THORChain Rejects Bitget's Request to Block Hacker Wallets After $387.5 Million Breach
Key Takeaways
- •THORChain refused Bitget's request to block hacker-linked wallet addresses, saying network halts are emergency security mechanisms that cannot selectively freeze funds and that the protocol does not censor by design.
- •Bitget raised its loss estimate for the Sept. 24 incident to approximately $387.5 million from the initially reported $351.6 million.
- •The attacker, reportedly linked to North Korea's Lazarus Group, used THORChain to convert stolen Ethereum into Bitcoin, and MistTrack noted that nearly $1.2 billion from the Bybit hack was previously traced through the protocol.
- •Bitget resumed Bitcoin withdrawals on Sept. 28 after remediating the wallet-infrastructure vulnerability, reporting no further unauthorized transfers and unaffected user funds.
- •Bitget transferred 2,042.28 BTC, worth about $169 million, from its roughly 5,500 BTC Protection Fund to hot wallets, while CEO Gracy Chen plans to restore the fund to its $300 million baseline within a week.

THORChain has declined a formal request from Bitget to refuse service to wallet addresses tied to the exchange's recent hack, defending its permissionless architecture even as attacker-linked funds continued moving through the cross-chain protocol.
Bitget now estimates that approximately $387.5 million reached attacker-controlled addresses during the Sept. 24 incident, up from the $351.6 million figure the exchange initially reported. Attacker-linked wallets used THORChain for cross-chain swaps as investigators traced the stolen funds across blockchains. Bitget, meanwhile, began restoring Bitcoin withdrawals on Sept. 28 after remediating the wallet-infrastructure vulnerability behind the breach.
Hacker Uses THORChain to Convert Stolen Funds
On-chain data shows the hacker behind the attack is exploiting THORChain to move assets. Data from Arkham Intelligence indicates the hacker address, reportedly tied to the notorious North Korean Lazarus Group, has swept Ethereum (ETH) into Bitcoin (BTC). The address is publicly viewable on Arkham's blockchain explorer.
As previously reported, the hacker stole 34,890 ETH worth $85 million from the exchange — the second-largest crypto asset stolen from Bitget by value, after XRP.
On Friday, Sept. 25, blockchain tracking firm MistTrack reported that the attacker is misusing the THORChain platform to escape with the proceeds via asset swaps and cross-chain transfers. "After the $1.46B Bybit hack last year, nearly $1.2B in stolen funds was reportedly traced through THORChain, as the attackers moved assets across chain," MistTrack noted.
The Bybit comparison underscores that this is not the first time large-scale breach proceeds have been traced through the protocol, a pattern that has made cross-chain swap venues a recurring focal point in post-hack fund tracing. The attacker-linked addresses have been publicly identified and are being actively monitored by exchanges, blockchain security firms, and AML firms. MistTrack argued that THORChain needs to take responsibility and should not become a go-to platform for attackers to swap assets.
Speaking on the matter, Bitget CEO Gracy Chen said: "Our attacker addresses are publicly listed and actively tracked. We are formally asking THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds. The industry is watching."
THORChain Defends Its Refusal to Block Addresses
THORChain said network halts are emergency security mechanisms designed to protect the protocol, and added that they cannot be used as tools to selectively freeze specific funds or block individual swaps.
The protocol cited a May 2026 exploit in which $10.7 million was stolen from its liquidity pools. During that incident, the attackers' addresses were not blacklisted and were therefore not prevented from swapping on the network.
"THORChain is permissionless and doesn't censor by design," it added in a message on the X platform.
The practical upshot is that even publicly labeled attacker wallets remain outside THORChain's blocking mechanisms, leaving tracking by exchanges and analytics firms — rather than on-chain interception — as the response currently in place. Some industry figures have also voiced support for THORChain's stance. Digital nomad Michael Perkins wrote: "All tools in existence are inherently neutral by nature. It is the man who wields the tool that decides whether they will use it for good or for bad, and you cannot blame tools for the actions of men."
Bitget Resumes Bitcoin Withdrawals
According to its scheduled timeline, Bitget resumed withdrawals on its platform starting today, Sept. 28. The said the vulnerability has been remediated and that no further unauthorized transfers have been identified since the incident was contained. User funds, it added, remain unaffected.
CEO Gracy Chen previously said Bitget plans to replenish its Protection Fund to its $300 million baseline within a week — a stated deadline that gives the industry a concrete near-term checkpoint for gauging the exchange's post-hack recovery.
As reported by the X handle "Ai," Bitget has transferred 2,042.28 BTC, worth approximately $169 million, from its roughly 5,500 BTC Protection Fund to hot wallets, while another 3,457.72 BTC remains on-chain. Chen noted that the transfers were made in advance and should not be interpreted as actual user withdrawal activity.
This article is for informational purposes only. Blockchain labels and analytics do not independently establish the identity of wallet controllers.
Source: The Market Periodical