RISEx XLP Vault exploit team publicly negotiates with attacker offering 20% bounty retention if remaining 80% ($538k USDC) is returned by September 23 deadline.
Security & Exploits ·
The team behind the RISEx XLP Vault, which was exploited on August 3rd, has made a public offer to the attacker via onchain message. The proposal grants the attacker retention of 20% of the stolen funds—134,566 USDC—in exchange for returning the remaining 80%, worth 538,265 USDC or its equivalent in ETH, to a specified Ethereum or Base address by 12pm AEST on September 23rd. If the funds are returned by that deadline, the team indicated it would classify the incident as a whitehat disclosure.
The message was posted by an address associated with the vault team after detecting movement of the stolen assets. The offer represents a shift from prior negotiations, explicitly framing the bounty structure as an incentive for full recovery. The attacker would keep a material portion while avoiding the legal and reputational consequences of retaining stolen cryptocurrency.
The outcome remains uncertain: whether the attacker accepts the terms, chooses to return funds under different conditions, or continues to hold or move the assets remains undetermined. The September 23rd deadline provides a concrete window, though enforcement mechanisms and the enforceability of such an arrangement are not addressed in the onchain message.