THORChain's refusal to block wallet addresses linked to the $387.5 million Bitget hack has reignited a structural debate over the obligations of permissionless cross-chain protocols when stolen funds transit their liquidity pools. The dispute, which escalated between September 25 and September 28...
"Decentralization is a design principle, not a shield for facilitating known stolen funds. The industry is watching." — Gracy Chen, CEO, Bitget
THORChain's refusal to block wallet addresses linked to the $387.5 million Bitget hack has reignited a structural debate over the obligations of permissionless cross-chain protocols when stolen funds transit their liquidity pools. The dispute, which escalated between September 25 and September 28, 2026, pits Bitget CEO Gracy Chen and OKX founder Star Xu against THORChain's node operators, who argue that selective censorship would compromise the protocol's neutrality.
The controversy is not new. THORChain faced nearly identical criticism in February 2025 when the Lazarus Group routed an estimated $900 million in stolen Bybit funds through the protocol. A node operator vote to block the attacker's addresses failed, and a core developer subsequently departed the project. The Bitget incident has reopened the same fault line — with one critical difference: THORChain's own May 2026 treasury exploit, in which node operators halted the entire network within hours, has handed critics a concrete example of selective intervention.
The economic data tells its own story. THORChain's daily swap volume surged to approximately $1.72 billion on September 26, with fees reaching $2.2 million — compared to $660,000 for the entirety of August 2026. Whether that volume spike was driven primarily by illicit flows or by organic traders riding the volatility remains contested.
On September 24, 2026, attackers compromised Bitget's backend wallet infrastructure, forging transaction data that passed through the exchange's own approval workflow. The exploit drained hot and warm wallets across eight blockchains.
According to on-chain analytics firm Bitquery and tracker Lookonchain, the breakdown of stolen assets included:
| Asset | Amount | Approx. Value | |-------|--------|---------------| | XRP | 102.93M | $157.5M | | ETH | 31,890 | $85.8M | | USDT | 34.75M | $34.8M | | USDC | 21.05M | $21.1M | | USD₮0 | 19.67M | $19.7M | | XAUt | 3,000 | $12.8M | | BNB | 12,719 | $9.9M | | AVAX | 821,012 | $8.4M | | TRX | 20.59M | $7.1M |
Bitget initially reported $351.6 million in losses. The figure was revised upward to $387.5 million on September 26 after additional stolen assets were identified on Zcash and TRON. IP patterns and on-chain behavioral analysis point to North Korean state-linked operators, according to TRM Labs, though formal attribution remains pending.
Circle and Tether froze approximately $318,000 in stablecoin balances across attacker-controlled wallets as of September 26. Bitget announced a 5% bounty on frozen assets and an additional 5% on recovered funds, with withdrawals scheduled to resume gradually from September 28.
THORChain operates as a decentralized cross-chain liquidity protocol that enables native asset swaps between blockchains without wrapped tokens or centralized intermediaries. Its architecture relies on a set of active validators who collectively manage vault assets through threshold signature schemes (TSS).
Within hours of the Bitget breach, on-chain observers identified stolen funds being swapped through THORChain's liquidity pools, primarily converting altcoins into Bitcoin. By the time Bitget flagged the activity, approximately $4 million had already been processed through the protocol, according to initial reports.
The volume impact was substantial. THORChain recorded approximately $211 million in trading volume on September 25, rising to $1.72 billion on September 26 — a figure that dwarfs its $610 million total for all of August 2026. Fees collected on September 26 alone reached $2.2 million, more than triple the protocol's entire August fee revenue of $660,000. By September 27, 24-hour DEX volume remained elevated at $508.4 million, a 134.4% increase over the prior period.
On September 26, Bitget CEO Gracy Chen publicly called on THORChain to deny service to wallet addresses linked to the attacker. The protocol declined.
THORChain's position, communicated through its official channels, was that its architecture is "permissionless and open to anyone, in the same way as Bitcoin, Ethereum, and BNB Chain." The protocol's operators drew a distinction between a network-wide halt — a blunt instrument that pauses all activity — and selective address blocking, which they argued would require introducing a censorship mechanism that does not currently exist in the protocol's design.
The protocol posed a counter-question: if THORChain should block specific addresses, what obligation do Bitcoin, Ethereum, and BNB Chain bear when known stolen funds pass through them?
OKX founder Star Xu and blockchain security firm SlowMist challenged THORChain's framing directly. Their argument centered on a specific historical event: THORChain's May 2026 treasury exploit.
On May 15, 2026, approximately $10.7 million was drained from a single THORChain vault. Node operators coordinated through Discord and initiated manual pauses, bringing the entire network to a halt within approximately two hours. The network remained offline for roughly five weeks before trading resumed on June 23.
Star Xu's critique was pointed: a network that can stop when its own funds are at risk, but refuses to stop when others' funds are at risk, does not behave equivalently to Bitcoin. The distinction matters because Bitcoin's miners cannot collectively halt the network — they lack the mechanism. THORChain's validators, through TSS-managed vaults and the Mimir governance system, demonstrably can.
THORChain's supporters countered that the May halt was a full network pause triggered by a protocol-level vulnerability, not a selective freeze targeting specific users. Michael Perklin, a crypto security executive who backed THORChain's position, argued that in both the May halt and normal operations, validators make "no active choice to sign, only an active choice to turn off the machine."
Web3 security firm GoPlus published research on September 27 that went beyond the ethical debate and challenged THORChain's architectural claims directly.
GoPlus's analysis focused on THORChain's TSS vault structure, in which active validators share control over outbound transfers. The firm argued this represents a meaningful structural difference from Bitcoin or Ethereum, where users hold their own private keys and no validator committee can collectively freeze or halt fund movements.
According to GoPlus, approximately 101.5 BTC linked to the Bitget incident had already exited through the protocol, while 27.63 million XRP was being routed toward Bitcoin conversion. The firm's conclusion: THORChain's validators have a degree of collective agency over fund movements that permissionless layer-1 networks do not, making the comparison to Bitcoin structurally inaccurate.
The Bitget dispute is the second time in 19 months that THORChain has faced pressure to block state-linked attackers.
In February 2025, North Korea's Lazarus Group used THORChain to launder proceeds from the $1.5 billion Bybit hack. Taylor Monahan, lead security researcher at MetaMask, estimated that approximately $900 million moved through the protocol, generating roughly $2.91 billion in trading volume and about $3 million in fee income for THORChain. Three validators voted to halt Ethereum trading; the action was reversed within minutes. A formal proposal to block Bybit-linked transactions failed to win node operator support. Core contributor "Pluto" subsequently announced his departure from the project.
THORChain founder John-Paul Thorbjornsen supported the decision to continue trading, though he stated he would support individual nodes using static deny lists based on official OFAC or FBI designations — a position that stops short of protocol-level censorship but acknowledges the regulatory reality.
The legal landscape shifted in this period. The Fifth Circuit Court of Appeals ruled in November 2024 that OFAC exceeded its authority by sanctioning Tornado Cash, holding that autonomous, immutable smart contracts do not constitute "property" under federal law. OFAC formally lifted Tornado Cash sanctions in March 2025. That ruling reduced the immediate legal risk of processing illicit flows through decentralized infrastructure, though a parallel challenge in the Eleventh Circuit reached the opposite conclusion, creating a potential circuit split that may eventually reach the Supreme Court.
The THORChain controversy exposes an economic tension at the core of permissionless cross-chain infrastructure. Protocols that process illicit flows generate fee revenue from those transactions. THORChain's fee structure directs income to liquidity providers, node operators, and — through a 5% burn mechanism — to RUNE token holders.
RUNE traded at approximately $0.69 on September 26, with a market capitalization of $227.7 million and a circulating supply of 328.7 million tokens. The protocol's maximum supply is 354.2 million RUNE.
The fee revenue spike from illicit-adjacent volume creates a structural incentive problem: node operators who vote to block transactions reduce their own income. This does not mean operators are motivated by profit in their refusal — the principled arguments about permissionlessness are legitimate engineering positions — but the incentive alignment makes the debate harder to resolve through governance alone.
From an economic value perspective, the question is whether the reputational and regulatory cost of processing stolen funds exceeds the fee revenue generated. The $2.2 million in fees collected on September 26 is material for a protocol with $660,000 in monthly revenue. But the long-term cost of being identified as preferred infrastructure for state-sponsored theft may prove higher, particularly as jurisdictions including the UK (with FCA crypto authorization beginning September 30) and the EU (with MiCA fully operational) develop enforcement capacity.
The recovery arithmetic is stark. Circle and Tether froze $318,000 — less than 0.1% of the total stolen. Once funds exit centralized stablecoin rails and enter permissionless swap infrastructure, the recovery rate drops toward zero. Bitget's 5% bounty program attempts to create counter-incentives, but the gap between what centralized issuers can freeze and what decentralized protocols will process represents a structural feature of the current architecture, not a bug that can be patched.
THORChain refused to block addresses linked to the $387.5 million Bitget hack, citing its permissionless design. The protocol's daily volume surged to $1.72 billion on September 26, with $2.2 million in fees — more than triple its entire August fee revenue.
OKX founder Star Xu and security firm SlowMist accused THORChain of a double standard, noting the protocol halted its entire network for five weeks in May 2026 when its own treasury was exploited for $10.7 million.
GoPlus Security challenged THORChain's comparison to Bitcoin, arguing that its TSS vault structure gives validators collective control over outbound transfers — a capability Bitcoin miners do not possess.
This is the second major incident in 19 months. THORChain processed an estimated $900 million in Bybit hack proceeds in February 2025. A core developer departed the project after a proposal to block those transactions failed.
Stablecoin issuers froze $318,000 of the $387.5 million stolen — less than 0.1% — illustrating the sharp decline in recovery options once funds move from centralized to permissionless infrastructure.
The THORChain-Bitget dispute is not a debate about whether decentralization is desirable. It is a dispute about whether THORChain qualifies as decentralized in the same sense as Bitcoin — and whether that distinction carries obligations.
The protocol's own history provides the data that undermines its defense. A network that can halt for five weeks when its treasury is drained, but declines to intervene when a third party loses $387.5 million, occupies an architectural middle ground between fully permissionless infrastructure and platforms with administrative control. GoPlus's TSS analysis adds technical specificity to what was previously a rhetorical argument.
The economic incentive structure — in which blocking illicit flows reduces protocol revenue — complicates governance-based resolution. And the legal landscape remains unsettled: the Tornado Cash circuit split means no definitive precedent exists on whether decentralized protocols can be compelled to block specific transactions.
What is clear is that THORChain has become a repeat destination for state-linked theft proceeds. Whether that status triggers regulatory action, institutional avoidance, or structural protocol changes will likely be determined in the next 12 months, as both U.S. and European enforcement frameworks mature.