THORChain Reportedly Declined to Block $387.5M in Alleged Bitget Hack Funds Moving to Bitcoin
Key Takeaways
- •Reports from September 28, 2026 allege that THORChain declined to block exploit-linked wallets, allowing approximately $387.5 million tied to a purported Bitget hack to be routed into Bitcoin.
- •The claim lacks primary evidence, as Bitget has published no incident disclosure and no transaction hashes or on-chain proof of the fund movement have been independently surfaced.
- •THORChain's permissionless architecture means blocking an address would require a coordinated node majority or an emergency halt through mimir governance parameters, both carrying significant trade-offs such as censorship precedents or impermanent loss exposure for liquidity providers.
- •The situation has a concrete precedent in the February 2025 Bybit theft, when a significant share of roughly $1.5 billion in stolen Ethereum was routed through THORChain, prompting a public debate among node operators over blocking such flows.
- •Verification requires a primary Bitget disclosure, traceable THORChain swap transaction hashes, and a statement from THORChain's node operators or governance forum, while the outcome could shape liquidity provider risk models and attract regulatory scrutiny of cross-chain routing infrastructure.

Reports circulating on September 28, 2026 claim that THORChain, the permissionless cross-chain liquidity protocol, declined to block wallets allegedly connected to a Bitget exchange exploit, allowing approximately $387.5 million to be routed toward Bitcoin.
The claim remains unverified. Available research contains no primary incident statement from Bitget, no transaction hashes, and no on-chain proof of the claimed movement. The $387.5 million figure, the hacker attribution, and THORChain's reported refusal should all be treated as unconfirmed until primary evidence emerges.
What Is Claimed, and What Remains Unconfirmed
The reported narrative describes a Bitget hack followed by a cross-chain conversion of stolen funds into Bitcoin, with THORChain acting as the routing layer. THORChain operates as a decentralised cross-chain automated market maker: it does not custody assets, instead facilitating swaps between native layer-1 tokens, including BTC and ETH, through bonded node operators and liquidity pools. A conversion into Bitcoin, if confirmed, would matter for tracing because chain-hopping is a well-documented laundering pattern: each cross-chain hop forces investigators to re-anchor their analysis on a different ledger, which is why raw transaction hashes rather than wallet labels anchor the verification checklist below.
No on-chain evidence for this specific movement has been independently surfaced at time of publication. Verification would require, at minimum, the origin wallet addresses on the source chain, intermediary swap transaction hashes traceable through THORChain router contracts, and a destination Bitcoin address confirmed by a block explorer such as Mempool.space. None of those elements have been provided in reporting.
Bitget has not issued a security disclosure or incident report confirming an exploit. Until a primary statement is published and the methodology behind the $387.5 million calculation is explained, the figure should be treated as an unconfirmed claim from a single source.
Why Blocking Is Technically and Politically Contested
THORChain's protocol design is permissionless at the swap layer: node operators validate and sign outbound transactions based on threshold signature schemes, not individual address whitelists. Blocking a specific wallet address would require either a coordinated node majority refusing to process transactions from that address, or an emergency halt triggered through the protocol's mimir governance parameters.
Both mechanisms carry significant trade-offs. A node-majority block would set a precedent that validators can selectively censor flows, undermining the censorship-resistance guarantee that underpins THORChain's value proposition to liquidity providers. An emergency halt, used previously during the 2021 exploit incidents, when successive attacks on THORChain's Ethereum router forced the protocol to pause swaps, freezes all swaps and creates impermanent loss exposure for liquidity providers across every pool while the protocol is paused, as Bitcoin prices continue moving while pool positions remain locked.
The censorship-versus-exposure tension has a concrete precedent. When North Korea-linked attackers stole roughly $1.5 billion in Ethereum from Bybit in February 2025 — the largest cryptocurrency exchange theft on record — a significant share of the stolen ETH was routed through THORChain in the days that followed, prompting an unusually public debate among node operators over whether such flows could or should be blocked. Any request arising from the present claim would land on the same fault line between censorship resistance and reputational exposure.
Liquidity providers and arbitrageurs interacting with THORChain's RUNE-denominated pools face a secondary risk if tainted assets enter and are subsequently flagged by compliance tooling downstream. Pool contamination can trigger counterparty refusals on centralised exchanges that source liquidity from cross-chain protocols. This risk is not hypothetical: similar contamination dynamics emerged after the Ronin bridge exploit in 2022, when Tornado Cash-linked ETH reached Uniswap pools.
Minimum Evidence Required Before This Can Be Treated as Confirmed
Three verification steps are needed before the story can be reported as fact rather than an unverified claim. First, a primary Bitget security disclosure or on-chain proof of the exploit's originating transaction. Second, the specific THORChain swap transaction hashes showing the cross-chain route from the source asset to Bitcoin, along with the USD-equivalent value at the time of each swap leg. Third, a statement from THORChain's node operators, core team, or governance forum addressing whether a block was formally requested, whether it was technically feasible given the protocol state at the time, and what the outcome of any internal deliberation was.
Readers tracking the story should monitor THORChain's Thornode governance parameters, maintained in the project's GitLab repository, for any mimir changes, as well as Bitget's official channels for an incident report. On-chain investigators should cross-reference suspected wallet addresses against THORChain's inbound transaction logs on the relevant chain before amplifying the $387.5 million figure.
Protocol-level censorship decisions in DeFi carry governance weight beyond the immediate incident. How THORChain's node set responds, or does not respond, to requests from hacked centralised exchanges will inform liquidity provider risk models and could attract regulatory scrutiny of permissionless routing infrastructure, a pressure point already shaping cross-chain bridge governance across the broader DeFi compliance landscape heading into Q4 2026.