THORChain Rejects Bitget’s Call to Block Funds Linked to $387.5M Hack

THORChain has rejected a request from Bitget to block cryptocurrency linked to the exchange’s September 24, 2026, security breach, which reportedly involved approximately $387.5 million in stolen assets. The response has renewed debate over how permissionless blockchain protocols should handle funds associated with suspected hacks. Bitget CEO Gracy Chen called on THORChain to refuse service…

4 minutes

Read Time

THORChain has rejected a request from Bitget to block cryptocurrency linked to the exchange’s September 24, 2026, security breach, which reportedly involved approximately $387.5 million in stolen assets. The response has renewed debate over how permissionless blockchain protocols should handle funds associated with suspected hacks.

Bitget CEO Gracy Chen called on THORChain to refuse service to addresses connected to the attackers. Her appeal puts pressure on decentralized infrastructure that can facilitate cross-chain swaps, including transactions involving assets that may have been stolen from centralized platforms.

THORChain said its network halt mechanism is an emergency security measure intended to protect the protocol as a whole. It argued that the mechanism is not designed to freeze specific wallets, block individual swaps or selectively restrict funds based on their suspected origin.

The protocol’s response centers on its permissionless design. THORChain described itself as a neutral public tool that does not censor transactions, suggesting that selectively blocking addresses would conflict with the principles guiding its operation.

THORChain Defends Its Permissionless Design

In its statement, THORChain pointed to its own May 2026 exploit, which it said resulted in approximately $10.7 million being stolen from liquidity pools. According to the protocol, the attackers’ addresses were not blacklisted and were therefore not prevented from swapping through the network.

The comparison is central to THORChain’s position. By referring to its own security incident, the protocol argued that its approach to attacker-linked addresses has been consistent, rather than a response created specifically for Bitget’s request.

A network halt and an address-level restriction serve different purposes. A halt can suspend protocol activity during an emergency to limit wider exposure, while a selective freeze would target particular addresses or transactions. THORChain says its halt mechanism is intended for the former, not the latter.

Related: THORChain Defends Permissionless Model Amid Bitget Exploit Fund Claims

The distinction also highlights the limits of emergency controls in decentralized systems. A protocol may have mechanisms to respond to technical threats, but those mechanisms do not necessarily provide a way to identify, investigate and block every transaction linked to suspected criminal activity.

THORChain’s position does not resolve the question of whether permissionless protocols should take additional steps when funds are publicly attributed to a security breach. Instead, it underscores a conflict between maintaining open access to decentralized infrastructure and responding to requests from victims seeking to limit the movement of stolen assets.

Bitget’s Request Raises Questions About Protocol Responsibility

For Bitget, asking THORChain to restrict attacker-linked addresses is an attempt to limit the routes available for moving the stolen assets. Cross-chain swap protocols can be relevant to such investigations because they allow users to exchange assets across different blockchain networks without relying on a conventional centralized exchange.

However, identifying an address as connected to an exploit does not, by itself, establish that every transaction involving it is controlled by the attacker. Address attribution, the movement of funds and the legal authority to restrict assets can involve separate technical and investigative questions.

Related: THORChain Returns Online as Team Prepares Monero and Zcash Integrations

The dispute reflects a wider challenge for decentralized finance. Centralized platforms can generally apply internal controls to accounts and transactions, subject to applicable law and their own policies. Permissionless protocols may lack a comparable central operator with the authority or ability to selectively intervene.

THORChain’s statement makes clear that it does not intend to use its network halt mechanism as a targeted blocking tool. Whether other protocol-level safeguards, governance decisions or law-enforcement processes could play a role remains a separate question.

Related: THORChain Reports $10.7 Million Vault Breach as Network Activity Pauses

The disagreement leaves the broader issue unresolved: how decentralized networks should respond when their infrastructure is used to move funds allegedly stolen in a major exploit. Bitget is seeking restrictions to impede the movement of those assets, while THORChain maintains that selective censorship is inconsistent with its design. The practical consequences will depend on how the stolen funds move and what additional responses, if any, emerge from the parties involved.

About The Author

About the Author

AltCoinsAnalysis.Com

The site primarily publishes price narratives, project updates, regulatory headlines, and speculative market insights, targeting traders and investors who want quick reads on potential opportunities in the crypto space. Its content style is opinionated and momentum-focused, often centered around market hype cycles such as altcoin seasons, ETF developments, and major token announcements.

Search the Archives

Access over the years of investigative journalism and breaking reports