THORChain refuses Bitget’s plea to block stolen funds
THORChain is at the centre of a fresh controversy over its role in the movement of funds stolen from crypto exchange Bitget, after the platform revised its loss estimate upwards to approximately $387.5 million and investigators traced a substantial portion of the attacker’s transfers through the cross-chain protocol.
Bitget first reported the breach on September 24, 2026, putting initial losses at about $351.6 million. That figure was later raised after the exchange traced additional attacker-controlled transfers, bringing the confirmed loss to roughly $387.5 million. It is one of the largest exchange breaches on record, and the follow-on dispute over where the money went has quickly become as significant as the theft itself.
Bitget chief executive Gracy Chen publicly called on THORChain to refuse service to wallets linked to the attackers. Her argument, as paraphrased in coverage of the dispute, is that decentralisation should not be used to facilitate known stolen funds. THORChain declined the request. The protocol maintains that it is permissionless by design and should not be expected to censor transactions in the way a centrally operated platform might.
The standoff is the sharpest public clash yet in a debate that has followed the decentralised finance sector for years: whether infrastructure that anyone can use, without gatekeepers, can also be infrastructure that criminals cannot exploit. For more background on how these incidents ripple through markets, see our DeFi coverage.
What the tracing shows
The attackers did not simply sit on their haul. Investigators tracked movement of the stolen assets across multiple rails, with THORChain among the most prominent. One tracing update put the amount confirmed as having passed through THORChain-linked routes at approximately $157 million, a figure that represents a meaningful share of the revised total loss.
The flow did not stop at a single chain. The stolen funds were spread across a range of assets, including AVAX, BNB, ETH, TRX, USDT, USDC, XRP and ZEC, according to one report on the breach. That asset spread is itself telling. Moving quickly between heterogeneous chains and token standards complicates conventional blockchain analytics, which tend to work best when funds stay within a single network’s address space.
From those cross-chain hops, investigators followed part of the flow into Bitcoin and from there into privacy tools such as Wasabi, the coin-mixing service that applies zero-knowledge techniques to obscure the link between inputs and outputs. The combination of a cross-chain protocol, a hop into Bitcoin and then a privacy tool amounts to a laundering pipeline that is difficult, though not impossible, to unwind.
The pattern is familiar to anyone who followed the aftermath of the Bybit hack. In that earlier incident THORChain was likewise accused of facilitating the movement of stolen funds, and the protocol weathered similar criticism while declining to change its posture. What is different this time is the scale of the loss and the seniority of the executive making the public demand. Chen’s intervention has moved the argument from specialist forums into mainstream industry discussion.
For readers tracking the destination asset, our Bitcoin coverage follows how large illicit flows into BTC have historically influenced regulatory scrutiny of on-chain privacy tools.
Censorship resistance versus credible neutrality
At the heart of the dispute is a question that the industry has never fully resolved. Critics of THORChain’s position argue that the protocol is not as helpless as it claims. THORChain, they contend, could implement blacklist screening at the level of its liquidity pools or routing logic, refusing swaps where the source address is publicly identified as attacker-controlled. The addresses in this case are known. The exchanges and investigators have published them. The technical path to refusing service exists.
Supporters of the protocol’s stance counter that any such intervention would strike at the foundation of what THORChain is. A permissionless cross-chain swap protocol derives its value from the fact that no operator can decide whose transaction is worthy. Introduce one blacklist, the argument runs, and you have established the principle that a protocol team can and should intervene, which invites pressure on every future dispute, including pressure from governments and litigants with far less sympathetic motives than a hacked exchange.
The tension is sometimes framed as the difference between neutrality and indifference. A rail network does not ask why you are travelling, but it also does not advertise itself as the best way to move stolen goods. Decentralised protocols sit somewhere in between, and the industry has not settled on where the line sits.
There are real consequences to both choices. If THORChain were to block the attacker wallets, it would likely earn goodwill from regulated exchanges and could shorten the laundering trail. It would also hand regulators a precedent: that decentralised teams can censor when sufficiently pressured, and therefore perhaps should be treated as responsible for what flows through their systems. That precedent could reshape how DeFi protocols are classified across jurisdictions.
If it does not, as it has chosen, the protocol preserves its design principles but invites exactly the scrutiny it is now receiving. Each large hack that routes through THORChain strengthens the argument, advanced by some policymakers, that decentralised infrastructure is structurally hostile to law enforcement. That argument, once it hardens into legislation, is far harder to reverse than a single blacklist.
Market and regulatory implications
The immediate market question is what this means for THORChain’s native token and for the protocol’s liquidity. Cross-chain protocols depend on deep liquidity from independent providers. Operators who fear regulatory exposure from processing stolen funds may quietly withdraw, and history suggests that outflows following laundering controversies can be persistent even when public total value locked figures appear stable. The reputational cost of being the favoured rail for two major exchange hacks in succession is not trivial.
For Bitget, the revised loss figure of approximately $387.5 million raises questions about the exchange’s reserves and its handling of the initial disclosure. A near ten per cent upward revision between the first announcement and later tracing suggests the full picture took days to establish, which is common in large breaches but rarely reassures depositors. Chen’s aggressive public posture toward THORChain serves partly to redirect attention to the laundering route rather than the breach itself.
The regulatory readout is the most consequential layer. The Bybit precedent already put THORChain on watchlists. A second, larger incident with a named executive demanding censorship gives regulators in the United States, European Union and Asia a concrete case study for the argument that decentralisation is being used as a liability shield. Expect renewed pressure for compliance obligations at the smart-contract or router level, and expect protocol teams to resist on exactly the grounds THORChain has articulated.
The deeper trend worth watching is behavioural. Attackers have learned that the most reliable laundering route is not a single mixer but a chain of legitimate-looking infrastructure: a cross-chain swap, a hop into Bitcoin, then privacy tooling. Each component is defensible in isolation. Together they form a pipeline. That is the uncomfortable truth this incident exposes, and it will not be resolved by any single protocol’s policy choice.
The closing analysis
The THORChain standoff is best understood not as a dispute about one hack but as the industry’s recurring stress test. Bitget lost roughly $387.5 million and about $157 million of traced funds moved through THORChain-linked routes. Chen wants the protocol to act. THORChain says permissionless means permissionless. Both positions are internally coherent, and that is precisely the problem.
The likely trajectory is uneven. Some protocols will adopt voluntary screening at the interface level, where legal exposure is clearest, while deeper infrastructure resists. Regulators will treat each refusal as evidence for stricter rules, and each compliance move as proof that resistance was always possible. In the meantime, attackers will keep routing stolen funds through whatever remains credibly neutral. The market’s verdict may arrive faster than the regulatory one, in the form of liquidity and token confidence, and THORChain will be the case everyone cites when the argument returns, as it surely will.”
}