Alephium bridge exploit — team publicly offers white hat deal: return 90% of drained assets within 24 hours and retain 10% as bounty.
Security & Exploits ·
Alephium's team has publicly offered a settlement to the actor behind a recent bridge exploit, posting an onchain message that proposes treating the incident as a white hat disclosure. The offer grants the exploiter 24 hours to return 90% of the drained assets to a specified address, with the option to retain 10% as a bounty in exchange for cooperation and the team's public acknowledgment that the matter is resolved.
The proposal frames compliance as an alternative to law enforcement involvement, though it does not specify the total value extracted or provide technical details of how the bridge was compromised. The message was transmitted via Ethereum mainnet, suggesting the exploit may have involved assets bridged across chains.
It remains unclear whether the exploiter will respond to the offer, whether they have the ability or intent to return funds, and what steps Alephium intends to take if the 24-hour deadline passes without action. The team has not yet disclosed a postmortem, patch status, or guidance for affected users.