• Market Cap: $2,418,160,157,835.35
  • 24h Vol: $108,433,118,919.67
  • BTC Dominance: 56.67%
XBT.Market
Advertisement
  • Home
  • Coins MarketCap
  • Crypto Exchanges
  • Crypto Calculator
  • Top Gainers and Loser
  • News
  • Contact Us
No Result
View All Result
XBT.Market
No Result
View All Result
Home Bitcoin

Ethics 101: Should crypto projects ever negotiate with hackers?

Jon Hartney by Jon Hartney
December 15, 2022
in Bitcoin, Blockchain, Business, Market
0
Ethics 101: Should crypto projects ever negotiate with hackers?
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

A highly profitable trading strategy was how hacker Avraham Eisenberg described his involvement in the Mango Markets exploit that occurred on Oct. 11.

By manipulating the price of the decentralized finance protocols underlying collateral, MNGO, Eisenberg and his team took out infinite loans that drained $117 million from the Mango Markets Treasury. 

Desperate for the return of funds, developers and users alike voted for a proposal that would allow Eisenberg and co. to keep $47 million of the $117 million exploited in the attack. Astonishingly, Eisenberg was able to vote for his own proposal with all his exploited tokens.

This is something of a legal gray area, as code is law, and if you can work within the smart contracts rules, theres an argument saying its perfectly legal. Although hack and exploit are often used interchangeably, no actual hacking occurred. Eisenberg tweeted he was operating within the law:

I believe all of our actions were legal open market actions, using the protocol as designed, even if the development team did not fully anticipate all the consequences of setting parameters the way they are.

However, to cover their bases, the DAO settlement proposal also asked that no criminal proceedings be opened against them if the petition was approved. (Which, ironically, may be illegal.)

Eisenberg and his merry men would reportedly go on to lose a substantial portion of the funds extracted from Mango a month later in a failed attempt to exploit DeFi lending platform Aave.

The Mango Markets $47 million settlement received 96.6% of the votes
The Mango Markets $47-million settlement received 96.6% of the votes. Source: Mango Markets

How much has been stolen in DeFi hacks?

Eisenberg is not the first to have engaged in such behavior. For much of this year, the practice of exploiting vulnerable DeFi protocols, draining them of coins and tokens, and using the funds as leverage to bring developers to their knees has been a lucrative endeavor. There are many well-known examples of exploiters negotiating to keep a portion of the proceeds as a bounty as well as waiving liability. In fact, a report from Token Terminal finds that over $5 billion worth of funds has been breached from DeFi protocols since September 2020. 

High-profile incidents include the $190-million Nomad Bridge exploit, the $600-million Axie Infinity Ronin Bridge hack, the $321-million Wormhole Bridge hack, the $100-million BNB Cross-Chain Bridge exploit and many others.

Given the apparently endless stream of bad actors in the ecosystem, should developers and protocol team members try and negotiate with hackers to attempt to recover most of the users assets?

1/ After four hacks yesterday, October is now the biggest month in the biggest year ever for hacking activity, with more than half the month still to go. So far this month, $718 million has been stolen from #DeFi protocols across 11 different hacks. pic.twitter.com/emz36f6gpK

— Chainalysis (@chainalysis) October 12, 2022

Should you negotiate with hackers? Yes. 

One of the greatest supporters of such a strategy is no other than ImmuneFi CEO Mitchell Amador. According to the blockchain security executive, developers have a duty to attempt communication and negotiation with malevolent hackers, even after they have robbed you, no matter how distasteful it may be.

ImmuneFis CEO Mitchell Amador
ImmuneFis CEO, Mitchell Amador. Source: LinkedIn

Its like when someone has chased you into an alley, and they say, Give me your wallet, and beat you up. And youre like, Wow, thats wrong; thats not nice! But the reality is, you have a responsibility to your users, to investors and, ultimately, to yourself, to protect your financial interest, he says.

And if theres even a low percentage chance, say, 1%, that you can get that money back by negotiating, thats always better than just letting them run away and never getting the money back.

Amador cites the example of the Poly Network hack last year. After post-facto negotiations, hackers returned back $610 million in exchange for between $500,000 to $1 million in bug bounty. When such an event occurs, the best and ideal, the most effective solution overwhelmingly, is going to be negotiation, he says.

For CertiK director of security operations Hugh Brooks, being proactive is better than reactive, and making a deal is only sometimes an ideal option. But he adds it can also be a dangerous road to go down.

Some of these hacks are obviously perpetrated by advanced persistent threat groups like the North Korean Lazarus Group and whatnot. And if you are negotiating with North Korean entities, you can get in a lot of trouble.

However, he points out that the firm has tracked 16 incidents involving $1 billion in stolen assets, around $800 million of which was eventually returned.

So, its certainly worth it. And some of those were voluntary returns of funds initiated by the hacker themselves, but for the most part, it was due to negotiations.

Perhaps the Poly Network hacker really just wanted a small bounty for his efforts
Perhaps the Poly Network hacker really just wanted a small bounty for his efforts. Source: Tom Robinson via Twitter

Should you negotiate with hackers? No.

Not every security expert is on board with the idea of rewarding bad actors. Chainalysis vice president of investigations Erin Plante is fundamentally opposed to paying scammers. She says giving in to extortion is unnecessary when alternatives exist to recover funds.

Plante elaborates that most DeFi hackers are not after $100,000 or $500,000 payouts from legitimate bug bounties but frequently ask upward of 50% or more of the gross amount of stolen funds as commission. Its basically extortion; its a very large amount of money that is being asked for, she states. 

She instead encourages Web3 teams to contact qualified blockchain intelligence companies and law enforcement if they find themselves in an incident.

Weve seen more and more successful recoveries that are not publicly disclosed, she says. But its happening, and its not impossible to get funds back. So, in the end, jumping into paying off scammers may not be necessary.

Many funds have been lost in DeFi exploits this year
Many funds have been lost in DeFi exploits this year. Source: Token Terminal

Should you call the police about DeFi exploits?

There is a perception among many in the crypto community that law enforcement is pretty hopeless when it comes to successfully recovering stolen crypto. 

In some cases, such as this years $600-million Ronin Bridge exploit, developers did not negotiate with North Korean hackers. Instead, they contacted law enforcement, who were able to quickly recover a portion of users funds with the help of Chainalysis.

But in other cases, such as in the Mt. Gox exchange hack, users funds amounting to approximately 650,000 BTC are still missing despite eight years of extensive police investigations.

Amador is not a fan of calling in law enforcement, saying that its not a viable option.

Not all hackers are interested in striking bounty deals with developers
Not all hackers are interested in striking bounty deals with developers. Source: Nomad Bridge

The option of law enforcement is not a real option; it is a failure, Amador states. Under those conditions, typically, the state will keep what it has taken from the relevant criminals. Like we saw with enforcement actions in Portugal, the government still owns the Bitcoin theyve seized from various criminals.

He adds that while some protocols may wish to use the involvement of law enforcement as a form of leverage against the hackers, its actually not effective because once youve unleashed that force, you cannot take it back. Now its a crime against the state. And theyre not just going to stop because you negotiated a deal and got the money back. But youve now destroyed your ability to come to an effective solution.

Read also
Features

How to bake your own DAO at home With just 5 ingredients!

Features

Why Animism Gives Japanese Characters a NiFTy Head Start on the Blockchain

Brooks, however, believes you are obligated to get law enforcement involved at some point but warns the results are mixed, and the process takes a long time.

Law enforcement has a variety of unique tools available to them, like subpoena powers to get the hackers IP addresses, he explains.

Chainalysis VP of Investigations Erin Plante
Chainalysis VP of investigations, Erin Plante. Source: LinkedIn

If you can negotiate upfront and get your funds back, you should do that. But remember, its still illegal to obtain funds through hacking. So, unless there was a full return, or it was within the realm of responsible disclosure bounty, follow up with law enforcement. In fact, hackers often become white-hats and return at least some money after law enforcement is alerted.

Plante takes a different view and believes the effectiveness of police in combating cybercrime is often poorly understood within the crypto community. 

Victims themselves are often working confidentially or under some confidential agreement, she explains. For example, in the case of Axie Infinitys announcement of funds recovery, they had to seek approval from law enforcement agencies to announce that recovery. So, just because recoveries arent announced doesnt mean that recoveries arent happening. Theres been a number of successful recoveries that are still confidential.

How to fix DeFi vulnerabilities

Asked about the root cause of DeFi exploits, Amador believes that hackers and exploiters have the edge due to an imbalance of time constraints. Developers have the ability to create resilient contracts, but resiliency is not enough, he explains, pointing out that hackers can afford to spend 100 times as many hours as the developer did just to figure out how to exploit a certain batch of code.

Subscribe
The most engaging reads in blockchain. Delivered once a week.


    Subscribe to Magazine by Cointelegraph Newsletter.

    Amador believes that audits of smart contracts, or one point-in-time security tests, are no longer sufficient to prevent protocol breaches, given the vast majority of hacks have targeted audited projects.

    Instead, he advocates for the use of bug bounties to, in part, delegate the responsibility of defending protocols to benevolent hackers with time on their hands to level out the edge: When we started on ImmuneFi, we had a few hundred white-hat hackers. Now we have tens of thousands. And that is like an incredible new tool because you can get all that enormous manpower protecting your code, he says. 

    For DeFi developers wanting to build the most secure outcome, Amador recommends a combination of defensive measures:

    First, get the best people to audit your code. Then, place a bug bounty, where you will get the best hackers in the world, to the tune of hundreds of thousands, to check your code in advance. And if all else fails, build a set of internal checks and balances to see if any funny business goes on. Like, thats a pretty amazing set of defenses.

    Brooks agrees and says part of the issue is there are a lot of developers with big Web3 ideas but who lack the required knowledge to keep their protocols safe. For example, a smart contract audit alone is not enough you need to see how that contract operates with oracles, smart contracts, with other projects and protocols, etc.

    Thats going to be far cheaper than getting hacked and trying your luck at having funds returned.

    Stand your ground against thieves 

    Best to avoid getting hacked in the first place. Source: Pexels

    Plante says cryptos open-source nature makes it more vulnerable to hacks than Web2 systems.

    If youre working in a non-DeFi software company, no one can see the code that you write, so you dont have to worry about other programmers looking for vulnerabilities. Plante adds, The nature of it being public creates those vulnerabilities in a way because you have bad actors out there who are looking at code, looking for ways they can exploit it.

    The problem is compounded by the small size of certain Web3 companies, which, due to fundraising constraints or the need to deliver on roadmaps, may only hire one or two security experts to safeguard the project. This contrasts with the thousands of cybersecurity personnel at Web2 firms, such as Google and Amazon. Its often a much smaller team thats dealing with a big threat, she notes

    But startups can also take advantage of some of that security know-how, she says. 

    Its really important for the community to look to Big Tech firms and big cybersecurity firms to help with the DeFi community and the Web3 community as a whole, says Plante. If youve been following Google, theyve launched validators on Google Cloud and became one the Ronin Bridge, so having Big Tech involved also helps against hackers when youre a small DeFi project. 

    It was an honor to speak at #AxieCon and share the successful recovery of $30M in crypto that was stolen from the Ronin Bridge. In these hack investigations it is a long road to recovery. But the Axie Infinity community is strong and we will continue to partner in this fight. https://t.co/V0lwrOtThr

    — Erin Plante (@eeplante) September 8, 2022

    In the end, the best offense is defense, she says and theres an entire population of white-hat hackers ready and willing to help. 

    Theres a community of Certified Ethical Hackers, which I am a part of, says Erin. And the ethos of that group is to look for vulnerabilities, identity, and close them for the larger community. Considering many of these DeFi exploits arent very sophisticated, they can be resolved before extreme measures, such as waiting for a break-in, theft of funds and requesting a ransom.

    Related articles

    White House Crypto Advisor Denounces Attempts To Sabotage CLARITY Act’s Goals

    White House Crypto Advisor Denounces Attempts To Sabotage CLARITY Act’s Goals

    March 12, 2026

    AI agent payment volumes lower than reported, but adoption is growing: a16z

    March 12, 2026
    Read also
    Features

    Why Grayscale’s New Digital Currency Ad Could Bring Crypto Investing To Millions

    Features

    The Road to Bitcoin Adoption is Paved with Whole Numbers

    Read Entire Article
    Tags: CointelegraphCryptocurrencyInvestmentMining Bitcoin
    Share76Tweet47

    Related Posts

    White House Crypto Advisor Denounces Attempts To Sabotage CLARITY Act’s Goals

    White House Crypto Advisor Denounces Attempts To Sabotage CLARITY Act’s Goals

    by Jon Hartney
    March 12, 2026
    0

    No progress has been made recently on the delayed CLARITY Act, the crypto market structure bill, primarily due to opposition...

    AI agent payment volumes lower than reported, but adoption is growing: a16z

    by Jon Hartney
    March 12, 2026
    0

    Andreessen Horowitz partner Noah Levine says AI agents made $16 million in payments in the past month, which “is not...

    Kalshi preemptively sues Iowa, claiming risk of enforcement action

    by Jon Hartney
    March 12, 2026
    0

    Kalshi claims in a preemptive lawsuit that there is “a substantial risk” that Iowa will take action against it after...

    Stablecoin yields will bring fresh money to US banks: White House’s Witt

    by Jon Hartney
    March 12, 2026
    0

    Global demand for the US dollar is “massive,” and stablecoin yields will only bring more interest to the currency, argued...

    Dogecoin (DOGE) Pullback Sparks Tension — Will Support Hold?

    Dogecoin (DOGE) Pullback Sparks Tension — Will Support Hold?

    by Jon Hartney
    March 12, 2026
    0

    Dogecoin corrected some gains and traded below $00950 against the US Dollar DOGE is now holding the $00915 support and...

    Load More
    • Trending
    • Comments
    • Latest
    SUI Price Hits All-Time High – But Questions About Valuation Remain

    SUI Price Hits All-Time High – But Questions About Valuation Remain

    October 17, 2024
    Solana Targets $160 Resistance As TVL Hits New Yearly Highs

    Solana Targets $160 Resistance As TVL Hits New Yearly Highs

    October 17, 2024
    Dogecoin Holder Base Falls To 6-Month Low, But Analyst Believes DOGE Price Is Headed To $10

    Dogecoin Holder Base Falls To 6-Month Low, But Analyst Believes DOGE Price Is Headed To $10

    October 17, 2024
    Bitcoin Price Holds Firm: Can It Power Toward New Gains?

    Bitcoin Price Holds Firm: Can It Power Toward New Gains?

    October 17, 2024
    All aboard! Elon Musk’s Vegas Loop now taking Dogecoin payments

    All aboard! Elon Musk’s Vegas Loop now taking Dogecoin payments

    0
    Crypto owners banned from working on US Government crypto policies

    Crypto owners banned from working on US Government crypto policies

    0
    Korean startup Uprise lost $20M shorting LUNC

    Korean startup Uprise lost $20M shorting LUNC

    0
    Ethereum testnet Merge mostly successful — ‘Hiccups will not delay the Merge.’

    Ethereum testnet Merge mostly successful — ‘Hiccups will not delay the Merge.’

    0
    White House Crypto Advisor Denounces Attempts To Sabotage CLARITY Act’s Goals

    White House Crypto Advisor Denounces Attempts To Sabotage CLARITY Act’s Goals

    March 12, 2026

    AI agent payment volumes lower than reported, but adoption is growing: a16z

    March 12, 2026

    Kalshi preemptively sues Iowa, claiming risk of enforcement action

    March 12, 2026

    Stablecoin yields will bring fresh money to US banks: White House’s Witt

    March 12, 2026

    XBT.Market

    This website is an automated news feed powered by the Nebulome cloud system. The site is made possible by YYC TECH Consulting and Alberta Digital Mining Company. As a team with major crypto and bitcoin enthusiasm, we have curated major sources of news, trading and financial data to bring you, our viewer, an unbiased source of truth.

    Recent Posts

    • White House Crypto Advisor Denounces Attempts To Sabotage CLARITY Act’s Goals March 12, 2026
    • AI agent payment volumes lower than reported, but adoption is growing: a16z March 12, 2026
    • Kalshi preemptively sues Iowa, claiming risk of enforcement action March 12, 2026
    • Stablecoin yields will bring fresh money to US banks: White House’s Witt March 12, 2026
    • Dogecoin (DOGE) Pullback Sparks Tension — Will Support Hold? March 12, 2026

    News Categories

    • Bitcoin
    • Blockchain
    • Business
    • Market

    Tags

    bitcoinMagzine Cointelegraph Cryptocurrency insidebitcoins Investment Mining Bitcoin NewsBTC

    Quicklinks

    • Home
    • Coins MarketCap
    • Crypto Exchanges
    • Crypto Calculator
    • Top Gainers and Loser
    • News
    • Contact Us

    © 2022 Xbt.Market - Powered by YYC Tech Consulting & ADMCO.

    No Result
    View All Result
    • Home
    • Coins MarketCap
    • Crypto Exchanges
    • Crypto Calculator
    • Top Gainers and Loser
    • News
    • Contact Us

    © 2022 Xbt.Market by Nebulome.

    • Steakhouse EURCV Morpho VaultSteakhouse EURCV Morpho Vault(STEAKEURCV)$0.000000-100.00%
    • FibSwap DEXFibSwap DEX(FIBO)$0.0084659.90%
    • TruFin Staked APTTruFin Staked APT(TRUAPT)$8.020.00%
    • bitcoinBitcoin(BTC)$84,372.003.58%
    • ethereumEthereum(ETH)$1,885.365.68%
    • tetherTether(USDT)$1.000.00%
    • rippleXRP(XRP)$2.186.84%
    • USDEXUSDEX(USDEX)$1.07-0.53%
    • binancecoinBNB(BNB)$617.995.03%
    • Wrapped SOLWrapped SOL(SOL)$143.66-2.32%
    • solanaSolana(SOL)$128.974.23%
    • usd-coinUSDC(USDC)$1.000.01%
    • dogecoinDogecoin(DOGE)$0.1736117.78%
    • cardanoCardano(ADA)$0.687.61%
    • tronTRON(TRX)$0.2342340.79%
    • staked-etherLido Staked Ether(STETH)$1,884.065.48%
    • Gaj FinanceGaj Finance(GAJ)$0.0059271.46%
    • Content BitcoinContent Bitcoin(CTB)$24.482.55%
    • USD OneUSD One(USD1)$1.000.11%
    • wrapped-bitcoinWrapped Bitcoin(WBTC)$84,309.003.84%
    • ToncoinToncoin(TON)$4.157.66%
    • UGOLD Inc.UGOLD Inc.(UGOLD)$3,042.460.08%
    • ParkcoinParkcoin(KPK)$1.101.76%
    • chainlinkChainlink(LINK)$14.027.76%
    • leo-tokenLEO Token(LEO)$9.211.17%
    • stellarStellar(XLM)$0.2743585.70%
    • avalanche-2Avalanche(AVAX)$19.647.71%
    • Wrapped stETHWrapped stETH(WSTETH)$2,256.395.40%
    • USDSUSDS(USDS)$1.00-0.01%
    • SuiSui(SUI)$2.429.03%
    • shiba-inuShiba Inu(SHIB)$0.0000137.71%
    • hedera-hashgraphHedera(HBAR)$0.17284810.00%
    • Yay StakeStone EtherYay StakeStone Ether(YAYSTONE)$2,671.07-2.84%
    • polkadotPolkadot(DOT)$4.257.34%
    • litecoinLitecoin(LTC)$85.265.04%
    • bitcoin-cashBitcoin Cash(BCH)$314.248.23%
    • mantra-daoMANTRA(OM)$6.301.94%
    • Pundi AIFXPundi AIFX(PUNDIAI)$16.000.00%
    • PengPeng(PENG)$0.60-13.59%
    • Bitget TokenBitget Token(BGB)$4.664.95%
    • wethWETH(WETH)$1,884.285.66%
    • Ethena USDeEthena USDe(USDE)$1.00-0.04%
    • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.00-0.18%
    • MurasakiMurasaki(MURA)$4.23-13.71%
    • Black PhoenixBlack Phoenix(BPX)$3.351,000.00%
    • Pi NetworkPi Network(PI)$0.714.53%
    • HyperliquidHyperliquid(HYPE)$13.729.80%
    • Wrapped eETHWrapped eETH(WEETH)$2,003.675.53%
    • WhiteBIT CoinWhiteBIT Coin(WBT)$28.350.76%
    • moneroMonero(XMR)$217.841.31%
    • Zypto TokenZypto Token(ZYPTO)$0.037139-3.47%
    • uniswapUniswap(UNI)$6.217.66%
    • AptosAptos(APT)$5.395.79%
    • PepePepe(PEPE)$0.00000811.37%
    • daiDai(DAI)$1.00-0.01%
    • nearNEAR Protocol(NEAR)$2.635.26%
    • XT.comXT.com(XT)$3.08-1.65%
    • Layer One XLayer One X(L1X)$23.35454.66%
    • sUSDSsUSDS(SUSDS)$1.050.05%
    • okbOKB(OKB)$48.762.12%
    • gatechain-tokenGate(GT)$22.883.58%
    • crypto-com-chainCronos(CRO)$0.1015853.46%
    • Coinbase Wrapped BTCCoinbase Wrapped BTC(CBBTC)$84,342.003.68%
    • MantleMantle(MNT)$0.814.44%
    • Tokenize XchangeTokenize Xchange(TKX)$33.460.86%
    • internet-computerInternet Computer(ICP)$5.517.85%
    • ethereum-classicEthereum Classic(ETC)$17.074.81%
    • OndoOndo(ONDO)$0.817.47%
    • First Digital USDFirst Digital USD(FDUSD)$1.00-0.12%
    • aaveAave(AAVE)$168.6110.19%
    • Aerarium FiAerarium Fi(AERA)$7.14-13.11%
    • Ethena Staked USDeEthena Staked USDe(SUSDE)$1.170.30%
    • BSCEXBSCEX(BSCX)$237.310.49%
    • Official TrumpOfficial Trump(TRUMP)$10.354.36%
    • vechainVeChain(VET)$0.0233636.04%
    • cosmosCosmos Hub(ATOM)$4.538.09%
    • fantomFantom(FTM)$0.70-1.56%
    • BittensorBittensor(TAO)$231.277.72%
    • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
    • EthenaEthena(ENA)$0.3616194.37%
    • render-tokenRender(RENDER)$3.6710.91%
    • filecoinFilecoin(FIL)$2.927.72%
    • CelestiaCelestia(TIA)$3.181.75%
    • Black AgnusBlack Agnus(FTW)$0.000183423.46%
    • Lombard Staked BTCLombard Staked BTC(LBTC)$84,465.004.02%
    • POL (ex-MATIC)POL (ex-MATIC)(POL)$0.2063993.13%
    • KaspaKaspa(KAS)$0.0682239.38%
    • STAUSTAU(STAU)$0.17397910.95%
    • FasttokenFasttoken(FTN)$4.020.01%
    • Sonic (prev. FTM)Sonic (prev. FTM)(S)$0.5212.98%
    • algorandAlgorand(ALGO)$0.1896979.65%
    • ORA CoinORA Coin(ORA)$4.885.92%
    • ArbitrumArbitrum(ARB)$0.3397526.22%
    • Arbitrum Bridged USDT (Arbitrum)Arbitrum Bridged USDT (Arbitrum)(USDT)$1.000.07%
    • GGTKNGGTKN(GGTKN)$0.1121180.75%
    • kucoin-sharesKuCoin(KCS)$11.231.19%
    • Solv Protocol SolvBTCSolv Protocol SolvBTC(SOLVBTC)$84,076.003.32%
    • fetch-aiArtificial Superintelligence Alliance(FET)$0.4856098.68%
    • optimismOptimism(OP)$0.776.43%
    • StoryStory(IP)$4.75-2.68%