Bitget Urges THORChain to Block Hackers Behind Exchange Breach

Bitget hack illustration showing a cyber attacker, cryptocurrency coins, a damaged exchange server, and a glowing THORChain security shield in blue and black tones.

Key Insights:

  • THORChain declined Bitget CEO Gracy Chen’s appeal to stop addresses tied to the $387.5 million hack saying THORChain operates without permission.
  • Attackers moved $4 million to $4.5 million via THORChain into Bitcoin making it hard to recover the funds.
  • THORChain’s previous emergency shutdowns have intensified debate over validator control, transaction censorship, and accountability for stolen funds.

THORChain has rejected Bitget CEO Gracy Chen’s request to block addresses linked to the exchange’s $387.5 million security breach on September 24. The dispute has intensified questions about decentralized finance security, validator control, and the responsibility of cross-chain protocols handling stolen cryptocurrency.

Bitget’s attackers used THORChain to convert portions of the stolen assets into Bitcoin after moving funds across several blockchain networks.The protocol, however, maintained its permissionless paradigm with the point that if it was not permissionless, it would not align with its operation.

As stolen funds cross chains, Bitget presses THORChain.

On September 24, Bitget noticed transfers from its hot and warm wallets that were unauthorized. The exchange initially estimated losses at $351.6 million before revising the figure to approximately $387.5 million.

According to Bitget, attackers compromised a critical backend system within its wallet infrastructure. They manipulated transaction data and exploited the exchange’s approval process to authorize unauthorized transfers.

The exchange said private keys remained secure, while cold wallets and its separate Bitget Wallet product escaped the incident.

Consequently, investigators began tracking the stolen assets across multiple blockchain networks. The affected assets included XRP, ETH, USDT, ZEC, USDC, BNB, AVAX, and TRX.

Blockchain tracking companies found the movements in the Ethereum, TRON, and other networks. Eventually some funds did go through THORChain where you can swap between chains without using wrapped tokens.

A part of the stolen ETH and BNB was converted to native Bitcoin within the protocol. Some of the funds of ETH and BNB were traded to native Bitcoin. Attackers subsequently distributed the converted BTC across numerous wallets, complicating recovery efforts.

Incident details                                         Reported figures

Initial reported loss                                    $351.6 million

Revised estimated loss                               $387.5 million

Funds frozen by Circle and Tether           Approximately $318,000

Bitcoin traced through THORChain          Roughly $4 million to $4.5 million

On September 26, Chen publicly requested that validators refuse service to identified attacker addresses. She argued that decentralization should not shield platforms processing transactions involving stolen assets.

THORChain Defends Permissionless Transactions

Chen maintained that the exchange had identified and tracked the attacker addresses. She urged the protocol to prevent further transfers while investigators pursued recovery efforts.

“Decentralization is a design principle, not a shield for facilitating known stolen funds,” Chen said. She added that the industry was watching the protocol’s response. However, THORChain rejected the request and defended its permissionless architecture. The protocol compared its transaction processing with Bitcoin, Ethereum, and BNB Chain.

Its response questioned what responsibility those networks should bear when processing transactions involving known stolen funds.

The protocol also distinguished emergency shutdown mechanisms from selective address restrictions. Its position holds that stopping network functions during security incidents does not establish an individual transaction blacklist.

Meanwhile, Bitget continued coordinating with security firms and other cryptocurrency companies. Chen also launched a recovery bounty offering rewards for successfully frozen and recovered assets.

Circle and Tether had frozen approximately $318,000 in USDC and USDT linked to the incident by September 26.

Previous Exploits Intensify Decentralization Debate

The disagreement has revived scrutiny of THORChain’s response to earlier security incidents involving stolen cryptocurrency.

Following the February 2025 Bybit hack, attackers moved approximately $1.2 billion through the protocol, according to reports. The stolen funds originated from an attack that Bybit valued at approximately $1.46 billion.

There was a significant amount of swaps processed by THORChain as attackers swapped stolen Ether for Bitcoin. According to the activity, the trading volume was $2.91 billion and the income for fees was reported to be about $3 million.

The protocol was also subject to more criticism when its own vault was compromised in May 2026. The attack was carried out by a malicious node operator exploiting a flaw in the GG20 threshold signature scheme to siphon off some $10.7 million.

The automatic solvency check identified the imbalance, and places a halt on signing and trading across multiple chains. The node operators then coordinated additional shutdown measures.

The incident showed the ability of the protocol to stop network functions in certain situations. Trading eventually resumed on June 23 after security checks and recovery measures.

GoPlus Security later challenged comparisons between THORChain and Bitcoin or Ethereum. The firm highlighted how THORChain validators collectively control assets held within threshold signature vaults.

According to GoPlus, validators can coordinate pauses and restrict network activity through documented mechanisms. Bitcoin and Ethereum users, by contrast, generally control their own private keys.

Industry Faces Difficult Questions Over Crypto Recovery

THORChain’s supporters dispute the argument that validator-controlled vaults automatically establish centralized transaction approval.

Michael Perklin, a crypto security executive, argued that node operators do not individually approve every swap. Instead, they participate in an automated process that continues while network infrastructure remains operational.

He equated this setup to miners and validators of Bitcoin and Ethereum deciding whether or not to turn their machines on. But Perklin also said that ending infrastructure would be disrupting legitimate transactions as well as fraudulent transactions.

However, the clash reveals differences between the centralized exchanges and the decentralized protocols. Centralized platforms can block withdrawals, utilize reserves, and place calls for the stop of assets from the token issuers.

Permissionless protocols generally lack comparable recovery mechanisms after transactions receive authorization. Yet emergency controls and coordinated validator decisions raise questions about how much practical control decentralized systems retain.

Bitget’s breach has therefore exposed competing expectations surrounding security and censorship resistance. Exchanges want faster intervention against identified attackers, while decentralized networks seek to preserve predictable transaction processing.

The issue thus boils down to two priorities for the industry: victim protection for large-scale cryptocurrency thefts, and permissionless infrastructure with selective transaction banning.

Brenda Mary

Brenda Mary is a cryptocurrency journalist, SEO analyst, and editor with over 3 years of experience in blockchain, digital assets, and crypto market analysis. She has contributed to leading platforms including Crypto.news, Cryptopolitan, The Coin Republic, and Analytics Insight.
At CoinRaftar, she covers crypto news, market trends, and Web3 developments, simplifying complex topics into clear, reader-friendly insights.
Bachelor’s in International Business Management, University of Nairobi.
https://www.linkedin.com/in/brenda-mary-248b2422b/

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top