Join Our Telegram channel to stay up to date on breaking news coverage
THORChain has rejected Bitget’s formal request to block the wallets behind the roughly $387.5 million hack of the exchange, saying the protocol is decentralized and permissionless.
The September 25 breach first looked like a loss of about $352 million; that estimate has since risen to roughly $387.5 million. Bitget CEO Gracy Chen said in an incident update that stolen assets included ETH, XRP, BNB, AVAX and stablecoins across Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base, with XRP the biggest single-chain loss and all cold wallets confirmed safe.
Bitget says the attack method is highly consistent with known patterns of North Korean hacker organizations. Security firms rate that attribution as highly likely, and it remains officially unconfirmed.
GoPlus Security, a blockchain security firm tracing the funds, said about 101.5 BTC, worth roughly $8.5 million, and about 27.63 million XRP, worth roughly $43 million, moved through THORChain during the incident.
The request and the refusal
On September 26, Chen formally asked the protocol in a post on X to refuse service to the attacker addresses, which she said are publicly listed and actively tracked. “Decentralization is a design principle, not a shield for facilitating known stolen funds,” she wrote.
THORChain answered in a post on X the same day, saying it was devastated to hear about the exploit but would not block the funds. “THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain. What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?” the post said.
A halt is not a freeze
The refusal drew immediate pushback from the firms tracing the money. MistTrack, the fund-tracing arm of security company SlowMist, said decentralization must not serve as a blanket excuse when known stolen funds are involved. ByBit CEO Ben Zhou reported in March 2025 that about $0.9 billion of the ether stolen in the exchange’s $1.4 billion hack that February, 72 percent of the total, had moved through THORChain.
Supporters of the protocol counter that blocking specific transactions would compromise its neutrality and turn validators into compliance officers.
In a follow-up post on September 28, THORChain said a network halt is an emergency security mechanism built to protect the protocol, not a selective freeze of specific funds or individual swaps. It noted that when the protocol lost $10.7 million to an exploit in May 2026, the attacker addresses were never blacklisted and were never prevented from swapping.
Join Our Telegram channel to stay up to date on breaking news coverage
Credit: Source link
