A halt is not a freeze: THORChain defends neutrality in Bitget hack dispute
Key Takeaways
- •Bitget CEO Gracy Chen formally requested on September 26 that THORChain deny service to publicly tracked wallets linked to the roughly $388 million stolen in the September 24 breach, suspected to involve North Korean attackers who exploited a third-party security product to gain internal credentials.
- •THORChain says its emergency halt after its own May 2026 exploit, which cost it about $10.6 million, was a protocol-wide protective action rather than a targeted freeze, and it will not blacklist specific attacker addresses.
- •GoPlus Security argues THORChain has never been strictly decentralized and differs from Bitcoin and Ethereum, while THORChain supporter Michael Perklin counters that threshold signing is automated and halting the network would block legitimate transactions along with criminal ones.
- •Bitget resumed Bitcoin withdrawals on September 28, processing 9,585 requests totaling approximately 4,098 BTC, with Ethereum, USDT, and other services scheduled to return progressively through October 2.
- •Bitget's recovery effort includes support from Mandiant and SlowMist, a bounty paying up to 5% for frozen or recovered funds, a live attacker-wallet dashboard, and a Protection Fund of 5,500 BTC worth roughly $464 million.

THORChain has clarified that the emergency halt it carried out after its own May 2026 exploit, which drained roughly $10.6 million, is not equivalent to the selective intervention Bitget has requested — a move that would prevent attackers from moving part of the $387.5 million stolen from the exchange through the cross-chain protocol.
The clarification is the latest episode in a standoff that has followed the year's largest crypto hack. On September 26, Bitget CEO Gracy Chen went public with a formal request that THORChain refuse service to publicly tracked attacker wallets, as Cryptopolitan reported. The dispute carries an uncomfortable precedent: attackers used the same THORChain route after the Bybit hack, which was, ironically, also the largest security breach of 2025. The protocol keeps appearing in incidents like this because of what it is: a decentralized cross-chain liquidity network that swaps native assets such as Bitcoin and Ethereum directly through pooled liquidity, without wrapped tokens or a custodial intermediary. By construction there is no gatekeeper positioned to screen individual transactions — which is precisely the neutrality now under dispute.
THORChain: a halt is not a freeze
In a statement posted on X, the decentralized exchange argued that important context is being missed in the debate. A network halt, it said, is "an emergency security mechanism designed to protect the protocol" and "is not a selective freeze of specific funds or an individual swap."
THORChain noted that during the May 2026 incident, in which it lost $10.7 million to hackers — an exploit documented by TRM Labs — it initiated a protocol-wide shutdown to contain the damage. Even then, it did not consider blacklisting the attacker's addresses, and it will not do so now. The distinction it is drawing — a blanket emergency switch versus targeted intervention on specific funds — is the same line base-layer networks have long claimed for themselves, and it is exactly the line Bitget's request would ask the protocol to cross.
Security firms challenge the comparison
GoPlus Security pushed back against THORChain's defense comparing itself with base layers like Bitcoin and Ethereum. Posting on September 27, the blockchain security firm said the protocol "has never been strictly decentralized" and urged it not to "enable criminals — or put the industry at risk — just to take swap fees on stolen funds." GoPlus highlighted distinctions between THORChain's threshold signature vaults and the mechanisms underlying Bitcoin and Ethereum.
Longtime crypto security executive and THORChain supporter Michael Perklin countered on X, flagging "AI slop" suspicion in the GoPlus comparison, which he considered "cherry picking at best, a false equivalency at worst."
Perklin argued that threshold signing is an automated process, not a series of human approvals on individual transfers. "In all 3, there is no active choice to sign, only an active choice to turn off the machine," he wrote, comparing a THORChain node operator's options to a Bitcoin miner or Ethereum validator powering down. Shutting the infrastructure to stop criminal transactions, he argued, would stop legitimate ones at the same time.
The clash crystallizes a question the industry has circled for years: whether cross-chain infrastructure should be pressed into selective enforcement against stolen funds, or whether neutrality — even neutrality that benefits hackers — is the cost of keeping decentralization meaningful. THORChain itself advanced a similar case, questioning what responsibility Bitcoin, Ethereum, and BNB Chain should bear when they process transactions touching known stolen assets. For victimized exchanges, the answer shapes how much recovery work has to be downstream, through tracking dashboards, freeze bounties and cooperation from individual services, rather than at the protocol layer.
Bitget pushes ahead with recovery plan
The dispute plays out against an active recovery effort. Bitget suffered the breach on September 24, with the loss later revised upward from $351.6 million to $388 million after transfers on Zcash and TRON were counted. According to a Fortune report, Chen suspects North Korean attackers exploited a backend system to make fraudulent withdrawals look legitimate, without stealing private keys. The exchange's investigation found that the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials. The suspicion places the incident in a familiar lineage: researchers and United Nations investigators have repeatedly tied North Korean-linked groups to record-scale crypto thefts, with proceeds assessed to help bankroll the sanctioned state.
In an update shared on X, Chen stated that Bitget had processed 9,585 BTC withdrawals across the Bitcoin and BSC networks, totaling approximately 4,098 BTC, after BTC withdrawals resumed on September 28. ETH withdrawals are scheduled to resume on September 29, USDT withdrawals on September 30, and other supported tokens, fiat, and P2P services on October 2.
Bitget said cybersecurity firms Mandiant and SlowMist are assisting with the response. The exchange has launched a recovery-bounty program paying up to 5% for funds frozen or recovered, alongside a live dashboard tracking attacker wallets. It also points to its Protection Fund of 5,500 BTC — worth roughly $464 million — though the hack would consume a large share of it. With THORChain refusing to step in, containment now has to run through Bitget's own downstream tools — the public wallet tracker, the freeze-or-recover bounty, and whatever counterparties choose to cooperate — making the coming days a live test of how far victim-side measures can reach when the rails themselves decline to discriminate.