THORChain’s response to Bitget’s $387.5M hack sparks blacklist debate
0
0

A hacker walks off with hundreds of millions in stolen crypto, and the exchange that got robbed turns to a blockchain protocol and asks it to simply stop the money from moving. That’s essentially what happened this week between Bitget and THORChain, and the protocol’s blunt refusal has reignited one of crypto’s oldest arguments: how far a “permissionless” network should go to help victims of theft. THORChain’s response to the hack has become a flashpoint for that debate, exposing a rift between exchanges that want intervention and infrastructure that insists on staying neutral.
Key takeaways
- Bitget suffered a security breach on September 24, with stolen assets eventually valued at about $387.5 million after the exchange traced additional Zcash and TRON transactions.
- Bitget CEO Gracy Chen publicly asked THORChain to refuse service to wallet addresses linked to the attacker.
- THORChain rejected the request, saying its emergency halt mechanism protects the protocol as a whole rather than freezing individual addresses or swaps.
- The protocol pointed to its own $10.7 million exploit in May, when attacker addresses were also never blacklisted.
- Security firm GoPlus Security pushed back on THORChain’s comparison to Bitcoin and Ethereum, while THORChain supporter Michael Perklin defended the protocol’s neutral-infrastructure argument.
Bitget Hack and CEO’s Call to Block Attacker Addresses
Bitget’s breach began on September 24, when an attacker compromised what the exchange later described as a critical backend system inside its wallet infrastructure and used it to trigger unauthorized transfers. The exchange initially estimated the damage at $351.6 million before revising that figure upward to roughly $387.5 million once investigators identified more transactions involving Zcash and TRON. Assets swept up in the breach spanned Ethereum and several EVM chains, the XRP Ledger, Zcash and TRON, with tokens including XRP, ETH, USDT, ZEC, USDC, BNB, AVAX and TRX among those affected.
Bitget said its private keys were not compromised and that its cold wallets, along with the separate Bitget Wallet product, remained untouched. Still, the scale of the theft put pressure on Chen to act publicly. On September 26, she said the addresses tied to the attacker had been identified and were being actively tracked, and she used that moment to make a direct appeal to THORChain.
“Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds,” Chen wrote, adding, “The industry is watching.”
THORChain’s Response to the Hack
THORChain’s answer, delivered on September 28, was a firm no. The protocol explained that its emergency halt mechanism exists to protect the network itself in moments of crisis, not to selectively cut off specific wallets or block a single transaction.
“A THORChain network halt is an emergency security mechanism designed to protect the protocol. A halt is not a selective freeze of specific funds or an individual swap,” the protocol said, pointing back to its own May 2026 exploit that drained $10.7 million from its liquidity pools without any addresses being blacklisted afterward.
Why a Network Halt Isn’t a Blacklist
That distinction sits at the center of THORChain’s defense. A halt, in the protocol’s telling, is a blunt instrument that pauses activity network-wide to stop further damage — not a scalpel that can be pointed at one wallet while letting everything else run normally. THORChain reiterated that its design is permissionless, meaning no central authority sits inside the system with the power to selectively deny service to a user based on who they are or what they’ve done. This is precisely why calls like Bitget’s create friction: they ask a decentralized system to behave like a centralized one, at least temporarily, for a cause most people would agree is justified.
Security Firms and Crypto Community React
THORChain’s neutrality argument didn’t go unchallenged. GoPlus Security argued on September 27 that comparing THORChain to Bitcoin or Ethereum overstates how decentralized its architecture actually is. The firm pointed to THORChain’s threshold signature vault system, in which the active validator set collectively controls vaults and signs outbound transactions — a structure that, according to GoPlus, gives node operators documented pause mechanisms, per-chain halts and the ability to coordinate votes that stop activity.
That’s different, GoPlus said, from Bitcoin and Ethereum, where individual users hold their own private keys and validators never collectively custody assets inside protocol-controlled vaults. In other words, if THORChain’s validators already have the technical means to pause chains and coordinate action, the firm suggested the “we simply can’t do that” defense deserves more scrutiny.
Comparing THORChain to Bitcoin and Ethereum
Michael Perklin, a longtime crypto security executive and vocal THORChain supporter, rejected that framing. He argued that threshold signing doesn’t mean node operators individually approve or reject each transaction — the process is automated, and the only real lever an operator has is switching their node off entirely. “In all 3, there is no active choice to sign, only an active choice to turn off the machine,” Perklin said, comparing THORChain node operators to Bitcoin miners or Ethereum validators who could theoretically go offline rather than process a transaction. He described Bitcoin, Ethereum and THORChain alike as neutral public infrastructure, arguing that shutting down that infrastructure to block one bad actor would also freeze legitimate users caught in the same pipeline.
This isn’t the first time THORChain has faced this exact accusation. During the 2025 Bybit hack, attackers routed stolen Ether through the protocol on their way to Bitcoin, generating roughly $2.91 billion in trading volume and about $3 million in fee income for THORChain along the way. A proposal at the time to block transactions linked to the Bybit attacker failed to win support from node operators, and a core developer subsequently left the project over the decision. The Bitget case follows almost the same script, which suggests this is less a one-off dispute than a recurring tension baked into how THORChain governs itself.
THORChain’s own May incident adds another layer to the story. A malicious node operator exploited a weakness in the protocol’s GG20 Threshold Signature Scheme on May 15, draining about $10.7 million from one of its five vaults. Automatic solvency checks caught the imbalance and halted signing and trading across several chains before operators coordinated a broader shutdown. THORChain later drew criticism for proposing to patch rather than fully replace the flawed signing framework, eventually rolling out version 3.19.0 as part of an 11-step restart plan that quarantined compromised vaults and added temporary keyshare checks. Full trading only resumed on June 23, more than a month after the halt began — and even then, the attacker’s addresses were never blacklisted.
Bitget’s Ongoing Recovery Efforts
While the THORChain dispute plays out publicly, Bitget is working through the practical business of tracing and recovering what it can. Chen launched a recovery bounty offering a 5% reward for anyone who successfully helps freeze stolen assets, plus another 5% for funds actually recovered. Circle and Tether had already frozen approximately $318,000 in USDC and USDT tied to the breach as of September 26, a small fraction of the total loss but an early sign that some centralized issuers are willing to act where a decentralized protocol won’t.
Independent cybersecurity firms Mandiant and SlowMist are supporting Bitget’s investigation and fund-tracing work. The exchange has also started restoring withdrawals in stages after fixing the underlying vulnerability: Bitcoin withdrawals were set to resume September 28, followed by ETH on September 29 and USDT on September 30, with remaining tokens, fiat and peer-to-peer services scheduled to come back online October 2.
The gap between what centralized issuers like Circle and Tether can do and what a permissionless blockchain like THORChain will do highlights a structural reality of crypto asset theft: recovery options narrow sharply once funds leave systems with a company behind them and enter infrastructure built specifically to have no one in charge.
FAQ
What was the scale and impact of the Bitget security breach?
On September 24, Bitget suffered a security breach with about $387.5 million in stolen assets affected.
What did Bitget CEO Gracy Chen request from THORChain after the hack?
Gracy Chen formally asked THORChain to refuse service to addresses linked to the attackers involved in the Bitget breach.
Why did THORChain refuse to block the attacker addresses?
THORChain’s network halt mechanism is designed to protect the entire protocol and does not support selectively freezing specific addresses, reflecting its permissionless design.
Has THORChain handled similar security incidents in the past?
Yes, during a $10.7 million exploit in May, THORChain did not blacklist attacker addresses but halted the network to protect the protocol.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
0
0
Securely connect the portfolio you’re using to start.





