Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

Hacker sells stolen ETH through THORChain as Bitget restarts Bitcoin withdrawal support

Bitget resumes Bitcoin withdrawals after a hacker swaps ETH via THORChain, which lacks tools to block specific addresses.

By mitch·4 min read
A hacker silhouette sits at a glowing computer terminal surrounded by digital currency symbols.

Bitget has resumed Bitcoin withdrawals after a hacker swapped ETH through THORChain, a decentralized protocol that links assets across blockchains. The exchange’s CEO, Gracy Chen, has asked THORChain to deny services to addresses tied to the attack, but the protocol’s design limits what it can do.

The move comes as the hacker continues to shift funds through the platform. Lookonchain reported Monday that the attacker was swapping Ether for Bitcoin via THORChain, with Arkham data showing ETH linked to the attacker flowing into THORChain vaults.

The Swap Through THORChain

The hacker’s method is simple: send ETH into THORChain’s vaults, then trade it for BTC. The platform handles the cross-chain movement automatically. For a hacker moving large sums, that removes the need to expose a wallet directly on the main chain, where activity is easier to trace.

Advertisement

THORChain operates as a decentralized protocol for swapping assets between blockchains. Its role in the Bitget hack is not yet fully understood, but the swap itself shows how quickly assets can move across chains when a protocol is used as a bridge.

Chen’s Request to THORChain

Chen has publicly called on THORChain to refuse services to addresses linked to the attack. The request puts the protocol in an awkward position. Decentralized protocols are built to serve anyone with a valid transaction, and THORChain has no built-in address blacklist.

That means a selective freeze of specific funds or an individual swap would require coordination across multiple nodes, which is not guaranteed to work. THORChain’s response has noted that its network halt is an emergency security mechanism that affects the protocol broadly.

“is not a selective freeze of specific funds or an individual swap.”

Why THORChain Can’t Block Addresses

Crypto author Anndy Lian explained the limitations. THORChain can halt trading, stop outbound transactions or pause a connected chain, but those measures affect users broadly. The protocol has no built-in address blacklist, he said, limiting its ability to block specific addresses.

That matters for Bitget and other exchanges facing similar attacks. If a hacker can route through a decentralized protocol, the exchange has limited recourse.

Feature THORChain Capabilities Limitations
Address Blacklist None built-in Can’t block specific funds
Emergency Halt Halt trading, stop outbound, pause chain Affects all users
Individual Swap Freeze Not possible No selective controls

The Network Halt Is Broad

THORChain’s network halt is an emergency security mechanism that affects the protocol broadly. That means it is not a selective freeze of specific funds or an individual swap. When the protocol stops, it stops for everyone.

That distinction is important. A protocol-wide halt is visible and affects all users. A targeted freeze of a single address is harder to implement and harder to enforce. THORChain’s response has noted that the mechanism exists, but it is broad, not precise.

The Hacker’s Path Continues

The hacker’s swap through THORChain remains active according to the reports. Lookonchain’s report and Arkham’s data show the flow of funds continuing. The exchange has resumed Bitcoin withdrawals, but the hacker’s ETH remains unaddressed by THORChain’s current mechanisms.

For Bitget, the immediate concern is containment. Resuming withdrawals allows users to recover their funds.

What This Means for DeFi

The Bitget hack highlights a tension in decentralized finance: protocols are designed to be open, but openness can be exploited. A decentralized protocol has no built-in address blacklist, and that creates a problem when a bad actor uses the protocol as a tool.

The question raised by this incident is uncomfortable. When a decentralized protocol cannot block a single bad actor’s funds without hurting everyone else, who gets to tell a protocol what to do?

The answer, in this case, is no one. THORChain cannot selectively freeze an address, and the network halt it can trigger is broad, not precise. That leaves exchanges and users with a narrower set of tools.

Bitget has taken the step it could take: resume withdrawals for its users. The hacker’s path remains open through THORChain, and the exchange has asked the protocol to act.

The broader lesson is that decentralized protocols create new failure points. A hacker can now route through a protocol that was not built to police individual addresses, and the protocol itself may lack the tools to stop them. That is a structural weakness, not a bug that can be patched.

Funds move freely, and so do attackers.

See the a run of 20 images at Cointelegraph.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.