Security firm GoPlus alleges $51.5M in stolen Bitget funds already laundered through THORChain's vaults, raising regulatory scrutiny of the protocol.
Regulation & Gov ·
Security firm GoPlus has alleged that approximately 101.5 BTC (worth roughly $8.5 million) and 27.6 million XRP (worth around $43 million) stolen in a recent Bitget hack have already been routed through THORChain's validator-controlled vaults and converted into other assets. GoPlus disputes THORChain's characterization of itself as decentralized, arguing that the protocol's transaction signing infrastructure—where a threshold set of active validators must jointly approve fund releases via cryptographic signatures—functions as intermediary custody rather than neutral base-layer ordering.
THORChain's active validator set comprises approximately 100 nodes that coordinate through shared communication channels and voting mechanisms (Mimir governance), with the ability to halt outbound signing on specific chains or pause trading entirely. GoPlus contends that validators have both the technical tools and established precedent to intervene: the protocol previously paused operations during its own May 2026 drainage incident, and validators voted to intercept alleged North Korean-linked funds in February 2025. Processing illicit transactions generates substantial fees—the firm notes that hundreds of thousands of dollars could be earned from the Bitget hack alone, alongside prior examples like the Bybit incident in which approximately $5.5 million in fees were generated.
The core question remains whether THORChain's validator set will use its existing halt and interception capabilities to reject the flagged funds, or whether fee incentives and operational inertia will allow the swaps to complete. Regulatory and reputational consequences for exchanges and protocols that route through THORChain are now in focus.