THORChain Refuses to Block Stolen Funds, Sparking Debate Over Permissionlessness
The recent Bitget hack has reignited the debate over whether decentralized protocols should block stolen funds. The hack saw approximately $387.5 million in funds tied to the attack move across chains, with some of that activity reportedly heading towards the decentralized cross-chain swap platform THORChain.
Bitget CEO Gracy Chen publicly urged THORChain to refuse service to attacker-linked addresses, warning that 'the industry is watching.' However, THORChain did not comply, and the decision has become the focus of a broader debate: should permissionless infrastructure be technically capable of stopping known illicit flows or does any ability to filter such activity undermine decentralization?
Critics point to a past May response by THORChain when validators halted trading after an automated system triggered during a vault-draining exploit exceeding $10 million. In contrast, NEAR Intents, a cross-chain transaction competitor, has taken a contrasting approach with an automated security layer (SHIELD) that identifies and blocks some hack-linked flows.
NEAR's team argues permissionlessness can coexist with automated, targeted controls, while THORChain's developers frame 'known stolen funds' screening as incompatible with true permissionless design.