NewsCryptoTHORChain Faces Renewed Pressure as Bitget Hacker Funds Move Through Its Cross-Chain Network

THORChain Faces Renewed Pressure as Bitget Hacker Funds Move Through Its Cross-Chain Network

Author: CryptoMeter io·

Key Takeaways

  • •Bitget raised its estimate of breach losses from $351.6 million to $387.5 million, while stating that user funds and cold wallets remained secure.
  • •Bitget CEO Gracy Chen publicly called on THORChain to refuse service to attacker-linked addresses, noting the industry is watching the protocol's response.
  • •TRM Labs reported that portions of the stolen proceeds moved through THORChain after passing through intermediary wallets before being converted into Bitcoin.
  • •THORChain's permissionless design leaves no single operator able to unilaterally block addresses, so any intervention would need to emerge through decentralized governance, as debated after the 2025 Bybit hack.
  • •Circle and Tether froze roughly $318,000 in stablecoins linked to the attacker, but more than 63,000 ETH stayed in exploiter addresses beyond issuer-controlled freeze mechanisms.
THORChain Faces Renewed Pressure as Bitget Hacker Funds Move Through Its Cross-Chain Network

THORChain is confronting renewed scrutiny after funds tied to the Bitget security breach were routed through its cross-chain infrastructure, reopening a debate over how decentralized protocols should handle known stolen assets.

Bitget initially estimated the breach at $351.6 million before raising the figure to $387.5 million. According to CoinDesk, the exchange said its user funds and cold wallets remained secure.

Gracy Chen, Bitget's chief executive, has publicly asked THORChain to refuse service to addresses linked to the attacker. Chen argued that decentralization should not become a shield for moving known stolen funds and said the industry was watching THORChain's response.

THORChain's Decentralized Model Under Scrutiny

The dispute centers on THORChain's permissionless design. The network enables users to swap native assets across blockchains without relying on a centralized intermediary, a structure that also makes direct intervention against individual addresses more difficult. With no single operator able to unilaterally block specific addresses, any intervention would have to surface through the network's decentralized governance — the same mechanism that anchored the earlier Bybit-era debate over whether validators should act.

Blockchain tracing has identified portions of the Bitget proceeds moving through THORChain before conversion into Bitcoin. Chain-analytics firm TRM Labs said some stolen assets moved through the network after passing through intermediary wallets, while other cross-chain services also appeared in the laundering path.

The episode echoes the earlier controversy surrounding THORChain after the 2025 Bybit hack, when the network faced pressure to restrict transactions involving funds attributed to North Korean-linked attackers. Its decentralized governance structure became central to the debate over whether validators should intervene. Chen's appeal now revives that question, this time with an exchange chief publicly pressing the protocol to refuse service.

Security and Recovery Pressure Mounts

The Bitget incident has also highlighted the differing recovery tools available across crypto networks. Stablecoin issuers Circle and Tether froze roughly $318,000 in stablecoins held in an attacker-linked wallet, while large amounts of ETH and other assets remained outside issuer-controlled freeze mechanisms. CoinDesk reported that more than 63,000 ETH stayed in exploiter addresses that issuers could not freeze. The split shows how recovery options narrow once stolen funds move beyond assets with issuer-controlled freezes into native assets traversing permissionless rails.

For THORChain, the dispute places decentralization, censorship resistance, and responsibility for illicit fund flows in direct tension. The outcome could influence how exchanges, regulators, and other decentralized networks assess cross-chain infrastructure when stolen assets pass through permissionless systems. Whether the network's governance produces any response to Chen's appeal could prove central to that assessment.