خبری درباره‌ی Cetus Protocol (CETUS)

Liquid Network attacker crossed into theft: Immunefi CEO

crypto.news ۵۶ دقیقه پیش خلاصه‌ی فارسی · ۴۵۴ کلمه
Liquid Network attacker crossed into theft: Immunefi CEO

Immunefi CEO Mitchell Amador has said the Liquid Network attackers lost any claim to white-hat status by retaining 598.5 BTC after returning 3,400 BTC from the roughly 4,000 BTC exploit. Summary Roughly 598.5 BTC remains with the attackers after they returned 3,400 BTC. Amador said coordinated disclosure ends when a researcher sets rescue terms without prior approval. Protocols should establish rescue rules and bounty limits before an exploit occurs. Immunefi’s CEO defended the 10% bounty convention when teams approve it in advance. Immunefi founder and CEO Mitchell Amador told crypto.news that moving user assets without permission cannot be treated as a rescue when the researcher later keeps part of the funds or sets payment terms. “Coordinated disclosure ends the moment you set the terms yourself,” Amador said. “The money was never yours to save, so moving it is not a rescue.” His comments address the dispute left by the Liquid Network incident, in which unidentified actors withdrew roughly 4,000 BTC, valued at about $320 million at the time, before describing themselves as whitehats. They returned 3,400 BTC after Blockstream patched the affected bridge nodes but retained 598.5 BTC. Blockstream has rejected the group’s demand for a 10% bounty and has said it will not pay for the return of the remaining Bitcoin. The company also rejected the attackers’ claim that the operation amounted to responsible disclosure. You might also like: 0G launches liquid staking gateway for AI compute credits Liquid Network attackers could not set their own terms Amador said a security researcher must use private disclosure channels, preferably through a defined bug bounty program, instead of taking assets and negotiating a reward afterward. “Keep a dollar of user funds, and it is theft, whatever the intent was at the outset. The path for a researcher is private disclosure, ideally within a well-defined program.” The distinction rests on authorization rather than the researcher’s stated motive. Under Amador’s view, finding a real vulnerability does not give someone the right to move user assets, hold them as collateral, or decide what compensation is owed. Blockstream took a similar position in its Sept. 11 response. As previously reported by crypto.news, the company said taking assets without permission and refusing to return them constituted theft rather than whitehat work. The company said its earlier discussions with the actors were intended to recover user funds and protect the Bitcoin community. According to Blockstream, engaging in those talks did not mean it had accepted either the withdrawal or the later bounty demand. A technical review of the exploit found that a cache-key collision in the confidential transaction verification logic allowed the actors to create unbacked L-BTC. They then used SideSwap’s peg-out service to obtain real Bitcoin from the federation reserve.

عنوان اصلی (انگلیسی): Liquid Network attacker crossed into theft: Immunefi CEO

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به Cetus Protocol

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.