Choose Rich Live
Crypto News

THORChain refuses Bitget request to freeze wallets as hacker swaps stolen crypto

THORChain has rejected appeals from Bitget to block wallets linked to a $387.5 million exploit, stating it does not censor transactions as the attacker actively converts stolen assets into bitcoin.

Logos of crypto exchange Bitget and decentralized protocol THORChain side by side on a split background.
Image: @BSCNews

THORChain has declined a formal request from crypto exchange Bitget to block wallet addresses tied to a $387.5 million security breach, maintaining that the decentralized protocol does not selectively freeze funds. Bitget CEO Gracy Chen publicly called on THORChain to refuse service to the tracked attacker wallets after intruders breached Bitget's backend wallet system on Sept. 24. Supported by blockchain security firm SlowMist, Chen argued that decentralization should not serve as an excuse to facilitate stolen funds.[1][3][4]

In response, THORChain stated on X that its network emergency halts protect the overall protocol rather than targeting individual users or swaps, comparing itself to permissionless networks like Bitcoin and Ethereum. The protocol noted it also avoided blacklisting attacker addresses when its own liquidity pools were drained for $10.7 million in May. However, critics like OKX founder Star Xu challenged the defense, pointing out that validator nodes jointly control vault assets and previously demonstrated the power to pause the network.[1][3][4]

The refusal comes as the exploiter actively launders the proceeds across chains. CoinMarketCap reported that the attacker converted 2,390 stolen ether into 75 bitcoin across 27 swaps on Sept. 28, while GoPlus Security estimated that around 101.5 BTC had already left through THORChain alongside tens of millions in XRP being swapped. Bitget, which noted the hack reflects tactics linked to North Korean cyber groups, confirmed its User Protection Fund fully covers user losses. Amid surging protocol volumes, THORChain's RUNE token gained 25% over the week.[1][2][3]

Key facts

  • Bitget formally requested that THORChain refuse service to wallet addresses tied to its $387.5 million hack from Sept. 24.
  • THORChain rejected the request, asserting that its halt mechanism protects the protocol as a whole rather than executing selective freezes, and said it does not censor by design.
  • The Bitget attacker swapped 2,390 stolen ETH into 75 BTC across 27 transactions on Sept. 28, according to CoinMarketCap.
  • GoPlus Security estimated that 101.5 BTC had already left through THORChain, with another 27.63 million XRP being swapped into bitcoin.
  • THORChain noted that it did not blacklist attacker addresses during its own $10.7 million hack in May.
  • Bitget stated that its User Protection Fund covers the entire loss and noted the exploit patterns resemble North Korean hacker organizations.
  • THORChain's native RUNE token rose 25% over the week, per CoinMarketCap.

Sources · 4 sources

  1. PR

    ProtosArticle ·

    THORChain refuses to block Bitget funds, despite pausing after own hack DeFi project THORChain has turned down a formal plea to “refuse service” to addresses associated with the recent hack of Bitget, a centralized crypto exchange which lost over $380 million on Thursday night. The decision comes four months after THORChain halted trading after it was hacked for $10 million. In the aftermath of Thursday’s hack, Bitget CEO Gracy Chen called it “highly consistent with known patterns of North Korean hacker organizations,” after on-chain analysts spotted connections to wallets used following previously attributed hacks. Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds. The industry is watching. https://t.co/rOzV9kpu0F — Gracy Chen @Bitget (@GracyBitget) September 26, 2026 Read more: Bitget’s eighth birthday ends with a $352M hack Both Chen and blockchain security firm SlowMist , which is supporting Bitget with tracing the stolen funds, appealed to THORChain, with the latter urging that “decentralization should not become a blanket excuse when dealing with known stolen funds.” Addressing the calls to take action, THORChain said it was “devastated to hear” of Bitget’s hack, but that it is “decentralized and permissionless.” It compared itself to “Bitcoin, Ethereum, and BNB Chain,” asking if those networks would be expected to halt when stolen funds passed through them. Notably, following a $600 million hack in 2022, BNB Chain validators did indeed halt the chain, preventing the attacker from extracting the majority of the loot. We are devasted to hear about the recent exploit and can imagine how difficult this must be for everyone involved. THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain. What responsibility should Bitcoin, Ethereum, and BNB Chain bear when… https://t.co/ArvP6N1w3F — THORChain (@THORChain) September 26, 2026 Read more: Explained: How $600M was stolen from Binance’s BNB chain THORChain’s refusal is widely seen as hypocritical considering its validators previously took swift action to halt trading in response to being hacked itself for approximately $10 million back in May. Revisiting the episode, THORChain has stressed the halt was to protect the protocol, it never selectively blacklisted the hacker, and that it “doesn’t censor by design.” According to THORChain’s own analytics page, the protocol processed a total of $678 million in the two days following the Bitget hack, compared to $20 million to $60 million daily volume in the week preceding it. Consequently, it generated a total of almost $1.2 million in “gross system income” over those same two days. THORChain’s track record THORChain swaps have been a hacker favorite for some time, and were most notably used to move the majority of the $1.5 billion hacked from ByBit in February last year. That incident was also linked to North Korean hackers from the so-called “TraderTraitor” operation. Following the theft, a similar discussion opened up, and a former THORChain developer known as “Pluto” left the project in response. Similarly, volume spiked immediately following April’s $280 million Kelp DAO hack, as Specter, the investigator who made the North Korean connection in the Bitget case, pointed out in their Telegram group. Got a tip? Send us an email securely via Protos Leaks . For more informed news and investigations, follow us on X , Bluesky , and Google News , or subscribe to our YouTube channel. The post THORChain refuses to block Bitget funds, despite pausing after own hack appeared first on Protos .

    Open source
  2. CO

    CoinMarketCap@CoinMarketCapPost on X ·

    HOT TOPIC: Bitget's $388M hacker, no freeze in sight 🥷 Bitget asked THORChain to block the attacker's wallets. THORChain's answer: a halt is not a freeze, and it doesn't censor by design. Meanwhile, 2,390 stolen $ETH became 75 $BTC in 27 swaps this morning, and $RUNE is up 25% on the week 👇 https://t.co/gLDQFSkrjl

    Open source
  3. UN

    UnchainedArticle ·

    THORChain Rejects Bitget’s Request to Block Hacker Wallets, Says It ‘Doesn’t Censor by Design’ THORChain pushed back again Monday on Bitget ‘s request to block wallets connected to its $387.5 million hack, saying its emergency halts exist to protect the protocol and are not a way to freeze particular funds. “A halt is not a selective freeze of specific funds or an individual swap,” THORChain wrote on X. “THORChain is permissionless and doesn’t censor by design.” Bitget CEO Gracy Chen made the request on Saturday, saying the attacker’s addresses are public and being tracked. “We are formally asking @THORChain to refuse service to these addresses,” she posted , adding that decentralization “is a design principle, not a shield for facilitating known stolen funds.” Bitget has said attackers broke into a backend wallet system on Sept. 24 and got its own approval process to sign the transfers , using techniques consistent with North Korea-linked hackers. Get Unchained’s crypto news in your inbox with the free Unchained Daily newsletter . The Bitcoin Comparison THORChain’s first reply said the protocol is “decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain.” Critics rejected the comparison. OKX founder and CEO Star Xu argued that THORChain’s validators jointly control the assets in its vaults. “TSS distributes control among multiple parties, but distributing an intermediary does not eliminate the intermediary,” he wrote. In a later post , Xu noted that node operators paused the network in May, when THORChain’s own vaults were drained. GoPlus Security said on Sunday that node votes can pause signing on a single chain, and estimated that about 101.5 BTC , worth roughly $8.5 million , had already left through THORChain, with another 27.63 million XRP , about $43 million , being swapped into bitcoin. “Do not put the industry at risk for the fee line,” the security firm wrote. THORChain’s Defense In Monday’s post, THORChain said that during its May exploit, in which $10.7 million was taken from its liquidity pools, the attackers’ addresses “were never blacklisted and therefore never prevented from swapping on THORChain.” It also pointed to a post by Michael Perklin , who called GoPlus’s argument “cherry picking at best, a false equivalency at worst” and wrote that “All tools in existence are inherently neutral by nature.” The protocol has faced these questions before. Attackers behind April’s $292 million Kelp DAO exploit routed stolen funds through THORChain, as did North Korea’s Lazarus Group with most of the ether it converted to bitcoin after the 2025 Bybit hack. Bitget has said its User Protection Fund covers the full loss. Related Listen: The Chopping Block: ColdCard’s $100M RNG Hack, AI-Powered Security & Ethereum’s Staking Yield Taper The post THORChain Rejects Bitget’s Request to Block Hacker Wallets, Says It ‘Doesn’t Censor by Design’ appeared first on Unchained .

    Open source
  4. WB

    Wu Blockchain@WuBlockchainPost on X ·

    THORChain Rejects Bitget’s Call to Block Attacker Funds After $387.5M Hack THORChain responded to Bitget after CEO Gracy Chen called on the protocol to refuse service to addresses linked to attackers from Bitget’s September 24 security breach, which involved about $387.5 million in stolen assets. THORChain said its network halt mechanism is designed to protect the protocol as a whole, not to selectively freeze specific addresses or individual swaps. It added that even during its own $10.7 million exploit in May, attacker addresses were not blacklisted, and reiterated that the protocol is permissionless by design.

    Open source