Home THORChain Rejects Bitget CEO’s Call To Block $387.5M Hacker Wallets

THORChain Rejects Bitget CEO’s Call To Block $387.5M Hacker Wallets

Share
THORChain Rejects Bitget Plea, Defends Permissionless Design
News
Share

THORChain has rejected a request from Bitget to block wallet addresses linked to the exchange’s $387.5 million security breach, defending its permissionless design. Bitget CEO Gracy Chen had asked the cross-chain protocol to refuse service to the identified hacker wallets as stolen funds continued to move.

THORChain responded that it is a decentralised and permissionless network, similar in this respect to Bitcoin, Ethereum and BNB Chain. The disagreement has opened a wider debate over whether a crypto network should intervene when known stolen funds pass through its infrastructure.

The dispute began after Bitget publicly identified addresses linked to the attacker and asked THORChain to stop processing transactions involving them. Chen said decentralisation should not become a reason to facilitate the movement of known stolen assets.

THORChain took a different position. The protocol argued that its emergency halt mechanisms should not be confused with a system for selectively freezing individual addresses. According to THORChain, these mechanisms are designed to protect the network itself during a security emergency rather than create a blacklist for particular users or wallets.

The issue is complicated by the way THORChain works. The cross-chain protocol allows users to swap native assets between different blockchains. Its vaults are controlled jointly by a rotating group of node operators, with outbound transactions authorised through a threshold-signature system. This means THORChain has mechanisms that can stop network activity, but the protocol says that does not mean it should selectively block individual transactions.

The distinction has drawn criticism from security researchers. GoPlus Security argued that THORChain’s structure is different from Bitcoin and Ethereum because its validator set collectively controls assets held in protocol vaults. The firm pointed to THORChain’s ability to pause activity, coordinate among node operators and stop transactions through established mechanisms.

The debate became sharper because THORChain itself halted parts of its network after a security incident earlier this year. In May, an exploit involving its GG20 threshold-signature system drained about $10.7 million from one of its vaults. Automatic checks detected an imbalance, after which node operators coordinated measures to halt activity. The network later followed an upgrade and restart process before trading and other functions were restored.

THORChain supporters, however, argue that this does not mean individual transactions can simply be approved or rejected at the discretion of node operators. Michael Perklin, a THORChain supporter, said node operators do not actively choose whether to sign each transaction. Instead, they participate in an automated process and can choose to take their nodes offline.

The Bitget case also brings to mind the controversies surrounding Bybit hack in 2025. Large volumes of pilfered Ether were transferred via THORChain by the attackers, who also converted the funds into Bitcoin. Node operators did not sufficiently support a request to prohibit transactions associated with the attacker.

The most recent disagreement coincides with Bitget’s ongoing efforts to recover. After discovering more Zcash and TRON transactions, the exchange updated its estimate of the September 24 hack from $351.6 million to around $387.5 million. According to Bitget, the larger number does not indicate a fresh theft but rather a more thorough accounting of the initial incident.

Some of the stolen assets have already moved through THORChain. Blockchain tracking firms have traced funds from Ethereum, BNB Chain and TRON through the protocol and eventually into Bitcoin. Other routes, including Uniswap, 1inch, Stargate, Across, Relay and Chainflip, have also been used to move funds.

Bitget has offered a recovery bounty of 5% for affected funds that are successfully frozen through voluntary efforts, with another 5% available for funds that are recovered. The exchange is working with cybersecurity firms Mandiant and SlowMist as it tracks the stolen assets.

For now, THORChain has not agreed to block the Bitget-linked addresses. The episode leaves an important question for the crypto industry: when a permissionless network becomes a route for stolen assets, where should the line be drawn between maintaining neutral infrastructure and taking action against clearly identified funds?

Stay informed with the latest trends in Web3, blockchain innovation, and cybersecurity updates at 3verseTV

Share
Written by
Kapil Rajyaguru -

Kapil Rajyaguru is a news editor at 3.0 TV with over 15 years of professional writing experience and more than four years dedicated to the cryptoverse.

An engineer by education and a writer by passion, Kapil brings a rare mix of technical insight and storytelling finesse. A firm believer that cryptocurrencies, blockchain and AI are the building blocks of the future, he crafts in-depth news and analysis to educate, empower and prepare the masses for the next frontier of Web3.

Leave a comment

Leave a Reply

Latest News

Vitalik Buterin Maps Ethereum’s Shift Beyond A Blockchain In 2030 Vision
News

Vitalik Buterin Maps Ethereum’s Shift Beyond A Blockchain In 2030 Vision

Ethereum co-founder Vitalik Buterin has outlined a vision for how the network could change by 2030, saying it may still be called...

California Bans Official Memecoins, Takes Aim At Trump’s Crypto Venture
News

California Bans Official Memecoins, Takes Aim At Trump’s Crypto Venture

California Governor Gavin Newsom has signed a new law banning covered public officials from issuing memecoins, while directly linking the move to...

THORChain Rejects Bitget Plea, Defends Permissionless Design
News

THORChain Rejects Bitget CEO’s Call To Block $387.5M Hacker Wallets

THORChain has rejected a request from Bitget to block wallet addresses linked to the exchange’s $387.5 million security breach, defending its permissionless...

Bitget Hacker Moves $83M In XRP As Exchange Offers 5% Recovery Bounty
News

Bitget Hacker Moves $83M In XRP As Exchange Offers 5% Recovery Bounty

The hacker behind Bitget’s September 24 security breach has moved about $83 million worth of stolen XRP, while the exchange has raised...

Related Articles

Token Unlocks To Watch Till 2026-end

Imagine you are holding a token of a crypto project that is...

5 Trending Tokens On Robinhood Chain In 2026

A few months ago, Robinhood Chain did not exist. Today, it has...

Memecoin Supercycle: How DOGE, SHIB, WIF Mint Millions

Did you ever notice how sometimes the crypto market gets absolutely taken...

5 Best Crypto Mining Apps In 2026: What They Actually Do

Introduction The phrase ‘crypto mining app’ sounds like you can download an...