THORChain has rejected a request from Bitget to block wallet addresses linked to the exchange’s $387.5 million security breach, defending its permissionless design. Bitget CEO Gracy Chen had asked the cross-chain protocol to refuse service to the identified hacker wallets as stolen funds continued to move.
Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds.
The industry is watching. https://t.co/rOzV9kpu0F— Gracy Chen @Bitget (@GracyBitget) September 26, 2026
THORChain responded that it is a decentralised and permissionless network, similar in this respect to Bitcoin, Ethereum and BNB Chain. The disagreement has opened a wider debate over whether a crypto network should intervene when known stolen funds pass through its infrastructure.
The dispute began after Bitget publicly identified addresses linked to the attacker and asked THORChain to stop processing transactions involving them. Chen said decentralisation should not become a reason to facilitate the movement of known stolen assets.
A THORChain network halt is an emergency security mechanism designed to protect the protocol.
A halt is not a selective freeze of specific funds or an individual swap.
During the May 2026 exploit that resulted in $10.7M stolen from the liquidity pools, the attackers addresses… https://t.co/HrigTUbA4Q
— THORChain (@THORChain) September 28, 2026
THORChain took a different position. The protocol argued that its emergency halt mechanisms should not be confused with a system for selectively freezing individual addresses. According to THORChain, these mechanisms are designed to protect the network itself during a security emergency rather than create a blacklist for particular users or wallets.
The issue is complicated by the way THORChain works. The cross-chain protocol allows users to swap native assets between different blockchains. Its vaults are controlled jointly by a rotating group of node operators, with outbound transactions authorised through a threshold-signature system. This means THORChain has mechanisms that can stop network activity, but the protocol says that does not mean it should selectively block individual transactions.
The distinction has drawn criticism from security researchers. GoPlus Security argued that THORChain’s structure is different from Bitcoin and Ethereum because its validator set collectively controls assets held in protocol vaults. The firm pointed to THORChain’s ability to pause activity, coordinate among node operators and stop transactions through established mechanisms.
❗️ #THORChain has never been strictly decentralized@THORChain comparing itself to decentralized L1s like BTC and ETH does not hold. Do not enable criminals — or put the industry at risk — just to take swap fees on stolen funds.
1️⃣ Custody: TSS vaults ≠ base-layer consensus… https://t.co/x23ZWABnNb pic.twitter.com/D3wD9qG3hX
— GoPlus Security 🚦 (@GoPlusSecurity) September 27, 2026
The debate became sharper because THORChain itself halted parts of its network after a security incident earlier this year. In May, an exploit involving its GG20 threshold-signature system drained about $10.7 million from one of its vaults. Automatic checks detected an imbalance, after which node operators coordinated measures to halt activity. The network later followed an upgrade and restart process before trading and other functions were restored.
THORChain supporters, however, argue that this does not mean individual transactions can simply be approved or rejected at the discretion of node operators. Michael Perklin, a THORChain supporter, said node operators do not actively choose whether to sign each transaction. Instead, they participate in an automated process and can choose to take their nodes offline.
The Bitget case also brings to mind the controversies surrounding Bybit hack in 2025. Large volumes of pilfered Ether were transferred via THORChain by the attackers, who also converted the funds into Bitcoin. Node operators did not sufficiently support a request to prohibit transactions associated with the attacker.
The most recent disagreement coincides with Bitget’s ongoing efforts to recover. After discovering more Zcash and TRON transactions, the exchange updated its estimate of the September 24 hack from $351.6 million to around $387.5 million. According to Bitget, the larger number does not indicate a fresh theft but rather a more thorough accounting of the initial incident.
Some of the stolen assets have already moved through THORChain. Blockchain tracking firms have traced funds from Ethereum, BNB Chain and TRON through the protocol and eventually into Bitcoin. Other routes, including Uniswap, 1inch, Stargate, Across, Relay and Chainflip, have also been used to move funds.
Bitget has offered a recovery bounty of 5% for affected funds that are successfully frozen through voluntary efforts, with another 5% available for funds that are recovered. The exchange is working with cybersecurity firms Mandiant and SlowMist as it tracks the stolen assets.
For now, THORChain has not agreed to block the Bitget-linked addresses. The episode leaves an important question for the crypto industry: when a permissionless network becomes a route for stolen assets, where should the line be drawn between maintaining neutral infrastructure and taking action against clearly identified funds?
Stay informed with the latest trends in Web3, blockchain innovation, and cybersecurity updates at 3verseTV
You need to login in order to Like










Leave a comment