Home
/
Regulatory news
/
Legal developments
/

$320 m stolen and repaid: white hat or thief?

$320M Drained from Liquid Network | Ethical Hacker or Thief?

By

Sofia Chang

Sep 17, 2026, 12:05 AM

Edited By

Priya Narayan

3 minutes needed to read

A visual representation of a digital wallet with money being transferred, symbolizing the theft of $320 million and the return of a portion by 'white hats'.
popular

On September 6, the Liquid Network suffered a significant breach when approximately 4,000 BTC, valued at around $320 million, was stolen from its federation wallet. The incident has sparked a fierce debate within the crypto community regarding the motives of those behind the theft and their subsequent actions.

The Sequence of Events

The attack left just 197 BTC remaining in the wallet meant to back L-BTC. In a notable twist, the attackers left a message in a Bitcoin transaction claiming to be "white hats" and inviting Blockstream to contact them.

After negotiations, Blockstream announced that the security vulnerability had been fixed and it was safe to return the funds. The attackers then sent back 3,400 BTC, keeping $47 million for themselves. Notably, this amount was never acknowledged as a pre-agreed bounty.

"The take-first-and-negotiate-later approach is not how white hats operate," stated Charles Guillemet, Ledgerโ€™s CTO.

Divided Perspectives

Comments from the community reflect a mix of skepticism and defense regarding the attackers' actions. Several points of contention have emerged:

  1. Ethical Dilemma: Some argue that returning most of the stolen funds shows a degree of morality, with one commenter stating, "What do you call someone who could have kept the whole $320M, but decided to return most of it voluntarily?"

  2. Concerns Over Internal Involvement: Another user raised the possibility of the situation being an inside job, pointing out Blockstreamโ€™s outstanding debt of about $50 million.

  3. Real Security Practices: Critics assert that true security researchers wouldnโ€™t need to commandeer such a sizable amount of funds to identify a vulnerability. One user framed it as a question of responsibility, mentioning, "A real security researcher might move the full amount into their wallet to demonstrate a bug."

Sentiment in the Community

The overall sentiment surrounding this theft is largely negative, with many labeling the incident as theft rather than heroism:

  • โ€œThis was theft and should be investigated as such.โ€

  • โ€œA thief.โ€

  • โ€œWhat do you call someone who steals eight antiques from a museum, then returns seven of them? I call them a thief.โ€

However, a smaller faction defends the actions, suggesting that simply identifying vulnerabilities merits some form of compensation, while acknowledging the ethical complexities involved.

Key Takeaways

  • ๐Ÿ”ป 4,000 BTC ($320 million) drained from the Liquid Network.

  • ๐Ÿ”„ Attackers returned 3,400 BTC, keeping $47 million.

  • ๐Ÿ“‰ Significant backlash; many label the act as theft.

As the crypto world processes this significant event, questions linger about security practices in such networks and how the community should label those involved. This incident not only reflects flaws in the security of crypto wallets but also raises doubts on the motivations behind actions in the realm of ethical hacking.

What Lies Ahead for the Liquid Network

Given the significant backlash and ongoing investigations, thereโ€™s a strong probability that regulatory bodies will step in to impose stricter security guidelines for cryptocurrency networks. Experts estimate around 60% chances that firms will face increased scrutiny related to their internal security measures and practices moving forward. Additionally, there will likely be heightened community pressure for transparent protocols that govern ethical hacking. As more people question the actions of those claiming to be ethical hackers, we may see a growing divide between traditional defenders of such practices and those advocating for a more rigorous definition of ethics in the crypto space. With the rise of stolen fund recoveries and bounty systems being debated, it's essential to consider whether new frameworks for accountability will emerge.

A Case from the Shadows

This incident may echo the controversial saga of the Sony PlayStation Network breach in 2011. During that debacle, hackers accessed personal information of millions, and while Sony later revamped its security, the public debate revolved around if the attackers held any moral ground for their actions. Just as with the Liquid Network, it sparked discussions about the essence of ethical hacking and responsibility. As the dust settled, it was apparent that the fallout reshaped how corporations addressed cybersecurity. In both instances, the complexities of morality in tech-related breaches are seen, reflecting not just the events of the day, but the long-term implications on how companies secure sensitive information.