Read as article
THORChain Refuses Bitget's Plea to Block Hacker Funds
By @sharedot · · 6 pages
THORChain rejected Bitget CEO Gracy Chen's formal request to refuse service to hackers routing her exchange's $387.5 million theft into Bitcoin.
The Request and the Rejection
Two days after the 24 September 2026 breach of Bitget, CEO Gracy Chen publicly asked THORChain to refuse service to the attacker addresses. "Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds," Chen wrote on X. THORChain's official account rejected the appeal, calling the protocol "decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain" and asking what responsibility those chains should bear when handling known stolen funds. Bitcoin News reported the exchange now estimates approximately $387.5 million was transferred to attacker-controlled addresses, up from its earlier $351 million figure.
How the Hackers Used THORChain
According to Coinpedia, blockchain security firms TRM Labs and SlowMist's MistTrack traced the stolen funds: the hackers swapped stolen USDT and USDC into ETH and BNB to dodge issuer freezes, though Circle and Tether still managed to freeze about $318,000 combined. Over the next 13 hours, the attackers pushed millions in ETH and BNB through THORChain, a cross-chain protocol allowing direct swaps without wrapped tokens, converting part of the loot into native Bitcoin. Bitcoin News reports tens of millions in XRP were deposited into THORChain vaults, with another stash already swapped for BTC and then peeled across myriad Bitcoin addresses. So far, roughly $4 million to $4.5 million of the stolen $387.5 million has been converted into Bitcoin via THORChain, per Coinpedia, and the hackers are also using Chainflip, Uniswap, 1inch Fusion, Stargate, Across, and Relay, according to Bitcoin News.
Why Critics Say THORChain Is Being Selective
The refusal has drawn sharp pushback because THORChain has shown it can act when its own money is at risk. Coinpedia notes developers once used a "red button" to pause the network during an exploit, and Bitcoin News reports that after the May 2026 GG20 exploit drained roughly $10.7 to $11 million from a vault, operators paused the network and it stayed down for weeks. Coinpedia also cites the 2021 network halt and the January 2025 freeze of ThorFi withdrawals by node vote as precedents. A post quoted by Coinpedia argues "decentralized and permissionless seems to apply only when it's other people's money." SlowMist founder Cosine questioned the network's response, according to Coinpedia, and critics note THORChain continues processing stolen funds and collecting fees.
The Bybit Precedent and What Comes Next
This standoff echoes the Bybit fight. Bitcoin News reports THORChain was used to move $1.2 to $1.5 billion in stolen Bybit funds, and after the FBI asked the industry to block DPRK-linked addresses, three validators voted to halt ETH trading — only for four validators to reverse the decision half an hour later. A developer quit over the episode, and THORChain front ends have screened flagged addresses for years, though that can be bypassed. Given that history, Bitcoin News assesses validators are unlikely to block the Bitget funds either. Meanwhile the attacker keeps moving: Bitcoin News reports a wallet tied to the hack pulled about $1.23 million in ether from Binance just before withdrawals reopened Monday, and Coinpedia notes $83 million in stolen XRP is moving on-chain. The industry's debate over whether permissionless means blameless is only intensifying.
Sources
More on Crypto
- Bitget Hit for $351.6M as Circle and Tether Freeze Loot
- Bitcoin ETFs Flip From $5.8B Outflows to 2026 Net Inflows
- 10-Year Yield Tops 5.2% as Bitcoin Retreats From $87K
- US Sanctions Iranian Crypto Exchange Behind 'Tehran Tollbooth'
- Trump Tells CNN at UN 'You Should Not Be Here' as Ban Fight Heads to Court