Bitget Formally Asks THORChain to Refuse Service to $387.5 Million Exploit Attacker Addresses
Key Takeaways
- •Bitget suffered a September 24 breach resulting in the theft of approximately $387.5 million assets including AVAX, BNB, ETH, TRX, USDT, USDC, XRP, and ZEC, with the figure revised upward from an initial estimate of $351.6 million.
- •Bitget CEO Gracy Chen publicly called on THORChain to refuse service to the attacker's addresses, warning that the industry is watching how the censorship-resistant protocol responds.
- •THORChain runs on 95 globally distributed nodes with no admin key and no controlling multisig, so any refusal of service would depend on voluntary coordination among independent node operators rather than a corporate decision.
- •Stablecoin issuers Circle and Tether halted nearly $318,000 in movements connected to the hack on September 25, exercising centralized control over token contracts that THORChain lacks by design.
- •Bitget launched a Recovery Bounty Program paying 5% of funds frozen and 5% of funds recovered, is receiving assistance from Mandiant and SlowMist, says the incident is contained, and will restart withdrawals in phases.

Bitget CEO Gracy Chen has publicly confirmed that the exchange is formally asking THORChain to block transactions tied to the exploit that drained approximately $387.5 million from its wallets — a direct appeal to the no-KYC decentralized exchange that blockchain analysts have flagged as a favored laundering route for major crypto thefts.
The request follows intervention by stablecoin issuers Circle and Tether, which halted nearly $318,000 in stablecoin movements connected to the hack on Friday, September 25, as Cryptopolitan reported. Issuers can act that quickly because they retain direct control over their tokens' contracts — a centralized lever THORChain, by design, does not have. Securing cooperation from THORChain, however, is not expected to be as straightforward.
Bitget's appeal to THORChain
Writing on X early Saturday, Chen said, “We are formally asking @THORChain to refuse service to these addresses.” She warned that “the industry is watching,” challenging the protocol not to lean on “a design principle” such as protocol neutrality or decentralization to absolve itself of responsibility while “known stolen funds” move through its platform.
How THORChain could actually intervene is complicated by its structure. Earlier Cryptopolitan reporting noted that the protocol is more synonymous with code than with an actual company: according to the protocol's own account, the DEX runs on 95 globally distributed nodes with no admin key and no controlling multisig. With no admin key, there is no single executive or office to petition; any refusal of service would rest on voluntary coordination among independent node operators rather than a unilateral corporate decision.
THORChain offers fast, permissionless native cross-chain swaps without know-your-customer checks for legitimate users — the same feature that makes it popular with bad actors seeking to move funds out of recovery range. Notably, the protocol did not freeze transactions after its own $10.7 million vault exploit earlier this year. That history is what gives Chen's appeal its weight: the industry is effectively watching whether a protocol built to be censorship-resistant will engage at all when the request comes from a hacked exchange in full public view.
What happened to Bitget
Bitget suffered a September 24 breach that resulted in the theft of $387.5 million, revised upward from an initial estimate of $351.6 million, according to a September 25 support-center update.
The stolen assets included AVAX, BNB, ETH, TRX, USDT, USDC, XRP, and ZEC, parked at primary receiving wallets, including 0x770b…63ee for Ethereum-side assets. Separate addresses hold the XRP, Zcash, and TRON assets.
Bitget has set up a live tracing dashboard and an attacker-address API to monitor the attackers in real time. According to Bitget, cybersecurity firms Mandiant and SlowMist are assisting the investigation, and the exchange says the incident is already contained, ruling out any possibility of further unauthorized transfers. Publicly shared attacker addresses are also what allow issuers, exchanges, and analytics firms to flag deposits across the industry — the same mechanism behind the Circle and Tether freezes.
Why THORChain is the pressure point
Chen is pointing at THORChain because of its track record. TRM Labs described the protocol in May as “the bridge of choice” for laundering North Korea's largest heists, citing the roughly $.5 billion Bybit hack in February 2025 and the nearly $300 million KelpDAO theft. TRM also noted that THORChain “has consistently refused to block illicit activity,” casting that refusal as an anti-censorship stance.
MistTrack called out the same pattern on September 25, citing how nearly $1.2 billion of the Bybit loot moved through THORChain. That gap — issuers and partner firms freezing what they can, while the venue analysts most often cite for laundering such proceeds has historically declined to act — is precisely the tension Bitget's public appeal is designed to force into the open.
What Bitget is doing to recover funds
Beyond the public plea, Bitget has launched a Recovery Bounty Program that pays 5% of any funds frozen and 5% of any funds recovered, routed in part through Bybit's LazarusBounty channel — the bounty framework Bybit built out after its own February 2025 hack. The exchange said some assets have already been frozen with help from industry partners, though actions taken under court orders or law-enforcement requests are excluded from the bounty.
Chen also said Bitget will restart withdrawals in phases, warning that the process will be slower than usual because the incident touches multiple blockchains and multiple tokens. From here, the observable markers are THORChain's response to the appeal, movements of the flagged addresses on Bitget's public tracker, and the pace at which phased withdrawals return to normal.