
The THORChain Bitget hack dispute cuts to DeFi's core: should a permissionless protocol block $387M in stolen funds or refuse to censor swaps? Both sides here.
Author: Kritika Gupta
After attackers stole $387.5 million from Bitget, the exchange faced another problem: stopping the stolen funds from moving. Investigators tracked part of the haul through THORChain, where cross-chain swaps let attackers convert assets into native Bitcoin. Bitget wanted those swaps blocked and THORChain refused, defending permissionless access. The clash exposes a difficult question for DeFi: who should act when stolen funds move through a protocol built to serve anyone?

On September 25, Bitget CEO Gracy Chen publicly demanded that THORChain block the wallet addresses linked to the $387.5 million theft from the exchange. THORChain refused, calling itself permissionless and comparing its role to Bitcoin and Ethereum. “What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?” the team asked. Bitget argued that decentralization should not shield the movement of stolen funds. THORChain argued that blocking addresses would set a censorship precedent. Both have a case. That is the problem.
The dispute reaches beyond one hack. Investigators had identified the wallets and tracked stolen funds into THORChain. As a result, Bitget wanted the protocol to stop converting those assets into Bitcoin. THORChain, however, argued that letting an exchange decide which addresses can swap would compromise permissionless access.
That leaves DeFi with a difficult question. If THORChain blocks these wallets, the next victim can ask every DEX and bridge to do the same. If it continues to process their swaps, attackers retain a public route from flagged assets into native Bitcoin.
Bitget hack and THORChain response
Bitget CEO Gracy Chen asked THORChain to refuse swaps from the attacker addresses, which the exchange had published and investigators were already tracking. “Decentralization is a design principle, not a shield for facilitating known stolen funds,” she wrote. In her view, THORChain could see where the funds came from and should act before the attackers converted more of them into Bitcoin.
“The entire industry is watching,” Chen added. Her argument goes beyond Bitget’s loss: if a protocol continues to process swaps from publicly identified theft wallets, victims and regulators may question where permissionless access ends and responsibility begins.
THORChain expressed sympathy for Bitget but rejected its request to block the attacker addresses. Instead, its team compared the protocol with major blockchains: “What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?” THORChain argues that it, too, must process valid transactions without deciding which users deserve access.
The team also points to a practical limit. THORChain retired its admin key in February 2025, so no administrator can simply add Bitget’s addresses to a blacklist. Node operators must approve parameter changes through a quorum. Therefore, creating and maintaining a blacklist would require them to make ongoing decisions about which wallets to exclude. THORChain argues that this would restore the central control it deliberately removed.
Bitget follows two major thefts in which attackers used THORChain to convert stolen assets into native Bitcoin.
Previous hacks with funds routed through THORChain
The response looked different when THORChain faced losses of its own. In May 2026, an attacker drained about $10.7 million from one of its vaults, and nodes halted trading within hours. Earlier, during THORFi’s January 2025 solvency crisis, an administrator briefly paused lending and savers. Nodes then voted to freeze redemptions overnight.
That contrast drives the criticism: “Decentralized and permissionless seems to apply only when it’s other people’s money.” THORChain’s defenders, however, distinguish between protecting the protocol from a vault drain or insolvency and blocking a third party’s flagged funds. Even so, those earlier interventions show that participants can coordinate and stop activity. The dispute centers on when they choose to act.
The arguments over THORChain’s response to Bitget
First, critics see selective decentralization. THORChain participants halted trading within hours when an attacker drained one of their vaults, and they froze THORFi redemptions during a solvency crisis. They have not taken comparable action over Bitget’s flagged wallets. Critics argue that the network can coordinate when it chooses to.
Second, investigators have linked roughly $2 billion in stolen funds to THORChain routes over about 18 months, depending on which partial flows they count. The protocol does more than record transfers: it swaps assets across chains and pays out native Bitcoin. That conversion can help attackers move proceeds beyond the reach of stablecoin issuers, while swap fees give the network an economic reason to keep processing volume.
Finally, repeated, publicly documented flows could draw a regulatory response. Critics argue that after Bybit, KelpDAO, and Bitget, THORChain cannot treat each flagged swap as an isolated transaction. They do not need to claim that node operators planned the thefts to question their responsibility. Their case is that continuing to process known theft proceeds at this scale has consequences, even if the protocol calls the decision neutrality.
If THORChain blocks Bitget’s attacker addresses, other hack victims will likely ask DEXs and bridges to do the same. Operators would then need to decide what evidence justifies a block and who maintains the address list. Over time, those decisions could narrow the access that permissionless protocols promise. If THORChain refuses, critics will instead see it as a reliable route for converting stolen assets, even as legitimate users continue to swap through it.
The Tornado Cash case shows why the dispute could extend beyond node votes. U.S. prosecutors charged its founders over their alleged operation of a crypto mixer, and a jury later convicted one founder on a money transmission charge. The case does not establish that THORChain’s developers face the same liability. The services and facts differ. Still, it shows that authorities may examine what people operate and control, not only what the code allows. Meanwhile, FATF’s Travel Rule addresses virtual asset service providers, and EU crypto rules govern covered services. Neither automatically requires THORChain nodes to block Bitget’s list.
A front end offers another possible response. A THORChain website could refuse to prepare swaps for flagged wallets while nodes continue to process valid transactions that users submit directly. This would restrict access through that website without adding a protocol-wide blacklist. However, determined attackers could use another interface, so the measure would limit their options rather than stop them.
Ultimately, this reaches beyond Bitget’s $387.5 million loss. When people operating decentralized infrastructure can identify stolen funds moving through it, what obligations, if any, do they have to act?