced negotiation of stolen capital.
To prevent such standoffs, Amador advocates for protocols to establish clear "safe harbor" frameworks before vulnerabilities are ever discovered. By setting predefined rules for incident response and bounty limits, projects can strip attackers of their leverage and ensure that security interventions remain within legal and ethical boundaries. Without these guardrails, the distinction between a helpful researcher and a common thief becomes dangerously blurred, leaving protocols vulnerable to both technical exploits and extortion.
Comments (0)
No comments yet. Be the first!