The Liquid Network attacker has returned 3,400 BTC but still retains 598.5 BTC, a move Immunefi says constitutes theft. The incident involves about 4,000 BTC; the partial return has not resolved the white-hat boundary dispute or its impact on trust in on-chain security.
The Liquid Network-related attack incident has made interim progress. According to information disclosed by crypto.news, the attacker has returned 3,400 BTC but still retains 598.5 BTC. Regarding the portion not yet returned, Immunefi explicitly stated that this conduct already constitutes theft. This means that although a large amount of funds has been returned, the incident does not automatically end, and unresolved matters remain. The fact of the partial return and the fact that the remaining funds have not been returned coexist, forming the basic state of the current incident.
The parties involved in this incident include Liquid Network, the party that carried out the attack and returned part of the funds, and Immunefi, which made the characterization. crypto.news reported that the scale of funds involved was approximately 4,000 BTC, of which the returned portion accounts for the majority, but funds remain unreturned. For Liquid Network, this is not only a single security incident but also concerns network users' trust in asset security. When the attacker returns most of the BTC but still retains part of the funds, outside attention shifts from 'whether it will be returned' to 'why the remaining portion has not been returned' and 'how this conduct should be characterized.' These two questions correspond respectively to the recovery process and the boundary of responsibility.
From the fund structure, 3,400 BTC and 598.5 BTC total about 3,998.5 BTC, broadly consistent with the scale of 'approximately 4,000 BTC.' The returned portion accounts for the vast majority, but the remaining portion still constitutes an unresolved exposure. The partial return reduces the direct funding gap, but it does not eliminate the incident's impact. Handling a security incident involves not only recovering funds but also characterizing conduct and restoring user trust. With funds still unreturned, the incident risk is not fully resolved. In particular, when most of the funds in a major security incident have been returned, the remaining unreturned portion, though a small share, may become key to determining the incident's nature.
The focus of this incident is on the boundary of white-hat behavior. The attacker returned most of the BTC but still retained part of the funds; whether this can still be regarded as white-hat behavior is the crux of the dispute. The source material mentioned that the attacker's retention of funds has triggered a white-hat boundary dispute and may affect users' trust in on-chain security. Immunefi gave a negative judgment on this, holding that retaining the funds already constitutes theft. This statement indicates that a partial return cannot automatically cover the liability determination for the unreturned portion, nor can it automatically classify the incident as white-hat testing or security research. In other words, the act of returning funds itself cannot dispel accountability for the unreturned portion.
Looking at the sequence of events, the facts that can currently be confirmed center on several points: the attacker has returned 3,400 BTC; still retains 598.5 BTC; the incident involves approximately 4,000 BTC; and Immunefi has characterized the retention of funds as theft. Beyond that, currently disclosed information does not yet include further handling arrangements, recovery progress, or security remediation details. This means the incident is at the stage of 'most funds returned, remaining portion unresolved,' and its future direction still depends on whether the remaining funds are returned and whether relevant parties take further measures. At the current stage, the contrast between returned and unreturned funds is an important clue for understanding the nature of the incident.
For Liquid Network users, the most direct information is that the attacker has returned most of the BTC, but some BTC remains unreturned. The impact of on-chain security incidents usually does not stop at the direct loss figure; it also extends to users' judgment of asset protection mechanisms, response efficiency, and subsequent recovery capabilities. With the remaining funds still unreturned and Immunefi having characterized the conduct as theft, the incident may continue to affect users' trust in Liquid Network's asset security. The positive signal from the partial return coexists with the unresolved risk from the remaining unreturned portion. Users need to face not only whether a particular sum can be recovered but also the reliability of the entire asset security system under abnormal circumstances.
It should be noted that the incident involves approximately 4,000 BTC, making it a major security incident. Even if the return ratio is high, the severity of a security incident cannot be fully offset merely by the returned portion. The attacker's retention of funds not only creates an actual funding gap but may also weaken users' stable expectations regarding the boundaries of on-chain security. If, after a partial return, a portion of funds can still be retained without accountability, the line between white-hat behavior and theft will become even more blurred; Immunefi's characterization attempts to provide a clearer boundary judgment. For observers of security incidents, this case provides a specific scenario: by what standards should remaining funds after a partial return be characterized and pursued?
Follow-up attention remains focused on several areas: whether the attacker will return the remaining portion; whether Immunefi's theft characterization will drive further recovery or handling; whether Liquid Network will disclose more security remediation and user asset protection arrangements; and how the industry defines the boundary between white-hat returns and theft. Based on currently disclosed information, the incident has not been fully concluded, and the ownership and characterization of the remaining funds remain core variables. Related developments will depend on whether the remaining funds are returned and how parties respond to the theft characterization. Before more information is released, the final outcome of the incident remains uncertain.
