THORChain Refuses to Block Attacker Addresses Amid $387.5M Bitget Hack
The security breach at Bitget has led to a debate about how far a permissionless network should go to help victims of theft. The exchange, which suffered a $387.5 million loss, requested that THORChain block the attacker's addresses. However, the protocol refused, citing its emergency halt mechanism as a way to protect the entire network rather than individual users.
THORChain pointed out that its design is permissionless, meaning no central authority can selectively deny service to a user based on who they are or what they've done. The protocol's neutrality was challenged by GoPlus Security, which argued that THORChain's threshold signature vault system gives node operators the technical means to pause chains and coordinate action.
Michael Perklin, a longtime crypto security executive and vocal THORChain supporter, rejected this framing. He described Bitcoin, Ethereum, and THORChain as neutral public infrastructure, arguing that shutting down that infrastructure to block one bad actor would also freeze legitimate users caught in the same pipeline.