so the Liquid hackers returned 3,400 BTC and kept 598.5 BTC (~$47m).
They’ve called themselves white hats throughout this whole saga. Maybe Blockstream agreed to them keeping the 15%, maybe they didn’t. We don’t know yet.
What’s arguably more interesting is what “white hat” hacking really means as AI makes serious vulnerability discovery accessible to a much larger group of people.
Historically, the people capable of finding a subtle bug in something like Elements were usually security researchers. There are established norms around what you do next: disclose it, don’t take the money, agree a bounty, etc.
AI increasingly separates the capability from those norms and I think we’ve probably underestimated how much security has relied on the two coming together.
To get good enough to find really hard bugs, you generally spent years inside security, cryptography or open-source communities. Along the way you didn’t just learn how to find them. You also picked up the norms, built a reputation you cared about, and had professional relationships you probably didn’t want to burn.
In other words, responsible disclosure hasn’t only worked because we’ve built good incentives for researchers (arguably most of the time the monetary incentives are crap or non-existent). It’s also worked because the population capable of finding these bugs was unusually selected.
AI breaks that selection effect. If the capability becomes cheap and widely available, the norms don’t automatically come with it.
That’s a pretty fundamental change to a security model which, it turns out, relied on social infrastructure more than we probably realised.