MCAP $2.89T ▼ 1.59% 24H VOL $100.3B BTC.D 58.4% FEAR & GREED 71 Greed BTC FEE 3 sat/vB BTC $84,074 ▲ 1.15% ETH $2,684 ▲ 0.32% USDT $0.9997 ▼ 0.01% BNB $768.95 ▲ 2.17% XRP $1.50 ▲ 1.29% USDC $0.9999 ▼ 0.01% SOL $119.63 ▲ 1.48% TRX $0.3380 ▲ 0.87% ZEC $1,455 ▲ 4.37% FIGR_HELOC $1.03 ▲ 2.92%

Hacks & Security

Could THORChain face prosecution over stolen Bitget funds

A lawyer says blocking hacker addresses can create legal risk, while SlowMist traces Bitget's stolen funds into BTC.

CoinDesk AI Desk
· 4 min read
✓ 2 SOURCES CHECKED
Could THORChain face prosecution over stolen Bitget funds
Image: Cointelegraph

Key takeaways

  1. THORChain cannot block. THORChain retired its admin key, so it says it has no easy way to censor addresses tied to the $387.5 million Bitget hack.
  2. NEAR Intents blocked funds. Its SHIELD program stopped $50 million in swaps and turned down Bitget's 5% bounty.
  3. Funds moved into BTC. SlowMist says the hackers converted stolen funds to BTC through CoW Protocol and Chainflip orders.

What happened

Suspected North Korean hackers took $387.5 million from Bitget, and investigators flagged and traced the recipient addresses. Bitget CEO Gracy Chen then demanded that THORChain refuse service to those addresses. THORChain said it is decentralized and permissionless and does not censor by design.

SlowMist traced the theft to August 31, when a service on a third-party product was compromised through a zero-day vulnerability. The attacker later used an internal employee identity on September 25. Logs show the theft began executing at 01:49 that day, with on-chain activity starting at 02:31.

Transfers continued across several blockchains until 05:23, covering about 2 hours and 52 minutes. Chainflip rejected one attempted deposit with the message 'Deposit rejected by the broker,' but the funds were refunded rather than frozen. Bitget attributed the incident to a backend system in its wallet infrastructure, not a stolen private key, and said its User Protection Fund will cover those affected.

Why it matters

Crypto lawyer Yuriy Brisov of D&A Partners told Magazine that the answer depends on the level of decentralization. When a protocol blocks addresses, he said, it shows its nodes are not truly decentralized. That can help stop malicious activity, but it also opens the protocol to other legal claims.

Brisov called 'we are decentralized' the strongest defense for any DeFi protocol. If a protocol shows it can block, control or interfere, even to prevent fraud in good faith, he said it opens itself to claims that it should apply due diligence, KYC and AML measures.

He also asked why control would be used in one case and not another, and why a platform would not check all of its token issuers. NEAR Intents blocked addresses tied to the hack and now faces criticism from decentralization supporters for not being permissionless enough.

What the data shows

The reported loss at Bitget is $387.5 million. NEAR Intents blocked $50 million in swaps and turned down a 5% bounty. SlowMist said the transfers from the Bitget theft ran for about 2 hours and 52 minutes.

Background

The dispute has come up before. THORChain was used to swap around $1.2 billion of the funds stolen in the $1.46 billion Bybit hack, and its admin key had been retired just 11 days earlier. Its own protocol was halted in May after $10.7 million of its own funds were exploited. THORChain has retired its admin key and does not have an easy way to censor addresses, even if it wanted to.

In the Uniswap case, Brisov noted, the protocol said it was truly decentralized and there was nothing it could do. Investors who bought 38 rugpull and scam tokens sued, and a judge dismissed the case in March.

What is still unclear

  • Brisov says the legal answer depends on the level of decentralization, which leaves the liability question open.
  • Brisov asks why a protocol would use control in one case but not another, and why it would not check all of its token issuers.

Questions readers ask

Did THORChain block the addresses linked to the Bitget hack?

No. THORChain said it is decentralized and permissionless and does not censor by design. It has retired its admin key and does not have an easy way to censor addresses.

How much was stolen from Bitget?

The reported loss is $387.5 million. Bitget has said its User Protection Fund will cover those affected by the incident.

How did the hackers move the funds?

SlowMist says they paired CoW Protocol orders with Chainflip deposit addresses and converted the proceeds to Bitcoin, then used CoinJoin. Chainflip rejected one attempted deposit, but the funds were refunded rather than frozen.

Could THORChain be prosecuted over the stolen funds?

Crypto lawyer Yuriy Brisov says it depends on the level of decentralization. He says 'we are decentralized' is the strongest defense for a DeFi protocol, but that showing control, even in good faith, can open a protocol to other claims.

Sources · 2 publishers

  1. Cointelegraph TIER 1 FIRST REPORT
    Could THORChain face prosecution over stolen Bitget funds?
  2. CryptoPotato TIER 2
    Stolen Bitget Funds Converted to BTC via CoW, Chainflip: Report