Bitget has resumed Bitcoin withdrawals after a hacker swapped ETH through THORChain, a decentralized protocol that links assets across blockchains. The exchange’s CEO, Gracy Chen, has asked THORChain to deny services to addresses tied to the attack, but the protocol’s design limits what it can do.
The move comes as the hacker continues to shift funds through the platform. Lookonchain reported Monday that the attacker was swapping Ether for Bitcoin via THORChain, with Arkham data showing ETH linked to the attacker flowing into THORChain vaults.
The Swap Through THORChain
The hacker’s method is simple: send ETH into THORChain’s vaults, then trade it for BTC. The platform handles the cross-chain movement automatically. For a hacker moving large sums, that removes the need to expose a wallet directly on the main chain, where activity is easier to trace.
THORChain operates as a decentralized protocol for swapping assets between blockchains. Its role in the Bitget hack is not yet fully understood, but the swap itself shows how quickly assets can move across chains when a protocol is used as a bridge.
Chen’s Request to THORChain
Chen has publicly called on THORChain to refuse services to addresses linked to the attack. The request puts the protocol in an awkward position. Decentralized protocols are built to serve anyone with a valid transaction, and THORChain has no built-in address blacklist.
That means a selective freeze of specific funds or an individual swap would require coordination across multiple nodes, which is not guaranteed to work. THORChain’s response has noted that its network halt is an emergency security mechanism that affects the protocol broadly.
“is not a selective freeze of specific funds or an individual swap.”
Why THORChain Can’t Block Addresses
Crypto author Anndy Lian explained the limitations. THORChain can halt trading, stop outbound transactions or pause a connected chain, but those measures affect users broadly. The protocol has no built-in address blacklist, he said, limiting its ability to block specific addresses.
That matters for Bitget and other exchanges facing similar attacks. If a hacker can route through a decentralized protocol, the exchange has limited recourse.
| Feature | THORChain Capabilities | Limitations |
|---|---|---|
| Address Blacklist | None built-in | Can’t block specific funds |
| Emergency Halt | Halt trading, stop outbound, pause chain | Affects all users |
| Individual Swap Freeze | Not possible | No selective controls |
The Network Halt Is Broad
THORChain’s network halt is an emergency security mechanism that affects the protocol broadly. That means it is not a selective freeze of specific funds or an individual swap. When the protocol stops, it stops for everyone.
That distinction is important. A protocol-wide halt is visible and affects all users. A targeted freeze of a single address is harder to implement and harder to enforce. THORChain’s response has noted that the mechanism exists, but it is broad, not precise.
The Hacker’s Path Continues
The hacker’s swap through THORChain remains active according to the reports. Lookonchain’s report and Arkham’s data show the flow of funds continuing. The exchange has resumed Bitcoin withdrawals, but the hacker’s ETH remains unaddressed by THORChain’s current mechanisms.
For Bitget, the immediate concern is containment. Resuming withdrawals allows users to recover their funds.
What This Means for DeFi
The Bitget hack highlights a tension in decentralized finance: protocols are designed to be open, but openness can be exploited. A decentralized protocol has no built-in address blacklist, and that creates a problem when a bad actor uses the protocol as a tool.
The question raised by this incident is uncomfortable. When a decentralized protocol cannot block a single bad actor’s funds without hurting everyone else, who gets to tell a protocol what to do?
The answer, in this case, is no one. THORChain cannot selectively freeze an address, and the network halt it can trigger is broad, not precise. That leaves exchanges and users with a narrower set of tools.
Bitget has taken the step it could take: resume withdrawals for its users. The hacker’s path remains open through THORChain, and the exchange has asked the protocol to act.
The broader lesson is that decentralized protocols create new failure points. A hacker can now route through a protocol that was not built to police individual addresses, and the protocol itself may lack the tools to stop them. That is a structural weakness, not a bug that can be patched.
Funds move freely, and so do attackers.
See the a run of 20 images at Cointelegraph.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

