THORChain Refuses to Block Stolen Funds Amid Hack-Linked Activity
The recent Bitget hack has reignited a long-standing debate in the crypto community over whether decentralized protocols should block stolen funds. The incident saw an estimated $387.5 million in stolen funds move across chains, with some of that activity heading towards THORChain, a decentralized cross-chain swap platform.
Bitget CEO Gracy Chen publicly urged THORChain to refuse service to attacker-linked addresses, warning that 'the industry is watching.' However, THORChain declined to comply, citing its commitment to permissionless infrastructure. This stance has been met with criticism from those who argue that protocols should be technically capable of stopping known illicit flows.
NEAR Intents, a cross-chain transaction competitor, has taken a contrasting approach through an automated security layer (SHIELD) that identifies and blocks some hack-linked flows. NEAR's team argues that permissionlessness can coexist with automated, targeted controls, while THORChain's developers frame 'known stolen funds' screening as incompatible with true permissionless design.
THORChain developer Boone Wheeler argued that a genuinely permissionless protocol cannot selectively treat funds based on their provenance. He emphasized that enabling it to block specific stolen funds would effectively make it permissioned, citing the protocol's past usage during major exchange-related hacks.