A whitehat is someone who finds a flaw and reports it so it can be fixed; a bounty is what the owner of the flawed thing pays for that service; and a demand is what you get when the person holding your money decides the price. The three words describe three different relationships, and the whole skill in reading a message like the one Liquid’s counterparty wrote on Wednesday is to work out which one you are actually looking at. This guide is written for the reader who holds a token backed by a reserve — L-BTC, a wrapped bitcoin, a bridge asset, an exchange balance — and who wakes up to find that the reserve has been taken and its taker is negotiating in public. It follows the format of the desk’s field guides: vocabulary first, then tests you can run yourself, then the arithmetic, then a scoring on the live case.

The vocabulary, and where the 10% comes from

In the world outside crypto a whitehat reports a vulnerability without exploiting it beyond what is needed to prove it exists, and is paid under a programme whose terms the company published in advance. In crypto the word has drifted to cover people who exploit the flaw fully, take the money, and then offer to return most of it — because on a public blockchain the money is traceable, laundering hundreds of millions is hard, and a negotiated return with a keep is often the taker’s best outcome as well as the victim’s. The 10% figure that both sides reach for comes from that market. Bounty platforms have for years published scales in which the top payout for a critical finding is capped at a percentage of funds at risk, and 10% became the number that protocols offered publicly to attackers after the fact — “keep ten percent as a bounty and return the rest” — often with a promise not to pursue. That offer, made by the victim, is a bounty. The same figure, set by the taker, with the money already gone, is a price. The number does not tell you which; the sequence does.

One more term. A “safe harbour” is a published promise that someone who takes funds to protect them and returns them within a stated window will not be pursued; a handful of DeFi protocols have adopted such terms. Blockstream’s Liquid did not have a published one that the desk can find, and nothing in the on-chain record shows the whitehats asking for one. That absence matters for the tests below, because a taker who wanted the protection of a whitehat’s status would normally ask for it before doing anything else.

Test 1: When was the demand made, relative to the return?

This is the test that does most of the work. A whitehat states the terms before returning anything, or returns everything and asks afterwards; either order is consistent with the money never having been the point. What is not consistent is returning most, keeping a fixed slice, waiting, and then demanding a further payment from the victim with the slice as leverage. Get the timestamps from the chain, not from the coverage. In Liquid’s case, read directly from mempool.space: the first whitehat message (“we are whitehats. contact us on chain”) at 18:30 UTC on 6 September; “sending most back” at 02:20 on the 7th; the return of exactly 3,400 of 3,998.5 BTC at 16:09 on the 7th, with 598.5 kept; a two-byte “:(” at 21:03; and the demand for a further 10% “using your own money” at 11:45 on the 9th, forty-four hours after the return. The word “most” was the only term stated in advance, and it was honoured — 85% is most. The 10% was introduced two days after the coins had been split.

Test 2: Is the kept amount hostage to the demand?

Read the conditional. A bounty is a payment for a service already rendered; it is not returned if the payer is displeased. A hostage is something whose return depends on a further act by the victim. Wednesday’s message says Blockstream must pay 10% from its own funds “or you will cause all your holders a 15% loss.” The 15% is the 598.5 BTC the senders hold, as a share of the 3,996 that left; the sentence makes its return conditional on a payment the senders have named. That is the structure of a hostage, whatever the senders call themselves, and it is why Ledger’s Charles Guillemet, quoted by Cointelegraph, said that if the kept coins were a negotiated reward the arrangement looked “more like extortion than white-hat hacking.” Note what the message does not say: it does not say the 598.5 will be returned if the 10% is paid. Read literally, the payment buys the absence of a loss to holders, which could mean return of the coins or could mean nothing more than that the senders keep 15% instead of — what? The message has no second branch. A reader should not supply one.

Test 3: Was the amount set unilaterally, and against what base?

Whitehat bounties are set by the party paying them, sometimes after negotiation; the base is usually the funds at risk. Check who set the number and what it is a percentage of. Here, 10% of 3,996 is 399.6 BTC, about $31.3 million at Wednesday’s close, and the senders already hold 598.5, about $46.9 million. So the demand is not “let us keep 10%” — they are keeping 15% — it is “pay us 10% on top, from money that is not the reserve.” The phrase “using your own money” is doing specific work: it distinguishes Blockstream the company from the federation’s reserve, and asks that the company, not the token holders, fund the payment. Whether Blockstream has $31 million in liquid funds it is willing to spend this way is a question about a private company’s balance sheet that the desk cannot answer; the senders’ own claim, that Blockstream spent “only $1.5M (maybe even 0)” on security, is unsourced and should be read as an allegation. Compare the Kelp DAO case earlier this year, where the sums and the bridge were different but the pattern of a taker naming its own keep was the same.

Test 4: Who does the threat name?

A message addressed to the victim about the victim’s money is a negotiation. A message that names a third party who will be hurt — “all your holders” — is leverage applied through people who were not party to the exploit and cannot pay the ransom. Read that sentence for who is being asked to carry the cost. In a federated sidechain the holders of L-BTC did nothing; their tokens were backed one-for-one by bitcoin on Sunday morning and were backed by 85 cents on the dollar by Monday evening. The senders know this, which is why the sentence is constructed as it is: Blockstream’s stinginess “will cause” the loss, not the senders’ keeping of the coins. The grammar transfers agency. A reader should transfer it back: the coins are where they are because the senders put them there and are keeping them there.

Who pays, by custody model

The answer depends on what backs the token. In a single-company custodian — an exchange, a wrapped-bitcoin issuer with one balance sheet — the company pays or the company fails, and its terms of service say which. In a smart-contract protocol with a treasury and a token, the treasury pays and token holders are diluted, usually by governance vote. A federated sidechain is the awkward case: the reserve belongs to the token holders collectively, the federation members hold the keys but not the economic interest, and the software vendor — Blockstream, in Liquid’s case — wrote the bug but does not, on the public record, own the reserve or guarantee it. That is why the senders wrote “using your own money”: they are trying to make the vendor the payer. Whether it becomes the payer is a decision for Blockstream, and it has not made one in public. As Liquid’s restart plan, in PANews’s rendering on Wednesday, puts it, peg operations resume “after the network state is fully restored and fund returns are confirmed” — which ties the reopening of the exit door to the coins, and so to the negotiation.

The holder-loss arithmetic, done on Liquid’s numbers

Do this yourself, because the percentage a message quotes is chosen to persuade. You need three figures: the reserve before, the reserve now, and the amount of the token in circulation. Liquid’s status note, per PANews, gives the reserve as approximately 4,205 BTC before and 197 BTC “at one point” after; the peg address held 3,601.47 BTC at 06:11 UTC on Thursday. The exploit created about 4,000 L-BTC with nothing behind them, of which 3,996 were pegged out and burned, so circulating L-BTC after the burn is roughly what it was before the exploit. On those figures the reserve covers 3,601.47 ÷ 4,205 = 85.6% of the tokens, a shortfall of about 603.5 BTC, or 14.4% — the senders’ “15%” is 598.5 ÷ 3,996 = 14.98%, a different base, and both are fair. The desk has not seen Liquid publish a reconciliation of circulating L-BTC against reserves since the incident; NFTevening noted on Tuesday that none had appeared. Until one does, the 85.6% is an estimate built from a status note and an address balance, and you should label it that way.

Then ask what “loss” would mean mechanically. A federated peg does not have a pro-rata redemption rule; it pays peg-outs one-for-one until it cannot. A 14% shortfall does not become a 14% haircut for everyone — it becomes a full payout for the first 86% of tokens to exit and nothing for the last 14%, unless someone tops the reserve up or the federation imposes a rule. That is why a restart that reopens the peg without resolving the 598.5 BTC would be a run, and why the three-phase plan puts the peg last. The 15% in the message is a portfolio number; the risk to any one holder is binary and depends on the queue.

How to verify a message like this yourself

Every claim above about who said what on-chain rests on one rule from Monday’s guide: a message belongs to the party whose coins fund the transaction’s inputs. Open the transaction on mempool.space, look at the inputs, and check that the address holding the disputed coins is among them; if it is not, the message is from a stranger, and Liquid’s incident has had dozens of those. Then read the OP_RETURN as bytes, not as a rendering: Monday evening’s “frown” was two ASCII characters, 0x3a and 0x28, and the coverage that printed an emoji printed something the senders did not send. For the other side, a signed message from a company can be checked against the company’s published key; the desk did that for each of Blockstream’s three signed messages and all three verify; the first, “Please contact security@blockstream.com,” carried no signature. A demand, by contrast, is unsigned and needs no key — the coins are the signature.

Scoring Wednesday’s message

Test 1, timing: the demand came forty-four hours after the return and two and a half days after the only stated term, “most.” Fails the whitehat pattern. Test 2, hostage: the kept 598.5 BTC is explicitly conditional on a further payment, with no stated branch for its return. Fails. Test 3, unilateral amount: 10% on top of a 15% keep, set by the senders, base chosen by the senders, payer specified by the senders. Fails. Test 4, third party: the threat is addressed through holders who cannot pay. Fails. Against that, the record also shows a party that pre-announced its destination, waited for a signed patch confirmation before moving anything, returned 85% within a day of it, and has so far sent nothing from that address anywhere but back to itself and to the peg. The honest description is that the return was conducted like a whitehat’s and the demand is written like a ransom note, and that a reader holding L-BTC should plan on the second document, not the first, because the second is the one that governs the coins that are still missing.

The marker

As standing practice we mark one falsifiable claim on the subject of this guide. Y1: by 23:59 UTC on Wednesday 30 September 2026, Blockstream or the Liquid Federation has published a statement, on blockstream.com, blog.liquid.net or the @Liquid_BTC or @Blockstream accounts on X, that either (a) commits to making L-BTC fully backed from sources other than the whitehats’ 598.5 BTC, or (b) confirms that a bounty of any size has been paid or agreed. The reasoning for: the restart plan conditions the peg on fund returns, the peg cannot safely reopen 14% short, and the company has every incentive to end a public negotiation it is losing in the press. The reasoning against: paying a demand structured as this one is a precedent no vendor wants to set, Blockstream has said nothing on-chain since Monday morning, and a private settlement could be reached and left unannounced. If Y1 fails and V1 passes, the peg reopened with the gap unaddressed in public, which would be the worst outcome for a reader of this guide.

Sources: mempool.space for every on-chain message, timestamp and balance, pulled 06:11 UTC 10 September; Cointelegraph, updated 9 September, for the Guillemet quotation; PANews, 9 September, for Liquid’s reserve figures, and PANews, 9 September, for the restart plan; NFTevening, 9 September; blockstream.com/pgp.txt for the signing key. Prices are Bitstamp’s 9 September close of $78,281.65. The desk holds no L-BTC.

Disclaimer: This article is for informational purposes only and does not constitute investment advice. Cryptocurrencies are volatile and you can lose money. Nothing here is a recommendation to buy or sell any security, digital asset or exchange-traded fund, including MSTR, STRC, L-BTC or HYPE. Do your own research and consult a licensed financial advisor before making investment decisions.