Bitget Requests THORChain to Block Hacker but is Rejected

By: nextmoney.jp|09/28/2026 03:00:31

Bitget Requests THORChain to Block Hacker but is Rejected

Following a massive hack at the cryptocurrency exchange Bitget, which resulted in approximately $387.5 million (about 61.1 billion yen) in unauthorized access (exploit), intense debates and criticisms have arisen regarding the core principles of decentralization and censorship resistance in cryptocurrency.

We are devastated to hear about the recent exploit and can imagine how difficult this must be for everyone involved.

THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain.

What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?

@star_okx @GracyBitget

--- THORChain (@THORChain) September 26, 2026

In response to the situation where some of the stolen funds were exchanged for Bitcoin (BTC) via the cross-chain protocol THORChain, Bitget requested the blocking of the attacker's address, but the protocol refused.

Bitget Hack and Money Laundering Using THORChain

On September 24, 2026 (Thursday), Bitget suffered unauthorized access, resulting in the outflow of various assets including AVAX, BNB, ETH, TRX, USDT, USDC, XRP, and ZEC, with the damage amount swelling to approximately $387.5 million from initial estimates.

Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds.

The industry is watching.

--- Gracy Chen @Bitget (@GracyBitget) September 26, 2026

According to tracking by blockchain security firms TRM Labs and SlowMist (MistTrack), the hacker group swapped the stolen Tether (USDT) and USD Coin (USDC) for Ethereum (ETH) and BNB to avoid direct freezing of funds by the issuers. Circle and Tether quickly intervened, successfully freezing approximately $318,000 worth of stablecoins. However, the attackers moved millions of dollars worth of assets through THORChain for the next 13 hours.

Thanks to THORChain's mechanism, which allows direct exchanges between different blockchains without wrapped tokens, the hackers successfully converted the funds into native Bitcoin (BTC). The converted BTC was distributed to thousands of individual wallets, making tracking and recovery even more difficult. It is estimated that approximately $4 million to $4.5 million (about 630 million yen to 700 million yen) of the total outflow has been converted to Bitcoin via the protocol.

Bitget CEO's Request and THORChain's Reason for Rejection

Recognizing the seriousness of the situation, Gracy Chen, CEO of Bitget, publicly requested THORChain to refuse service to addresses related to the attackers through her X account and other channels.

The CEO strongly argued that even with the principle of decentralization, obvious movements of stolen funds should not be ignored, but THORChain immediately rejected this request. The protocol explained that, like Bitcoin and Ethereum, it is a permissionless and decentralized network without a central administrator, and that censoring or blocking specific transactions goes against the fundamental principles of the system. They maintain that individual responses are difficult due to the absence of management keys or multi-signatures, operating purely on code.

Recurring Money Laundering and Criticism from Security Experts

THORChain is facing harsh scrutiny from the security industry regarding its response.

According to reports from TRM Labs and others, the protocol has a history of being favored as a bridge for large-scale money laundering by hacker groups associated with North Korea. Past incidents, such as the hacking of Bybit, which involved approximately $1.5 billion (about 236.6 billion yen), and the KelpDAO leak, have also reported that many stolen funds were moved via THORChain.

Critics point out that there have been instances in past incidents where developers activated emergency stop functions (red buttons), indicating that the protocol has means to prevent fund movements. Furthermore, questions have been raised about the continued collection of fees through the processing of stolen funds.

Bitget's Independent Measures and Future Outlook

Bitget is collaborating with external cybersecurity firms Mandiant and SlowMist to investigate and resolve the situation, asserting that there is no further risk of unauthorized outflow. They have also launched a "Recovery Bounty Program," offering a 5% reward for frozen and recovered funds, calling for voluntary cooperation in recovery efforts.

This incident highlights a deep-rooted challenge for the industry on how to balance the censorship resistance, which is the greatest strength of DeFi (decentralized finance), with victim relief and measures against illicit funds in the event of security incidents.

Bitget Suffers $350 Million Hack, Withdrawals Halted 2026.09.25

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:[email protected]
VIP Program:[email protected]