THORChain Refuses Bitget's Request to Block Hacker Addresses
Bitget's CEO Gracy Chen recently asked THORChain to block addresses linked to hackers who breached their platform in September. However, THORChain rejected this request, citing its permissionless design that does not allow it to censor transactions.
The hack on Bitget occurred on 24 September 2026 and resulted in the theft of $387.5 million. The hackers first swapped stolen USDT and USDC into ETH and BNB to avoid freezes by issuers such as Tether and Circle. They then moved millions of dollars in ETH and BNB through THORChain, a cross-chain protocol that allows direct swaps between different blockchains without using wrapped tokens.
This allowed hackers to convert part of the stolen funds into native Bitcoin (BTC). The newly converted BTC was then spread across thousands of private wallets, making it harder to track and recover. Until now, hackers have moved about $4 million, $4.5 million of the stolen funds through THORChain and converted it into Bitcoin.
THORChain's decision not to block the attacker addresses has drawn criticism from crypto security experts. SlowMist founder Cosine pointed out that THORChain used a 'red button' to pause the network during an exploit in the past, but this time is continuing to process stolen funds and collect fees from these transactions.