If an Attacker Sets Their Own Fee, It Is Not a Bounty. The Industry Needs to Say So.
A white hat bounty is agreed in advance and capped, typically at 5% to 10%. The Liquid attackers took $319 million first and kept roughly 15% on terms nobody offered.
On this page
- How a white hat bounty is supposed to work
- The percentages, in context
- Why defenders keep paying
- What would actually change the incentives
- The part protocols control
- What to watch
- The number nobody publishes
The Liquid Network attackers took roughly 4,000 BTC, returned 3,400, and kept 598.5 — about $47 million. They call the remainder a bounty.
That is roughly 15% of the total taken. Standard programme terms run 5% to 10%, capped, and agreed in advance. The difference between those two arrangements is not the percentage. It is who decided.
How a white hat bounty is supposed to work
A functioning bug bounty has four properties, and every one of them was absent here.
Prior agreement. The programme publishes its scope, its reward tiers and its cap before anyone finds anything. Both sides know the terms.
Disclosure before exploitation. The researcher reports the flaw. They do not take the funds to demonstrate it. Proof-of-concept on a testnet is the accepted standard.
A defender who can decline. If the report is weak or out of scope, the programme says no. That option is what makes the reward a reward.
Identity or a safe harbour. Either the researcher is known, or the programme's safe harbour terms protect anonymous submission.
Take the funds first and all four collapse. The defender cannot decline, cannot verify, cannot negotiate from anything but weakness, and cannot know who they are dealing with.
The percentages, in context
| Arrangement | Typical share |
|---|---|
| Standard bug bounty programme | 5%–10%, capped |
| Post-exploit negotiated return | 10% commonly offered |
| Liquid attackers, self-declared | ~15%, uncapped |
Caps matter more than percentages. A programme offering 10% capped at $2 million behaves very differently from 10% of whatever an attacker can reach. Uncapped percentage rewards create an incentive to wait for the treasury to grow before reporting, which is precisely backwards.
Why defenders keep paying
Because the alternative is usually worse.
DeFi protocols lost at least $1.3 billion in the first eight months of 2026, and North Korea's Lazarus Group accounts for roughly 44% of it. Those attackers return nothing. Against that baseline, recovering 85% looks like a good day.
That comparison is how a bad norm gets established. Nobody endorses it. It simply keeps looking reasonable relative to something worse, and each instance makes the next one easier to justify.
The pattern has recurred all year. Attackers embed on-chain messages, protocols open negotiations, funds partially return, and the retained share is described afterwards as a bounty by the person who set it.
What would actually change the incentives
Three things, and none requires new technology.
Published, capped programmes with real numbers. A protocol holding $300 million with a $50,000 maximum bounty has told researchers exactly what its security is worth. Immunefi-style programmes with seven-figure caps on critical findings change that calculation.
Industry-wide language. A returned-funds arrangement negotiated after an exploit is a ransom settlement. Calling it a bounty in press releases launders the method. Firms writing incident reports control this and can stop.
Safe harbour that works. Researchers avoid disclosure partly because the legal exposure is genuine and unclear. Clear safe harbour terms remove the argument that exploitation was the only viable route.
The part protocols control
Blockstream's position was bad by the time it had a choice. Every real decision happened before: how large the bounty programme was, whether the range proof caching code had been independently reviewed, whether anything monitored for anomalous issuance, and whether a 36-minute window between minting and payout could have triggered an alert.
By the time an attacker is messaging you on-chain, you are not managing a security programme. You are managing a loss.
What to watch
Whether the $47 million moves. Visible on-chain. Movement to a mixer settles the white-hat question.
Whether other protocols adopt the framing. If the next incident report uses "bounty" for a self-set retention, the norm has taken.
Bounty programme sizes. Protocols raising their caps after this would be the constructive response.
Legal follow-through. Whether any jurisdiction treats a self-declared bounty as theft is genuinely untested, and the answer would settle a great deal.
The number nobody publishes
There is one figure that would settle most of this debate and almost no protocol discloses it: the ratio of its maximum bug bounty to its total value at risk.
A protocol securing $300 million with a $50,000 maximum payout has set that ratio at roughly 0.017%. It has told every researcher in the world precisely what finding a critical flaw is worth, and the answer is less than a week of an exploit's proceeds.
Publishing the ratio would be trivial and would create immediate competitive pressure. A protocol at 1% would advertise it; one at 0.017% would have to explain it.
That is the kind of disclosure norm the industry could adopt without any regulator, and its absence is a choice rather than an oversight.
About this report. Liquid figures are from TRM Labs' analysis and reporting by The Hacker News, 7-9 September 2026; the bounty characterisation is the attackers' own and is unverified. Standard bounty ranges are widely published programme terms instead of a single source. 2026 loss totals and attribution are from crypto.news reporting of rekt.news data.
Not legal or security advice. Negotiating with attackers carries legal exposure that varies by jurisdiction.
Frequently asked questions
What is a normal bug bounty percentage in crypto?
Typically 5% to 10% of funds at risk, capped at a published maximum and agreed before anyone finds anything. Post-exploit negotiated returns commonly offer around 10%. The Liquid attackers retained roughly 15%, uncapped, on terms they set themselves.
What makes a bounty legitimate?
Four properties: prior published terms, disclosure before exploitation, a defender who can decline, and either a known researcher or a working safe harbour. Taking the funds first removes all four, because the defender can no longer verify, decline or negotiate from anything but weakness.
Why do protocols pay attackers at all?
Because the alternative is often total loss. DeFi protocols lost at least $1.3 billion in the first eight months of 2026, and North Korea's Lazarus Group accounts for roughly 44% of it. Those attackers return nothing, which makes an 85% recovery look reasonable by comparison.
What would change the incentives?
Published capped programmes with realistic maximums, industry language that calls a post-exploit settlement what it is, not a bounty, and safe harbour terms clear enough that disclosure is a viable route for an anonymous researcher.
Related reading
- Liquid Hack: 85% of Bitcoin Returned, $47M Kept as Bounty
- Elements Range Proof Bug: How 4,000 Fake L-BTC Was Minted
- DeFi Market Cap $78bn Against $1.6bn in 2026 Hack Losses
- Liquid Network Hack: $320M and 95% of BTC Reserves Gone
Sources
- 2026's Biggest Hack To Date: Attackers Drained $319 Million From Liquid Network — TRM Labs
- $47M Still Missing After Liquid Hack as Blockstream Bargains With 'White Hats' — BitcoinEthereumNews
- DeFi has lost $1.3 billion to hacks in 2026 and the same attack keeps working — crypto.news
- Liquid Network White-Hats Return 3,400 BTC, $47M Still Out — Spendnode
Read next
- Thirty-Six Minutes From Mint to Payout: How the Liquid Bug Actually Worked The Elements range proof cache bug let attackers mint about 4,000 unbacked L-BTC and withdraw real bitcoin ag…
- For the First Time, Stolen Keys Cost DeFi More Than Broken Code DeFi hacks in 2026 have cost $1.3bn across 30+ exploits, and compromised keys now cause more losses than smar…
- The Liquid Attackers Gave Back 3,400 Bitcoin and Kept $47 Million. Nobody Agreed to That. Liquid Network attackers returned 3,400 BTC of the roughly 4,000 taken, keeping about $47 million they descri…