Crypt0's NewsCrypt0's News

Crypto

THORChain Turned Down Bitget’s Request, and Asked the Industry Its Hardest Question

The Bitget hack keeps growing. What started as a $351 million estimate now stands at approximately $387.5 million moved to attacker controlled addresses, after additional Zcash and TRON transactions were classified. The attackers have been washing the haul across several rails, Chainflip, Uniswap, 1inch Fusion, Stargate, Across, Relay, and THORChain among them. On Saturday, Bitget CEO Gracy Chen took the fight public, formally asking THORChain to refuse service to the identified addresses, writing “Our attacker addresses are publicly listed and actively tracked,” she wrote. “Decentralization is a design principle, not a shield for facilitating known stolen funds. The industry is watching.”

On Saturday afternoon Eastern time, THORChain’s official account answered, tagging Chen directly. “We are devastated to hear about the recent exploit and can imagine how difficult this must be for everyone involved. THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain. What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?” MistTrack, SlowMist’s tracking platform, had flagged THORChain as a conduit for the stolen funds and argued the industry needs a real discussion about what decentralized protocols owe in these cases. OKX founder Star Xu joined the thread, questioning the decentralization claim.

THORChain has been here before. After the Bybit breach, when roughly $1.2 billion in stolen funds flowed through the protocol, the FBI asked the industry to stop DPRK linked addresses; three THORChain validators voted to halt ETH trading, four reversed the decision within half an hour, and the network kept running. A developer quit over the episode. The protocol can pause itself, as it showed after the May 2026 GG20 exploit drained about $10.7 to $11 million from a vault, operators kept the network down for weeks while they patched. Some THORChain front ends have screened flagged addresses for years, though that screening is easy to bypass. The pattern is consistent. The base layer stays permissionless, and the edges do the filtering.

The honest version of the debate is bigger than one protocol. Bitcoin miners confirm transactions from sanctioned addresses every day. Ethereum validators include whatever the mempool offers. Compliance desks are asked of custodians and exchanges, the businesses with customer relationships, while base layers stay neutral by design. THORChain’s counter question lands for the same reason. If the rule is that permissionless infrastructure must freeze funds on request, then every base layer becomes a regulated intermediary, and the censorship resistance that gives the whole space its value proposition dissolves at the first phone call.

There is a middle worth naming. Chen’s position has real weight. The addresses are public, the funds are tracked, and refusing them costs a protocol nothing technically. THORChain’s has weight too. A network that freezes on request today freezes on a different request tomorrow, and the list of requesters only grows. The market, tellingly, read the refusal as conviction. RUNE jumped on the day as traders priced in the protocol’s commitment to its own design. Both sides are arguing from principles they actually hold, which is why the argument keeps recurring.

For readers, the practical lesson sits one layer up from the drama. Permissionless rails move any funds, clean or stolen, and that property is the design working as intended. Recovery of stolen crypto will keep depending on the off ramps, the exchanges, bridges with compliance teams, and investigators following the money across chains. The base layer stays neutral. Everything built on top gets to choose. That division of labor is the whole design, and this weekend showed it working exactly as specified, under the worst possible spotlight.

Quick answers

What is this story about?

The Bitget hack keeps growing. What started as a $351 million estimate now stands at approximately $387.5 million moved to attacker controlled addresses, after additional Zcash and TRON transactions were classified. The attackers have been washing the haul across several rails, Chainflip, Uniswap, 1inch Fusion, Stargate, Across, Relay, and THORChain among them. On Saturday, Bitget CEO Gracy Chen took the fight public, formally asking THORChain to refuse service to the identified addresses, writing “Our attacker addresses are publicly listed and actively tracked,” she wrote. “Decentralization is a design principle, not a shield for facilitating known stolen funds. The industry is watching.”

Why does this story matter?

For readers, the practical lesson sits one layer up from the drama. Permissionless rails move any funds, clean or stolen, and that property is the design working as intended. Recovery of stolen crypto will keep depending on the off ramps, the exchanges, bridges with compliance teams, and investigators following the money across chains. The base layer stays neutral. Everything built on top gets to choose. That division of labor is the whole design, and this weekend showed it working exactly as specified, under the worst possible spotlight.

Sources

New to crypto? Read the crypto glossary, browse frequent questions, read our story, or explore the story archive.

← Back to Crypt0's News