THORChain Refuses to Block Bitget Hack Wallets After $387.5M Theft, Reigniting Bybit Controversy

THORChain Refuses to Block Bitget Hack Wallets After $387.5M Theft, Reigniting Bybit Controversy

Custom Image

Bitget Hack Puts THORChain’s Permissionless Design Under Scrutiny

On September 24, 2026, Bitget detected unauthorized transfers from portions of its hot and warm wallet infrastructure at 18:31 UTC. The exchange later revised the total value of assets moved to attacker-controlled addresses to approximately $387.5 million, up from an initial $351.6 million estimate after accounting for additional Zcash and TRON transfers. The stolen assets spanned XRP, ETH, USDT, USDC, BNB, AVAX, ZEC, and TRX across multiple networks. Bitget CEO Gracy Chen publicly identified the attacker addresses and, on September 26, formally asked THORChain to refuse service to those wallets.
 
THORChain declined the same day, stating that the protocol is decentralized and permissionless in the same manner as Bitcoin, Ethereum, and BNB Chain. Stolen XRP and other assets continued to be swapped toward Bitcoin on the network after the refusal. The episode has renewed industry debate over selective intervention by cross-chain protocols and drawn direct comparisons to THORChain’s handling of funds from the February 2025 Bybit breach. This article examines the verified sequence of events, the technical and governance arguments advanced by both sides, the documented historical parallel with Bybit, the market response in RUNE volume and price, and the practical implications for users and protocols operating under a permissionless design.

Bitget’s September 24 Breach and Revised Loss Estimate

Bitget’s security systems registered abnormal transfers beginning at 18:31 UTC on September 24. The company suspended withdrawals while leaving deposits and trading operational and confirmed that cold wallets and private keys remained uncompromised. Initial public estimates placed the loss at $351.6 million. After further on-chain accounting that incorporated previously uncounted Zcash and TRON movements from the same attack window, Bitget raised the figure to approximately $387.5 million. Affected assets included roughly 103 million XRP (valued near $157 million at the time), tens of thousands of ETH, multimillion-dollar quantities of USDT and USDC, plus BNB, AVAX, ZEC, and TRX. The exchange engaged Mandiant and SlowMist for the investigation and stated that a third-party security product vulnerability had allowed attackers to obtain internal credentials and forge withdrawal commands that bypassed risk checks. Bitget maintained that customer funds would be covered by its User Protection Fund, which holds 5,500 Bitcoin valued at over $464 million, and scheduled a phased resumption of withdrawals beginning with Bitcoin on September 28.
 
Chen described the attack patterns, including certain IP and VPN indicators, as consistent with techniques previously associated with North Korean-linked groups. Blockchain analytics firms, including Elliptic, assessed the incident as highly likely to be linked to the same actors responsible for earlier large-scale thefts, citing infrastructure overlaps with addresses used in the laundering of Bybit proceeds. Bitget offered a 5 percent bounty for assistance in freezing or recovering the assets, excluding actions taken under court order. The scale of the loss placed immediate pressure on the protection fund, which could absorb the full amount while leaving a residual balance, after which the exchange planned to replenish the reserve toward its $300 million baseline commitment.

Chen’s Public Request to THORChain on September 26

Two days after the breach, Chen posted a formal request on X directed at THORChain. She stated that the attacker addresses were publicly listed and actively tracked and asked the protocol to refuse service to those addresses. Chen argued that decentralization functions as a design principle rather than a shield for facilitating known stolen funds and added that the industry was watching the response. The appeal quoted tracking data from MistTrack, the platform operated by SlowMist, which had already flagged flows of Bitget-linked assets into THORChain liquidity pools. The request was framed as an industry test of whether cross-chain infrastructure would cooperate in containing the movement of assets whose illicit origin had been publicly asserted by the victim exchange.
 
THORChain’s official account replied the same day at 18:17 UTC. The response expressed sympathy for those affected by the exploit and then restated the protocol’s core position: THORChain operates as a decentralized and permissionless network comparable to Bitcoin, Ethereum, and BNB Chain. The account asked what responsibility those base-layer networks should bear when handling known stolen funds. The reply tagged both Chen and OKX founder Star Xu, signaling that the protocol viewed the demand as a broader industry question rather than a bilateral operational request. Subsequent on-chain activity showed that at least one address flagged by Bitget successfully completed an XRP-to-Bitcoin swap on September 27 after both the request and the refusal had been posted.

THORChain’s Permissionless Design and Network Halt Distinction

THORChain functions as a cross-chain liquidity protocol that enables native asset swaps without centralized custody or identity checks. Liquidity is provided through pools secured by a threshold-signature scheme operated by independent node operators. Network parameters and emergency actions are governed by code, smart contracts, and node consensus rather than a single administrative entity. The protocol maintains an emergency network-halt mechanism intended to protect the system as a whole when its own security is threatened. In May 2026, that mechanism was activated after approximately $10.7 million was drained from liquidity pools; the network was halted, and the attackers’ addresses were not blacklisted for future activity.
 
THORChain has repeatedly distinguished a full network halt from selective address blocking. A halt suspends all activity and requires node coordination through the Mimir governance system. Selective refusal of individual wallets or swaps is not supported by the current design without altering the permissionless character of the protocol. Critics, including Star Xu, have argued that the existence of a working halt capability demonstrates that node operators can intervene when protocol-owned funds are at risk and that the same capacity could be applied to external stolen assets. THORChain maintains that applying the mechanism selectively would convert the network into a discretionary intermediary and undermine the neutrality that underpins its value proposition.

Continued Movement of Stolen Assets Through THORChain Pools

On-chain trackers documented ongoing swaps of Bitget-linked assets after Chen’s request and THORChain’s refusal. One flagged address completed a transfer of nearly 10,000 XRP into Bitcoin at 3:14 a.m. ET on September 27. Separate monitoring showed additional ETH deposits into THORChain vaults on September 28 with instructions to stream the output as Bitcoin. Earlier estimates indicated that tens of millions of dollars in value had already passed through the protocol’s pools in the days immediately following the breach, converting portions of the stolen XRP, BNB, and other assets into native Bitcoin. Once converted, Bitcoin becomes significantly harder to freeze through conventional centralized channels.
 
The volume surge produced measurable fee revenue for liquidity providers and node operators. Daily swap volume on THORChain rose sharply, with reports of multi-month highs and single-day figures approaching or exceeding $500 million in the period surrounding the Bitget flows. The activity contributed to a short-term price advance in RUNE, which rose more than 20 percent in a 24-hour window around September 26–27 before later consolidating. The market reaction illustrated the economic incentive structure of a permissionless liquidity network: elevated volume, regardless of asset origin, generates fees that accrue to participants.

Parallels with the February 2025 Bybit Incident

The Bitget episode revived detailed scrutiny of THORChain’s role after the February 21, 2025, Bybit breach. In that attack, approximately $1.5 billion in ETH and related assets were taken; the FBI later attributed the theft to North Korean actors. Within roughly ten days, the majority of the stolen ETH had been converted to Bitcoin, with Bybit’s CEO saying about 72 percent of the converted value passed through THORChain. Tracking firms placed the THORChain-handled portion near $1.2 billion. At the peak of those flows, a minority of validators voted to halt ETH trading; a larger set of nodes reversed the halt within minutes. A core contributor who had supported intervention subsequently departed the project.
 
The Bybit precedent established two lasting points of contention. First, THORChain demonstrated both the technical ability to pause activity and the governance preference for remaining open. Second, the protocol earned substantial swap fees during the laundering window. Industry observers noted that the same pattern, public identification of stolen funds followed by continued processing, had now repeated with Bitget. The recurrence strengthened arguments that the protocol’s neutrality policy is consistent across external incidents while remaining selective when its own vaults are directly threatened.

Criticism from OKX Founder Star Xu and Supporting Voices

Star Xu publicly rejected THORChain’s comparison of itself to Bitcoin and Ethereum. He argued that a network whose validators can halt activity when protocol funds are at risk, yet declines to do so when external stolen funds are moving, cannot claim equivalence to base-layer chains whose private keys rest solely with users. Xu characterized THORChain’s threshold-signature vault model as creating an intermediary layer rather than pure permissionlessness. The critique was amplified by security firms that pointed to the May 2026 halt as evidence of operational capacity that could, in principle, be applied more broadly.
 
Defenders of THORChain’s stance, including some independent developers and Dashpay’s Joel Valenzuela, maintained that requiring selective censorship would destroy the protocol’s core value. They noted that Bitcoin and Ethereum themselves have processed known stolen funds without network-level freezes and that imposing such freezes on THORChain would set a precedent for every subsequent demand. The exchange of views on X highlighted a structural tension: the same node operators who can coordinate a halt for self-protection face no automated incentive or legal compulsion to intervene on behalf of external victims.

Market Reaction in RUNE Price and Protocol Volume

Despite the critical coverage, RUNE advanced more than 20 percent in the 24 hours surrounding THORChain’s refusal, briefly trading above $0.80 and reaching levels not seen since late 2025. Trading volume expanded several-fold as the controversy drew attention. The price later retraced some of the gains, yet the episode demonstrated that elevated swap activity can produce short-term positive price pressure even when the activity itself is the subject of public dispute. Liquidity providers earned fees on the elevated volume, reinforcing the economic logic that keeps the network open under normal operating conditions.
 
The volume spike also illustrated a practical reality for cross-chain protocols. When large quantities of assets need rapid conversion across chains, THORChain’s deep native liquidity becomes an attractive venue precisely because it does not impose address-level filters. That attractiveness generates revenue and, in turn, supports the token price and node economics that sustain the network. Critics view the revenue as tainted; supporters view it as the unavoidable consequence of a neutral design.

Bitget’s Protection Fund and User Impact

Bitget stated that its User Protection Fund, holding 5,500 Bitcoin valued at over $464 million, would cover the full $387.5 million loss. After reimbursement, the residual balance would still exceed the exchange’s long-standing $300 million baseline commitment, which management planned to restore within a week. The company also cited proprietary assets exceeding $1 billion as additional backstop capacity. Phased withdrawal restoration began on September 28 with Bitcoin, followed by ETH, USDT, and remaining assets through early October. The fund structure allowed Bitget to assert that individual users would not bear direct losses from the incident.
 
The episode nevertheless tested the practical limits of exchange-level insurance. A single event consuming more than 80 percent of the stated fund value left limited headroom for subsequent incidents of comparable size. Bitget’s public commitment to replenish the reserve and its engagement of external forensic firms were presented as steps toward restoring operational confidence. The speed of the planned withdrawal restart indicated that the exchange viewed the technical vulnerability as contained once the immediate investigation and patching process concluded.

North Korean Attribution and Broader Threat Context

Chen stated that certain IP and behavioral indicators were consistent with techniques used by North Korean-linked groups, while emphasizing that attribution remained preliminary. Elliptic independently assessed the Bitget incident as highly likely to be linked to the same actors behind earlier major thefts, citing on-chain overlaps with addresses used in Bybit laundering and infrastructure patterns previously associated with the TraderTraitor campaign. The assessment placed cumulative suspected North Korean crypto thefts for 2026 above $1 billion after the Bitget event.
 
The pattern of rapid conversion of stolen assets into Bitcoin through permissionless venues has become a recurring operational signature. Once funds reach native Bitcoin, recovery options narrow substantially. Protocols that maintain open access therefore sit at a critical junction in the post-theft lifecycle. The industry debate centers on whether those protocols should treat publicly identified stolen funds as ordinary traffic or as a category requiring exceptional handling.

Governance Limits of Selective Intervention

THORChain’s node set can coordinate a network-wide halt through Mimir votes, yet the protocol’s published design does not include an address-level blacklist that can be applied without broader consensus. Past interventions have focused on protecting protocol-owned liquidity rather than external claims. Implementing selective blocking would require either a change in consensus rules or an informal administrative layer that the current architecture explicitly avoids. The May 2026 halt demonstrated that emergency action is feasible when the network’s own solvency is threatened; the Bitget and Bybit cases demonstrated that the same operators have chosen not to extend that action to external victims.
 
The absence of a selective mechanism is therefore both a technical statement and a governance preference. Node operators face no contractual or automatic obligation to act on third-party requests. Any future decision to introduce address filtering would itself require a governance process that could be contested by the same participants who currently prioritize openness.

Industry Influence for Cross-Chain Infrastructure

The Bitget–THORChain exchange has significantly illuminated the nuanced and practical boundary that exists between base-layer chains and application-layer liquidity protocols. In the realm of cryptocurrency, Bitcoin and Ethereum are designed to process transactions without any regard to their origin, primarily because there is no committee of validators that exercises control over users' private keys. In contrast, THORChain’s innovative vault model introduces a certain threshold of operator control, which critics argue effectively creates a de facto intermediary in the transaction process. However, supporters of this model counter that such control is exercised solely for the purpose of ensuring the survival of the protocol itself and that any expansion of this control could potentially undermine the competitive advantage that permissionless cross-chain swaps currently enjoy.
 
In the broader space, other bridges and swap venues have opted for different methodologies, including the implementation of temporary freezes or cooperation with law enforcement requests to address issues of security and compliance. This divergence in approaches leaves the industry grappling with the absence of a uniform standard, which is crucial for fostering trust and stability. Each new instance of large-scale theft serves as a critical test of whether the permissionless model can withstand the mounting public pressure without compromising the neutrality that is essential for attracting legitimate trading volume and participation in the ecosystem.

Ongoing On-Chain Activity and Recovery Efforts

As of late September 2026, various segments of the assets linked to Bitget continued to traverse through THORChain and alternative routes. Tracking dashboards that are diligently maintained by Bitget, alongside independent analysts, indicated a steady and progressive conversion of these assets into Bitcoin and various secondary layers. While stablecoin issuers managed to freeze relatively small amounts, the majority of the overall value remained active and mobile. Bitget’s bounty program, in conjunction with its coordination efforts with forensic firms, continues to serve as the primary channel for asset recovery, particularly in the absence of judicial orders.
 
The ongoing flow of these assets highlights the inherent difficulty in containing them once they have entered a permissionless liquidity network. Each successful swap diminishes the available window for freezing these assets and simultaneously increases the costs associated with any subsequent recovery efforts. The protocol’s refusal to take intervention measures, therefore, has direct and significant consequences for both the speed and the completeness of any restitution process that may be undertaken.

What the Episode Reveals About Protocol Neutrality

The sequence of events, from the September 24 transfers, through Chen’s September 26 request, THORChain’s same-day refusal, and the subsequent continued swaps, provides a concrete case study rather than an abstract debate. THORChain has articulated a consistent policy: network-level emergency halts exist to protect the protocol; selective address blocking does not. Critics have documented instances in which the same operators acted when their own funds were at stake.
 
The resulting tension is structural and unlikely to resolve through a single exchange of public statements. Future incidents will test whether node operators maintain the same line under sustained external pressure or whether governance evolves toward more discretionary tools. For now, the protocol continues to process transactions without origin-based filters, and the market has responded to the elevated volume with both higher fees and short-term price appreciation in RUNE.

🔥 Beyond the Headlines: What KuCoin 5.0 Means for You

Market news moves fast — but where you act on it matters just as much. This October, KuCoin launches KuCoin 5.0, transforming KuCoin into a rebuilt platform. Here's what actually changes for you:
 
  • One account for everything. Older platforms split your money across separate "spot," "margin," and "futures" accounts and expected you to understand why. KuCoin 5.0's unified account removes that entirely — deposit once, and everything is simply there (only available to VIPs for now).
  • Stocks, indices, and commodities. KuCoin 5.0 expands beyond crypto into global markets. When crypto chops sideways and equities rally (or the reverse), you rotate in minutes instead of opening a brokerage account and waiting days for fiat rails.
  • Real-world assets (RWA). Tokenized exposure to traditional assets like commodities, right inside your crypto account. One of the fastest-growing segments in global finance is no longer reserved for institutions — you access it from the same balance you trade with.
  • Earn while you learn. Not ready to trade? KCUSD lets your stablecoins earn daily, auto-compounding interest. The lowest-stress way to put your idle deposit to work for 4% yield.
  • An AI assistant in plain language. Ask questions, get market context, understand what you're looking at — built into the platform, no jargon required.
  • An app that doesn't overwhelm. Faster, cleaner, and consistent — intuitive from the first tap, not after a tutorial.
  • Safety you can check, not just trust. A MiCAR-licensed EU entity, Proof of Reserves you can verify yourself, and internationally certified security (SOC 2 Type II, ISO 27001:2022).
 
Create your account in minutes — and start on the platform built for where crypto is going, not where it's been.

FAQs

How large was the Bitget loss, and how was the figure revised?

Bitget initially reported approximately $351.6 million in unauthorized transfers detected on September 24, 2026. After incorporating additional Zcash and TRON movements from the original attack window, the exchange raised the confirmed total to about $387.5 million. The revision reflected expanded accounting rather than new thefts after the initial detection. Affected assets included substantial quantities of XRP, ETH, stablecoins, and other tokens across several networks. The company stated that cold wallets and private keys were never compromised.
 

Why did THORChain refuse Bitget’s request to block specific wallets?

THORChain stated that it operates as a decentralized and permissionless protocol comparable to Bitcoin, Ethereum, and BNB Chain. Its design does not support selective refusal of individual addresses without compromising that neutrality. The protocol’s emergency halt mechanism is reserved for protecting the network as a whole and is not configured as a tool for freezing specific funds or swaps. The official response emphasized that base-layer networks also process transactions without origin-based censorship.
 

What historical parallel exists with the Bybit hack?

In February 2025, Bybit suffered a theft of roughly $1.5 billion in ETH and related assets, later attributed by the FBI to North Korean actors. Tracking showed that a large majority of the converted value, estimated near $1.2 billion, passed through THORChain within about ten days. A temporary validator vote to halt ETH trading was reversed shortly after it was enacted. The Bitget episode has been widely compared to that earlier pattern of continued processing after public identification of stolen funds.
 

Did any of the stolen Bitget assets continue moving after the refusal?

Yes. On-chain records show that at least one address listed by Bitget completed an XRP-to-Bitcoin swap on September 27 after both the request and THORChain’s response had been published. Additional ETH deposits into THORChain vaults with Bitcoin output instructions were observed on September 28. Trackers reported tens of millions of dollars in value already converted through the protocol’s pools in the days following the breach.
 

How is Bitget covering user losses?

Bitget’s User Protection Fund holds 5,500 Bitcoin valued at over $464 million. The exchange stated that the fund is sufficient to cover the full $387.5 million loss and that it would replenish the reserve toward its $300 million baseline commitment. Phased withdrawal restoration began with Bitcoin on September 28. The company also cited proprietary assets exceeding $1 billion as further capacity.
 

What role did North Korean attribution play in the discussion?

Bitget’s CEO cited IP and behavioral indicators consistent with techniques used by North Korean-linked groups. Analytics firm Elliptic assessed the incident as highly likely to be connected to the same actors behind prior major thefts, noting on-chain overlaps with Bybit laundering infrastructure. The assessment contributed to estimates that suspected North Korean crypto thefts for 2026 exceeded $1 billion after the Bitget event. Attribution remains based on pattern matching rather than definitive public forensic proof.
 
Disclaimer: This content is for informational purposes only and does not constitute investment advice. Cryptocurrency investments carry risk. Please do your own research (DYOR).