THORChain, a cross-chain swap protocol, has declined a formal request from Bitget Chief Executive Officer (CEO) Gracy Chen to refuse service to wallet addresses tied to the exchange’s September 24 hack. Funds from those addresses continued to move into Bitcoin (BTC) through the protocol after it declined.
THORChain said it is decentralized and permissionless in the same way as Bitcoin, Ethereum, and BNB Chain, and asked what responsibility those networks carry when known stolen funds pass through them.
Bitget says assets worth approximately $387.5 million were transferred to attacker-controlled addresses, up from an initial estimate of $351.6 million. The exchange said the revision added Zcash (ZEC) and TRON (TRX) transfers from the original attack window and does not reflect any new theft.
How the Bitget Breach Unfolded
Bitget’s security systems detected unauthorized transfers at 18:31 Coordinated Universal Time (UTC) on September 24, 2026. The transfers came from part of the exchange’s hot and warm wallet infrastructure. Hot wallets stay connected to the internet to process routine withdrawals, and warm wallets sit between hot and offline storage. Chen posted a security notice on X at 21:30 UTC the same day, and withdrawals were paused.
In a technical update on September 25, Chen said the attacker compromised a backend system in Bitget’s wallet infrastructure and used it to spoof transaction data. The spoofed data then triggered the exchange’s own authorization process. She said a private key compromise had been ruled out. Chen also said investigators found patterns consistent with earlier operations by North Korean hacking groups. Bitget has not published a final attribution.
Blockchain analytics firm TRM Labs said cold wallets were unaffected and that Bitget says its User Protection Fund of about $464 million covers the loss.
Chen’s Request and THORChain’s Reply
The dispute began on September 25, when MistTrack, the on-chain tracking unit of blockchain security firm SlowMist, posted at 08:36 UTC that Bitget-linked funds were again entering THORChain for swaps and cross-chain transfers.
MistTrack noted that nearly $1.2 billion from the $1.46 billion Bybit hack in 2025 was reported to have moved through the protocol. It asked what responsibility a protocol carries once the source of funds is known. SlowMist is also one of the two firms assisting Bitget’s investigation, alongside Mandiant.
At 11:44 UTC on Saturday, September 26, Chen quoted that post and wrote on X: “Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds. The industry is watching.”
At 18:17 UTC the same day, the official THORChain account replied, tagging Chen and OKX Founder Star Xu: “We are devastated to hear about the recent exploit and can imagine how difficult this must be for everyone involved. THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain. What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?”
The reply did not mention a blacklist, a halt vote or any change to inbound routing. As of September 28, no public node vote to pause Bitget-linked flows had been recorded.
What On-Chain Data Shows
Public traces differ on how much has cleared through THORChain, but they agree on the route. TRM Labs reported that funds on BNB Chain and Ethereum were swapped through THORChain and split across Bitcoin addresses in peel chains. Stolen TRX was swapped for Tether (USDT) on SunSwap, bridged to Ethereum through USDT0, and sent along the same THORChain route.
Blockchain data provider Bitquery counted 126.71 BTC paid out across 66 THORChain swaps tied to stolen BNB and TRX by 14:38 UTC on September 25.
XRP, the native token of the XRP Ledger, was the largest single asset taken in the breach. Bitquery traced about 102.98 million XRP. By 02:54 UTC on September 26, it said 27.63 million XRP had left two tracked attacker accounts, while about 75.35 million XRP remained across six accounts.
The movement continued after THORChain’s reply. At 03:14 Eastern Time (07:14 UTC) on September 27, 9,999 XRP left an address on Bitget’s published attacker list. Midgard, THORChain’s public data indexer, marked the XRP-to-Bitcoin swap as successful.
GoPlus Security, a blockchain security firm, later estimated that about 101.5 BTC, worth roughly $8.5 million, had already left through THORChain. It said about 27.63 million XRP, worth roughly $43 million, was mid-swap into Bitcoin. Those are GoPlus’s own figures, not Bitget’s.
THORChain is not the only route in use. Traces also show the attacker using Uniswap, 1inch, Stargate, Across, Relay, Chainflip, and Circle’s Cross-Chain Transfer Protocol (CCTP).
Read: Bitget Withdrawals Resume September 28: Full Schedule After $387.5M Hack
Why THORChain Sits at the Center
THORChain is a Layer 1 blockchain built with the Cosmos software development kit. It swaps native assets across chains through liquidity pools paired with its token, RUNE, so users do not receive wrapped tokens. The coins sit in Asgard vaults held jointly by a rotating set of node operators.
Outbound transfers are signed by the active validator set under GG20, a Threshold Signature Scheme (TSS) based on a 2020 paper by cryptographers Rosario Gennaro and Steven Goldfeder. No single node holds the full private key. This design lets stolen ETH, BNB, TRX, and XRP leave as native Bitcoin. Once funds become Bitcoin, no token issuer can freeze them the way Tether or Circle can freeze stablecoins.
The Decentralization Dispute
Star Xu rejected THORChain’s comparison with Bitcoin on September 26. He argued that a model combining TSS with a validator set is not true decentralization, because the active validators jointly control vault assets and can move them once the signing threshold is met.
Xu also pointed to May 2026, when THORChain halted after an exploit and, he said, stayed down for 39 days. In his view, a network that can stop when its own funds are at risk, but not when someone else’s funds are at risk, is not “like Bitcoin.”
GoPlus made a similar custody argument. On Bitcoin and Ethereum, miners and validators order transactions but do not hold user keys. On THORChain, every outbound transfer requires an active threshold signature over pooled native assets. GoPlus also cited the network’s small, bonded validator set, a churn cycle of roughly three days and real-time coordination among operators on Discord.
THORChain’s position rests on its structure. The protocol retired its admin key in February 2025, and no listed operator has a switch to blacklist a single address. Blocking specific flows would require node operators to refuse to observe or sign particular vault transactions. That is possible in principle, and node operators have coordinated halts before. They have not done so for the Bitget addresses.
Supporters of THORChain’s stance also point to consistency. Ethereum, BNB Chain, the XRP Ledger and TRON continue to process the same flagged transactions. Asking only THORChain to intervene, they argue, would make it the first entry on a censorship list rather than a neutral protocol rule.
A Pattern Seen Before
The dispute closely follows the Bybit case. On February 21, 2025, Bybit lost about $1.5 billion in ETH in an attack the Federal Bureau of Investigation (FBI) attributed to North Korea. The attacker laundered the stolen ETH mainly through THORChain within about 10 days. At the time, a validator vote to block the flows was overturned, and core contributor Pluto, who had backed the intervention, left the project.
In April 2026, the attacker behind the KelpDAO exploit routed stolen ETH to Bitcoin through THORChain, pushing the protocol’s volume sharply higher.
A month later, THORChain became the target itself. On May 15, 2026, a newly joined node exploited a weakness in the GG20 signing system and drained about $10.7 million from one of six Asgard vaults. Node operators responded with emergency governance votes to halt the network. Trading on BNB Chain, Base, and Solana was only set to resume with the v3.20 upgrade on August 25. That episode is the centerpiece of Xu’s argument that the network has the capacity to stop.
Where Bitget Stands
Bitget scheduled a phased restart of withdrawals beginning with Bitcoin at 08:00 UTC on September 28, followed by ETH, USDT, and remaining assets through October 2. The exchange has also launched a recovery bounty program that pays 5% of affected funds frozen or recovered through voluntary efforts. It says some assets have already been frozen through coordination with exchanges, blockchain projects, and security firms, though frozen amounts reported so far are a small share of the total.
What Remains Unresolved
Several facts are settled. Bitget lost about $387.5 million on September 24; Chen asked THORChain to refuse the published attacker addresses at 11:44 UTC on September 26; THORChain declined at 18:17 UTC the same day; and XRP kept swapping into Bitcoin on September 27.
Other questions remain open. It is unclear how much of the $387.5 million will ultimately pass through THORChain and whether node operators will later vote for a narrow halt. The larger question is whether “permissionless” in THORChain’s case means it lacks the technical capacity to intervene or lacks the will to do so. The May halt showed the capacity exists. So far, no such decision has been made for the Bitget funds.
Also Read: Analyst Exposes $18.43M Robinhood Chain Memecoin Rug Pull Ring
