THORChain Refuses Bitget Request to Block Hack Addresses

THORChain Refuses Bitget Request to Block Hack Addresses

THORChain rejects Bitget's freeze request

The decentralized protocol THORChain has refused a request from Bitget to block specific wallet addresses linked to a recent hack. Bitget CEO Gracy Chen asked the protocol to deny service to these addresses to help recover stolen funds. However, THORChain stated that its system is permissionless, meaning it cannot selectively block users.

Despite the request, an address listed by Bitget as compromised successfully completed a swap. At 3:14 a.m. ET on September 27, nearly 10,000 XRP were exchanged for Bitcoin through the network. This transaction occurred after both Chen's public appeal and THORChain's official response.

Key details of the exchange hack

  • Bitget reported that approximately $387.5 million in assets were moved to attacker-controlled addresses during an incident on September 24.
  • Bitget is offering bounties of 5% for funds successfully frozen or recovered, excluding actions taken under court orders.
  • The security firm SlowMist, via its MistTrack platform, noted that funds linked to the exploit were entering THORChain for swaps.
  • MistTrack argued that because the addresses were publicly flagged, the protocol had a responsibility to act.

Arguments over decentralization

On September 26, THORChain compared its design to major blockchains like Bitcoin and Ethereum. The protocol's official account asked what responsibility those networks bear when handling stolen funds, implying they do not intervene. Chen countered that decentralization is a design principle, not a shield for facilitating known theft.

OKX founder Star Xu challenged THORChain's comparison to Bitcoin. He explained that THORChain uses a threshold-signature system where multiple validators must authorize transactions. Xu argued that while control is distributed, the presence of validators means there is still an intermediary capable of making decisions.

Technical controls and past disputes

THORChain's documentation confirms it has mechanisms to halt all trading on a specific chain or stop outbound signing entirely. These changes require a vote by nodes through a system called Mimir. However, the protocol distinguishes between a total network halt and blocking specific addresses, noting that a full halt would affect all users, not just bad actors.

This situation mirrors a previous debate following a Bybit hack in 2025. At that time, a vote to stop certain swaps passed initially but was later reversed by other voters.

Current status and recovery efforts

Bitget has released a live application programming interface (API) containing the list of attacker addresses. The exchange continues to seek ways to trace and recover the lost assets. While Bitget urges the industry to block these specific wallets, THORChain maintains its current operational stance based on its decentralized architecture.

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!