Bitget CEO calls on THORChain to block hacker addresses following $10.7M vault exploit, raising tensions between decentralization principles and stolen-fund recovery.
Security & Exploits ·
A May 2026 vault attack on THORChain resulted in approximately $10.7 million in losses, prompting Bitget CEO Gracy Chen to call for the protocol to block attacker addresses. Chen argued that decentralization should not serve as justification for enabling access to stolen funds. THORChain responded by reaffirming its permissionless network design, emphasizing that no central authority controls address access.
The incident triggered a broader debate about protocol responsibility. Automatic safeguards activated following the attack, and node operators coordinated to halt the network. THORChain co-founder Chad Barraford subsequently outlined potential defenses—including anomaly detection and emergency pause mechanisms—on a podcast, detailing security checks and asset migration procedures that would need to precede resumption of trading activity.
The core tension remains unresolved: the distinction between temporarily halting an entire network versus selectively freezing specific addresses raises an open question about when, if ever, a decentralized protocol should intervene in disputes involving stolen funds originating from external platforms. The incident has intensified scrutiny around how permissionless systems balance security with their foundational operational model.