Liquid Network Attackers Keep 598.5 BTC as Coldcard Recovery Trust Receives 52.37 BTC

1 hour ago 1 sources negative

Key takeaways:

  • Liquid exploit's disputed bounty signals legal risk for BTC DeFi whitehats setting self-serving terms.
  • Blockstream's no-pay stance may deter future whitehats but sets precedent against post-hoc ransom demands.
  • Coldcard recovery highlights cooperative BTC security model, yet persistent seed flaws demand self-custody vigilance.

Immunefi founder and CEO Mitchell Amador has declared that the operators behind the Liquid Network exploit crossed from security research into theft when they retained 598.5 BTC after returning 3,400 BTC from the roughly 4,000 BTC exploit, valued at about $320 million at the time.

Amador told crypto.news that moving user assets without permission cannot be treated as a rescue when the researcher later keeps part of the funds or sets payment terms. 'Coordinated disclosure ends the moment you set the terms yourself,' Amador said. 'The money was never yours to save, so moving it is not a rescue.'

Blockstream has rejected the group's demand for a 10% bounty and said it will not pay for the return of the remaining bitcoin. The company also rejected the actors' claim that the operation amounted to responsible disclosure. A technical review found that a cache-key collision in the confidential transaction verification logic allowed the actors to create unbacked L-BTC. They then used SideSwap's peg-out service to obtain real Bitcoin from the federation reserve. Federation keys were not compromised; the issue involved verification logic in the Elements codebase.

Amador said serious protocols should set rescue conditions before an emergency occurs, including maximum bounty, payment conditions and legal protections. He defended the industry's informal practice of offering up to 10% of funds at risk as a whitehat bounty, but said the protocol must control that decision instead of allowing a researcher to set the fee after taking custody of user assets. He also cited U.S. prosecutions such as the Shakeeb Ahmed case, where returning funds did not prevent criminal charges after unauthorized access.

In a separate Bitcoin security recovery, whitehat operators moved 52.37 BTC linked to the July Coldcard wallet exploit into an address associated with a recovery trust. Galaxy Digital Head of Research Alex Thorn said the Bitcoin came from the tracked Wave 2 cluster and represented 2.8% of the exploit funds his team was tracking, with the consolidation recorded in Bitcoin block 967,948.

The destination transaction carried an OP_RETURN message pointing to 'claim:cryptorecoverytrust dot com.' The Crypto Recovery Trust, a Wyoming statutory trust, holds recovered digital assets while ownership claims are verified. The Digital Asset Recovery Trust, or DART, had previously disclosed recovering just over 50 BTC from vulnerable addresses as of Aug. 17 and said whitehat researchers did not request a bounty.

Coinkite's incident record explains that the Coldcard exploit began July 30 when a firmware integration defect caused the seed-generation path to resolve to MicroPython's Yasmarang software pseudorandom generator instead of the intended hardware random number generator. Attackers regenerated vulnerable private keys offline after reduced randomness made seed phrases easier to search. Coinkite says installing fixed firmware does not change an existing seed; users with affected seeds are instructed to generate a corrected replacement seed and migrate funds. Current recommended firmware versions are 5.6.2 for Mk4/Mk5 and 1.5.2Q for Q devices.

Sources
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.