このコンテンツは現在日本語に翻訳中です。
What is white-hat recovery, and how does it actually happen?
White-hat recovery covers a few different scenarios: the first is an independent security researcher, after an attack, racing to use the same exploit before a malicious attacker can act further, moving whatever remaining vulnerable assets haven't been stolen yet to a safe address for safekeeping, then returning them to the project; the second is the project team or community members directly negotiating publicly with the attacker, offering that if the attacker voluntarily returns the majority of assets, the team won't pursue prosecution or will offer a bounty in exchange (this kind of bounty negotiation is sometimes called a "white-hat agreement" in the industry); the third is the attacker voluntarily choosing to return some or all of the assets themselves, possibly out of guilt, fear of being traced and prosecuted, or simply judging that the risk of being publicly identified outweighs the benefit of keeping the assets.
While these three scenarios play out differently, they share a common trait: all of them happen after assets have already been moved on-chain — this is a post-hoc remediation mechanism, not something that can prevent a loss from happening in the first place.
Why does a mechanism like white-hat recovery exist at all, and is there anything comparable in traditional finance?
Once crypto assets have been moved through an on-chain transaction, a mechanism like a traditional bank freezing an account usually doesn't exist or is hard to directly apply — no centralized institution can unilaterally freeze the assets held at an on-chain address. This decentralized characteristic is one of crypto's core value propositions, but it also means that once assets are in an attacker's hands, forcibly recovering them through traditional legal or financial mechanisms is far harder than in a traditional financial fraud case.
The emergence of white-hat recovery is, in some sense, a practice the industry itself developed to partially fill that structural gap — using the blockchain's own transparency (anyone can see exactly where assets got moved) and negotiation leverage (the attacker's real choice is between "return part of the assets and walk away clean" versus "keep everything but keep carrying the risk of being traced and prosecuted") to create a middle ground between "completely unrecoverable" and "traditional legal enforcement."
ホワイトハットによる資産回収は実際どのように機能し、報奨金交渉には通常どんな詳細が伴いますか?
報奨金交渉を例にとると、プロジェクト側は通常まずオンチェーンのメッセージ(攻撃者が資産を保有しているアドレスにメッセージ付きのゼロ金額の取引を送るなど)やコミュニティの公開チャネルを通じて、攻撃者に交渉の意思があることを伝え、具体的な条件を提示する:例えば攻撃者が資産の90%を返還し、残りの10%を「ホワイトハット報奨金」として攻撃者が保持できるようにし、その交換条件としてプロジェクト側は法的責任を追及せず、(まだ身元が公開されていない場合は)攻撃者の身元も公開しないことを約束する。この報奨金の割合は固定されておらず、事件ごとに一桁台の割合から3割近くまで、交渉プロセスにおける双方の相対的な交渉力によって様々な結果がある。
同じ脆弱性を利用して資産を先んじて移動させるホワイトハット救済のシナリオは、より技術的な操作に偏る——セキュリティ研究者は極めて短時間で(しばしば悪意ある攻撃者との実際の時間との競争になる)攻撃経路を分析し複製し、脆弱性がさらに悪用される前に、まだ盗まれていない資産を安全なアドレスに移動させる必要がある。この行動自体は法的・倫理的に曖昧な領域にある。なぜなら技術的には研究者も資産の所有者の明確な承認を得ずに資産を動かしているからであり、唯一の違いは意図である。
ホワイトハットによる資産回収は一般ユーザーにどのような実際の影響を与えますか?この仕組みを全体のリスク評価にどう位置づければいいですか?
過去にセキュリティインシデントを経験したことのあるDeFAI製品を評価している際、「ホワイトハット交渉を通じて一部の資産が回収された」といった記録を見たとしても、注目すべきなのは、これがそのプラットフォームの安全性がそれによってより信頼できるようになったことを意味するわけではないという点だ。ホワイトハットによる回収は、運と交渉力に大きく依存する事後的な救済メカニズムであり、プラットフォームの安全設計の一部ではない。回収に成功するかどうかは、攻撃者個人の選択や、事件が公になった後のコミュニティとメディアの注目度合いに大きく左右され、これらはユーザーもプラットフォーム側も事前にコントロールできない変数である。
より現実的な態度は、ホワイトハットによる資産回収の可能性を、「もし本当に起きれば、いくらかの追加の緩衝材になるかもしれない」という確率的な要因として扱うことであり、投入する金額の大きさを決める上での中心的な考慮事項に組み込むことではない。これは本シリーズで繰り返し強調してきた原則と一致する——ポジションサイズの判断基準は「このお金が完全に戻ってこなくても受け入れられる」という前提の上に築かれるべきであり、いかなる形の事後回収の可能性(法的手段であれホワイトハット交渉であれ)も、起きれば嬉しい予想外の出来事にすぎず、あなたのリスク計画の中で当然起きるものと想定すべき要素ではない。
2021年、約6億ドルの損失が発生したPoly Networkの事件では、事件が公になりコミュニティとオンチェーン分析からの継続的な圧力を受けた後、攻撃者は最終的に盗まれた資産の大部分を返還することを選んだ。その後のコミュニケーションで、動機の一部はプロトコル自体のセキュリティ上の脆弱性を浮き彫りにすることだったと述べている。この事件は、暗号資産業界でホワイトハットによる資産回収メカニズムを議論する際に最も頻繁に引用される事例の一つとなっている。
The advantage is that, given crypto assets' structural lack of a traditional finance-style freezing mechanism, this offers a remediation possibility somewhere between completely unrecoverable and traditional legal enforcement, and some past incidents have genuinely recovered the majority of losses through this mechanism; the drawback is that it's highly unpredictable and can't be institutionally guaranteed — success depends on variables outside a user's control, like the attacker's personal motivation and the level of community pressure, and it shouldn't be treated as a default cushion in your risk assessment.