THORChain declines to blacklist addresses tied to Bitget's $387.5M hack
Security & Exploits ·
The protocol says its halt mechanism protects the network as a whole, not individual addresses, rejecting a direct request from Bitget's CEO.
THORChain has turned down a request from Bitget to block attacker-linked addresses following the exchange's September 24 security breach, which involved roughly $387.5 million in stolen assets, according to a report. The request came from Bitget CEO Gracy Chen, who called on the protocol to refuse service to wallets connected to the incident.
THORChain's response centered on how its network halt mechanism functions: it is built to protect the protocol at a systemic level, not to selectively freeze specific addresses or individual swaps. The distinction matters because it draws a line between pausing operations broadly during a threat and targeting particular users or transactions, something the protocol says its architecture is not designed to do.
To reinforce the point, THORChain noted that it did not blacklist attacker addresses during its own exploit in May, which involved about $10.7 million in losses. The protocol framed this as consistent past practice rather than an exception made for Bitget, underscoring its stated commitment to remaining permissionless regardless of the circumstances or the size of the incident involved.
The exchange between Bitget and THORChain has surfaced broader questions about the responsibilities of intermediary services, including mixers, when stolen funds move through decentralized infrastructure after a hack. The cluster around this episode reflects that tension, with coverage noting the episode raises questions about where responsibility sits when a permissionless protocol is used as a conduit following a breach.
What remains unresolved is whether Bitget will pursue other avenues to recover or trace the $387.5 million in stolen assets, and whether THORChain's stance will shift if pressure from exchanges or regulators intensifies. Also unclear is what portion, if any, of the stolen funds has moved through THORChain's infrastructure to date, and whether other protocols facing similar requests will adopt the same permissionless posture or diverge from it.