DownDepo

Liquid Network Hackers Demand 10% Bounty

· deals

Liquid Network Hackers’ Public Posturing Masks a More Troubling Reality

The recent hack of Blockstream’s Liquid Network has taken an unexpected turn, as the perpetrators have shifted from negotiating in private to grandstanding in public. The attackers claim to be “white hats” but are now demanding a 10% bounty from Blockstream’s own funds, citing the company’s supposed negligence and mismanagement.

The facts of the case are well-documented: a software bug in Liquid’s Elements node software allowed an attacker to mint unbacked L-BTC, which was then cashed out through SideSwap for approximately $320 million. The attackers have since returned 3,400 bitcoin to the Liquid federation but retained 598.5, worth around $47 million.

The most striking aspect of this case is not the hackers’ brazen demands or their claim of being “white hats,” but rather how they are attempting to frame their actions as a legitimate form of security work. By accusing Blockstream of being delusional, greedy, and arrogant, the attackers are trying to shift the focus away from their own culpability and onto the supposed shortcomings of the company.

Critics argue that this is not how security work is done. If the hackers were truly concerned about the vulnerability, they would have contacted Blockstream’s security team directly and allowed them to decide the best course of action. Instead, the attackers chose to exploit the bug and then demand a payout from Blockstream.

The Dubious Claim of Being “White Hats”

The term “white hat” is often used to describe hackers who use their skills for good, but in this case, it seems like a convenient label applied by the perpetrators themselves. It’s not difficult to see why some might view this as an attempt to whitewash their actions and deflect criticism.

Charles Guillemet, Ledger CTO, was blunt in his assessment: “This is straight extortion.” He argued that if the hackers were truly concerned about security, they would have contacted Blockstream directly and allowed them to handle the situation. Guillemet’s critique highlights the fundamental problem with the attackers’ approach: it prioritizes personal gain over responsible behavior.

The Bigger Picture

The Liquid Network hack is just one example of a larger trend in the cryptocurrency space. As more hacks occur, it becomes clear that the current model of security and bug bounty programs is not working as intended. SideSwap’s admission that their own choices contributed to the loss of funds raises important questions about accountability and responsibility within the ecosystem.

This incident highlights the need for companies like Blockstream and SideSwap to implement more robust security measures, communicate more transparently, and emphasize responsible behavior. The Liquid Network hack is not just a technical failure but also a human one – a failure of leadership and accountability.

As the dust settles, it’s essential to remember that the hackers’ public posturing masks a more troubling reality: their actions are motivated by self-interest rather than a genuine concern for security. By acknowledging this, we can begin to address the root causes of these incidents and work towards creating a safer, more responsible cryptocurrency ecosystem.

The aftermath of the Liquid Network hack will likely be marked by continued finger-pointing and blame-shifting. However, it’s essential to focus on the real issue at hand: creating a culture of responsibility and accountability within the cryptocurrency space. Only then can we hope to prevent similar incidents in the future and build a more secure and trustworthy ecosystem for all users.

Reader Views

  • PR
    Pat R. · frugal living writer

    The Liquid Network hack is a prime example of how the label "white hat" can be hijacked for nefarious purposes. But let's not get sidetracked by semantics - what's more concerning is Blockstream's potential liability here. If the hackers did indeed exploit a software bug, it's likely that the company will have to take a closer look at their security protocols and procedures to prevent similar vulnerabilities in the future. The question is, who really bears responsibility for this mess: the attackers or Blockstream?

  • TC
    The Cart Desk · editorial

    The Liquid Network hack is a textbook example of hackers seeking to profit from their own exploits rather than genuinely addressing vulnerabilities. While some might argue that 10% of Blockstream's funds would be a small price to pay for a security audit, this line of thinking ignores the broader implications: if every company were expected to shell out millions for "white hat" hackers to fix their own mistakes, the security landscape would become even more convoluted and ripe for abuse.

  • SB
    Sam B. · deal hunter

    It's time to cut through the hype and look at this Liquid Network hack for what it is: a classic case of opportunism masquerading as altruism. The fact that these self-proclaimed "white hats" are demanding a 10% bounty from Blockstream's own funds, after exploiting a software bug and cashing out millions, screams of ulterior motives. While I agree the company should take responsibility for its negligence, it's naive to think this is about security work done right – it's about lining pockets with easy money.

Related articles

More from DownDepo

View as Web Story →