Live Prices
DeFi

Bitget Urges THORChain to Block $387.5M in Stolen Hack Assets Routed Through Swaps

TheCryptoDesk Editorial · 3m read
Bitget Urges THORChain to Block $387.5M in Stolen Hack Assets Routed Through Swaps

Bitget CEO Gracy Chen has formally requested that cross-chain liquidity protocol THORChain block 2,377 wallet addresses associated with the $387.5 million exchange exploit after attackers began moving stolen funds through the decentralised network. The request follows disclosures that 1,497 of those tagged addresses have already processed transactions through THORChain swaps following the September 24 breach.

Bitget Demands Intervention as Attacker Funds Flow Through Swaps

The total losses from the exploit were updated from an initial $351.6 million to $387.5 million after stolen Zcash and Tron assets were identified. Bitget clarified that the incident stemmed from a backend system vulnerability in its wallet setup rather than compromised private keys. On September 26, Gracy Chen directly appealed to THORChain to deny service to the attacker addresses, writing: "Decentralization is a design principle, not a shield for facilitating known stolen funds," and adding that "the industry is watching."

THORChain responded by reiterating its status as a permissionless network comparable to Bitcoin, Ethereum, and BNB Chain, questioning what liability those layer-1 blockchains would bear in identical circumstances. However, blockchain monitoring firm MistTrack pointed out that nearly $1.2 billion linked to the 2025 Bybit hack was previously laundered through THORChain, fueling debate over protocol accountability. In contrast, centralized stablecoin issuers Circle and Tether acted quickly to freeze approximately $318,000 connected to the theft. Bitget has offered a 5% bounty on frozen or recovered funds while preparing a phased withdrawal rollout, beginning with Bitcoin on September 28 at 08:00 UTC.

Network's Historical May Halt Fuel Censorship Arguments

Industry observers and security analysts pointed to historical precedents to challenge THORChain's stance on neutrality. In May, THORChain validators halted the entire network within hours of a $10.7 million exploit, keeping trading and withdrawals suspended for roughly five weeks until June 22. Commentators from Satoshi Club questioned why the protocol could pause operations to protect its own liquidity, yet claims inability to restrict transactions involving third-party thefts.

Security researcher Taylor Monahan criticized THORChain's governance record during a debate with crypto advocate Joel Valenzuela. Valenzuela argued that transaction screening constitutes outright censorship, whereas Monahan pointed to prior emergency asset reallocations by the core team. When asked to evaluate the dispute, the Grok AI tool noted that THORChain had suffered at least three exploits in 2021 totaling roughly $16 million and paused a lending product with $200 million in liabilities, though it found no evidence supporting claims of North Korean involvement or operator rug pulls.

  • Bitget identified 2,377 attacker addresses holding $378 million, with 1,497 moving funds via THORChain.
  • Circle and Tether froze $318,000 in stolen assets, while Bitget offered a 5% bounty for asset recovery.
  • THORChain previously executed a five-week network halt following a $10.7 million exploit in May.

Why It Matters

This dispute underscores the growing friction between permissionless protocol architecture and accountability standards in decentralized finance. As multi-million-dollar exploits continue to target centralized platforms, attackers increasingly rely on cross-chain bridges to obfuscate stolen assets, as seen in how hackers laundered stolen assets via THORChain. Pressure from affected exchanges and stablecoin issuers may force decentralized protocols to confront governance dilemmas as exchanges resume withdrawals under intense scrutiny.

Read next