THORChain rejects Bitget request to block hacker as $6 million moves to bitcoin
CoinDesk found 27 successful swaps moving about 2,390 ETH into 75.2 BTC, even as Bitget urged THORChain to stop serving addresses tied to the $387.5 million theft.
A wallet linked to the Bitget hacker converted about $6.3 million in ether ETH$2,683.28 into bitcoin BTC$83,315.33 through THORChain on Monday, as the exchange pressed the cryptocurrency swap network to block addresses holding stolen funds.
CoinDesk’s analysis of THORChain’s public transaction records identified 27 swaps marked successful, exchanging about 2,390 ETH for 75.2 BTC. All the bitcoin payouts went to one address. Four additional swaps involving 400 ETH were marked pending in the response reviewed.
The records cover orders submitted between about 03:55 and 06:23 UTC on Monday from an Ethereum wallet identified by blockchain tracker Lookonchain as part of the attacker’s activity. Most were submitted in roughly 100 ETH batches, worth about $265,000 each.
THORChain lets users exchange assets on different blockchains without opening an account at a centralized exchange. An attacker can send in stolen ether and receive bitcoin in another wallet without passing through an exchange that could block the transfer. The swaps remain publicly visible, however, allowing investigators to follow the funds across networks.
Crypto exchange Bitget lost about $388 million in a Sept. 24 breach after an attacker bypassed security controls protecting its exchange wallets. The company has since said it has identified and fixed the vulnerability, though it has not publicly detailed how the attacker gained access.
The exchange had published attacker addresses and offered a 5% bounty for eligible efforts that freeze or recover stolen funds. As the attacker moved those assets through other services, Bitget CEO Gracy Chen publicly asked THORChain over the weekend to refuse the transactions.
“Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses,” she wrote on X. “Decentralization is a design principle, not a shield for facilitating known stolen funds.”
THORChain’s public response on Monday defended its policy of allowing anyone to use the network and distinguished its emergency shutdown controls from an address blocklist.
“A THORChain network halt is an emergency security mechanism designed to protect the protocol,” the project wrote. “A halt is not a selective freeze of specific funds or an individual swap.”
Its operators do have controls that can interrupt trading, the team said. THORChain’s documentation describes settings that stop swaps across every connected blockchain or restrict activity involving a particular chain, such as Ethereum. Using those controls would also interrupt other users’ transactions on the affected routes.
As such, the network used emergency controls in May after an attacker stole about $10.7 million from one of its own vaults, or the accounts holding assets used for swaps. Operators coordinated a shutdown while developers investigated and repaired the vulnerability. Trading resumed June 22 after roughly five weeks.
THORChain said the May attacker’s addresses were never blacklisted. That intervention protected a compromised protocol, while Bitget is asking it to reject funds stolen from an outside exchange.
Monday’s swap records also show the attacker encountering trading limits. Two 100 ETH orders were only partly filled after portions failed to meet their specified minimum price, returning about 114 ETH to the sending wallet.
As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.
Asanat Analysis — Why it matters
THORChain's rejection of Bitget's blocking request highlights a core tension in permissionless blockchain design: the protocol cannot selectively censor transactions without compromising its foundational architecture. Unlike centralized exchanges that can freeze accounts, THORChain's cross-chain swap mechanism operates through smart contracts that execute automatically when conditions are met. Attempting to blacklist addresses would require protocol-level changes that contradict the system's purpose as a non-custodial liquidity aggregator.
The $6M Bitcoin conversion signals a known money-laundering pattern in DeFi exploits—moving stolen assets through atomic swaps to reduce traceability before reaching final destinations. This echoes previous large hacks (Poly Network, Ronin) where hackers used DEX routing to fragment stolen funds. The incident underscores why institutional players like Bitget still rely on downstream intervention: exchanges can delist suspicious Bitcoin wallets or flag deposits, but can't block swaps at the protocol layer. For THORChain, this positions the protocol as infrastructure-neutral but also exposes it to reputational risk when facilitating stolen asset movement.
This episode tests regulatory appetite for permissionless protocols. If regulators classify THORChain as a transmission mechanism requiring AML controls, it could force redesign trade-offs between censorship-resistance and compliance—a precedent affecting all non-custodial DEXs handling cross-chain flows.