THORChain Faces Scrutiny After the Bitget Hack

THORChain is at the center of a fresh debate after hackers moved part of the funds stolen from Bitget through its network. The dispute is not only about one crypto hack. It is also about a much bigger question: should a decentralized network stop a transaction when it knows that the money may come from a theft?

The issue came to public attention after the Bitget exchange suffered a major security breach on September 24, 2026. Bitget first said that about $351.6 million had left its wallets without permission. The exchange later revised the total to about $387.5 million after it added assets on Zcash and TRON to its estimate. Bitget said the higher figure did not mean that more money was stolen after the first report. It was a broader count of the assets affected.

The attack has now placed THORChain under close attention because some of the stolen assets passed through its cross-chain system before they reached Bitcoin.

What Happened to Bitget

Bitget said the attackers gained access to a backend system linked to its wallet setup. According to the exchange, the attackers changed the transaction information shown to the people or systems that approved transfers. This allowed unauthorized transactions to receive approval.

Bitget said its private keys were not stolen and its cold wallets were not affected. The affected funds came from hot and warm wallets, which are used for regular transactions and withdrawals. Bitget paused withdrawals after it detected the problem. The exchange also said that its User Protection Fund had more than $464 million to cover such losses.

The stolen assets came from several networks. They included Ethereum, XRP, BNB, Avalanche, TRON, Zcash, USDT, USDC and other assets. Early estimates focused on Ethereum and other EVM networks, but later research showed that a large amount of XRP also left Bitget wallets. TRM Labs said about $351.6 million had left the exchange based on its own blockchain analysis.

How the Stolen Funds Moved

The attackers did not keep all the stolen assets in one place. Blockchain researchers saw the money move into new wallets soon after the attack.

On Ethereum, much of the stolen ETH passed through a wallet that also received funds from Arbitrum, Avalanche, Base, BNB Chain and Optimism. Another wallet then sent funds to several new addresses. Many of these wallets held round amounts of about 10,000 ETH.

The XRP funds followed a similar pattern. Money passed through several smaller accounts before it reached wallets that held round amounts of about 20 million XRP. Much of this money had not moved again as of the morning of September 25, according to TRM Labs.

Some of the stolen assets did move toward Bitcoin. ETH and BNB were swapped through THORChain, and part of the stolen value was converted into native Bitcoin. TRON funds also reached the same route after a swap for USDT and a move across networks.

TRM Labs said the funds that passed through THORChain were then split across Bitcoin addresses. The company also noted that the stolen assets had links to wallets used in earlier attacks that researchers associated with North Korean hacking activity. However, TRM said it had not made a final attribution of the Bitget theft itself.

Why THORChain Matters

THORChain is a cross-chain swap protocol. It allows users to exchange assets from different blockchains without the need for wrapped versions of those assets.

This makes the network useful for people who want to move between different crypto ecosystems. It also makes THORChain useful to people who want to move stolen assets from one blockchain to another.

That does not mean THORChain itself stole the funds or took part in the Bitget attack. The dispute is about what the network should do after stolen funds enter its system.

According to reports, about $4 million to $4.5 million of the stolen Bitget funds had passed through THORChain and been converted into Bitcoin at the time of the reports.

The use of Bitcoin is important because Bitcoin transactions cannot be reversed in the same way as some transactions involving centralized stablecoins. Tether and Circle, for example, can freeze certain USDT and USDC funds when they identify an address that meets their internal or legal criteria.

TRM Labs said Circle and Tether froze about 218,023 USDT and 99,990 USDC from an address linked to the attack. The combined value was about $318,000.

Bitget Asks THORChain to Act

Bitget CEO Gracy Chen publicly asked THORChain to block addresses linked to the attackers.

Her argument was simple. If the addresses are already known and publicly identified, she said, a decentralized network should not use decentralization as a reason to continue to process their transactions.

This request created a direct clash between two different ideas about crypto networks. Bitget focused on the fact that the funds came from a known security breach. THORChain focused on its permissionless design.

THORChain rejected the request. Its response compared its model with Bitcoin, Ethereum and BNB Chain and asked what responsibility those networks should have when they process transactions tied to stolen assets.

The answer is not simple because there is a major difference between knowing that funds may be stolen and having a reliable system that can stop only those funds without harming legitimate users.

The Censorship Resistance Debate

Censorship resistance is one of the main ideas behind decentralized crypto networks. It means that a single company, government or other central authority should not have complete power over which transactions can take place.

For supporters of this model, a blacklist creates a serious problem. If a network can block one address today because it is linked to a hack, who decides which address should be blocked tomorrow?

There can also be mistakes. Blockchain addresses can interact with one another through exchanges, bridges, smart contracts and other services. A wallet that receives stolen money may later send part of it to an innocent person or business. A simple blacklist could therefore affect people who had no role in the original crime.

But the other side of the debate is also important. A permissionless system can become useful to criminals if it always processes transactions without regard to their source. In the case of a major theft, victims and exchanges may expect crypto infrastructure to help stop the stolen funds.

This creates a difficult balance between open access and financial crime controls.

A Halt Is Not the Same as a Blacklist

Another important part of the debate is THORChain’s ability to stop parts of its network.

THORChain has emergency controls that can halt certain activities across the network. Its history also shows that the network can take action when there is a serious threat to its own security.

In May 2026, an attacker stole more than $11 million from THORChain across at least nine chains. TRM Labs said the incident affected Bitcoin, Ethereum, BNB Chain, Base, Avalanche, Dogecoin, Litecoin, Bitcoin Cash and XRP. THORChain then took steps to stop further damage.

However, stopping a network is not the same as blocking one specific address.

A full halt is a broad emergency measure. An address blacklist is much more precise. It requires a decision about which addresses should be blocked, what evidence should be accepted and who should have the authority to make that decision.

That difference is now a major part of the THORChain debate.

Why Regulators May Care

The Bitget case also raises questions about future crypto regulation.

Regulators around the world have spent years trying to decide how laws should apply to decentralized networks. A system with no clear central operator is harder to fit into rules that were designed for banks, exchanges and payment companies.

If stolen funds can pass through decentralized protocols and reach Bitcoin, authorities may ask whether those protocols should have stronger controls. They may also ask whether developers, validators or other participants have legal duties when they know that specific funds came from a crime.

There is no simple answer yet. The legal position can vary by country, the design of the protocol and the role played by each participant.

The Bitget case could add more pressure to that discussion because the amount involved is so large.

What This Means for Bitcoin

The incident also shows why Bitcoin remains part of the debate around crypto crime.

Bitcoin itself does not have a central company that can simply reverse a transaction. But Bitcoin transactions are public, which means researchers can follow the movement of funds across addresses.

The attackers can still make tracing harder by splitting funds across many wallets, using cross-chain swaps and moving assets through several services. That can slow investigations without making the transactions completely invisible.

THORChain therefore sits between different parts of the crypto system. It can provide a path between blockchains, while blockchain researchers can still trace the movement of assets after a swap.

That makes the argument less about whether stolen funds can be seen and more about whether a network should have the power to stop them.

The Bigger Question for Crypto

The Bitget incident has turned a large security breach into a much wider debate about the future of decentralized finance.

One view says that permissionless systems must remain open even when criminals use them. Another view says that known stolen funds deserve a different response, especially when the victim has publicly identified the addresses and law enforcement or blockchain researchers can trace the money.

Neither side changes the basic facts of the case. Bitget reported a loss of about $387.5 million. Researchers traced part of the stolen funds across several blockchains. A portion moved through THORChain and into Bitcoin. Bitget asked THORChain to block addresses tied to the exploit. THORChain refused and defended its permissionless model.

The next stage will depend on how the stolen funds move, whether more assets can be frozen or recovered, and what further evidence emerges about the attacker.

For the crypto industry, the larger question will remain: how much control should a decentralized network have when it faces a clear case of stolen money? The Bitget case shows that this question is no longer only theoretical. It now affects real users, large sums of money and the future relationship between decentralized finance and regulators.

ALSO READ: Solana Alpenglow: 150ms Finality Moves Closer

Leave a Reply

Your email address will not be published. Required fields are marked *