Bitget asks THORChain to block hacker addresses, protocol refuses
The cross-chain DEX says decentralization prevents it from censoring transactions, reigniting debate over responsibility for stolen funds.
The short answer
After hackers stole $387.5 million from Bitget on September 24, CEO Gracy Chen asked THORChain to block addresses linked to the attackers. THORChain declined, saying its permissionless design prevents it from censoring transactions, comparing itself to Bitcoin and Ethereum.
What happened
Hackers breached Bitget and stole $387.5 million. Within hours, they began moving stolen funds through various routes to obscure their trail. They first converted USDT and USDC into ETH and BNB to sidestep freezes by stablecoin issuers. Tether and Circle managed to freeze $318,000 worth of tokens before the funds escaped.
Over the next 13 hours, the attackers routed millions in ETH and BNB through THORChain, a cross-chain protocol that enables direct swaps between blockchains. This allowed them to convert part of the stolen funds into native Bitcoin and spread it across thousands of private wallets. THORChain processed about $4 million to $4.5 million in stolen assets during this period.
Bitget CEO Gracy Chen publicly requested that THORChain block the attacker addresses. Chen argued that decentralization should not shield networks from acting against known stolen funds. THORChain rejected the request, saying its permissionless design works like Bitcoin and Ethereum, preventing it from censoring transactions.
Why it matters
The dispute highlights a fundamental tension in crypto: whether decentralization means networks must remain neutral even when handling clearly identified stolen funds. THORChain's refusal echoes a longstanding principle that permissionless systems cannot pick which transactions to allow. However, critics argue that THORChain differs from base-layer chains like Bitcoin and Ethereum because its validators collectively control assets in its vaults and can act collectively.
This is not THORChain's first encounter with hacked funds. After the Bybit hack in February 2025, an estimated $1.2 billion in stolen assets moved through THORChain as funds from the North Korean Lazarus Group. The pattern suggests the protocol has become a preferred conduit for moving large amounts of stolen funds.
What is still unclear
- Whether THORChain validators could technically block specific addresses if they coordinated to do so remains disputed, as OKX founder Star Xu pointed out that the network did pause itself for 13 hours in May after its own vaults were drained.
Questions readers ask
How much money did hackers steal from Bitget?
Hackers stole $387.5 million from Bitget on September 24, 2026. They moved about $4 million to $4.5 million of it through THORChain and converted it into Bitcoin. Tether and Circle froze $318,000 in stablecoins before the funds escaped.
Why did THORChain refuse to block the hacker addresses?
THORChain said it operates as a decentralized, permissionless network similar to Bitcoin and Ethereum, and blocking selected transactions would contradict how the protocol functions. Blocking transactions would require censoring specific addresses, which the protocol says goes against its design.
Has this happened before with THORChain?
Yes. After Bybit was hacked in February 2025, an estimated $1.2 billion in stolen funds moved through THORChain connected to the North Korean Lazarus Group. Despite FBI pressure, THORChain did not block those transactions either.
What do security experts say about THORChain's response?
SlowMist founder Cosine and OKX founder Star Xu questioned THORChain's decision, arguing that the protocol's validators can act collectively and have paused the network before. Critics say this differs from base-layer chains like Bitcoin, where no central authority can intervene.