Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

THORChain Blocks Bitget’s Request to Halt a Hacker While $6 Million Exits Move Into Bitcoin

THORChain rejects Bitget's request to block a hacker's wallet, as $6 million in ether moves to bitcoin through its network.

By mitch·4 min read
A digital illustration showing stolen cryptocurrency funds moving through a blockchain exchange network.

On Monday, a wallet connected to the Bitget hacker traded around 2,390 ether, worth roughly $6.3 million, into 75.2 bitcoin via THORChain. This happened even though Bitget’s chief executive, Gracy Chen, had requested over the weekend that THORChain deny service to the hacker’s addresses.

Swap Records

Between about 03:55 and 06:23 UTC on Monday, CoinDesk found 27 successful swaps that moved roughly 2,390 ETH into 75.2 BTC, along with four additional swaps involving 400 ETH that were marked pending. Orders came from an Ethereum wallet identified by Lookonchain as part of the attacker’s activity, and all bitcoin payouts went to a single address. Most orders were submitted in roughly 100 ETH batches, worth about $265,000 each.

Chen’s Message

Chen made her request public on X. “Our attacker addresses are publicly listed and actively tracked,” she wrote. “We are formally asking @THORChain to refuse service to these addresses.” She added that decentralization is a design principle, not a shield for facilitating known stolen funds.

Advertisement

The exchange Bitget suffered a Sept. 24 breach that resulted in losses estimated at about $388 million. In response to the incident, the platform has put up a reward of 5 percent for anyone who can freeze or recover the funds that were taken.

THORChain’s Position

THORChain rejected selective blacklisting. “A THORChain network halt is an emergency security mechanism designed to protect the protocol,” the project wrote. “A halt is not a selective freeze of specific funds or an individual swap.”

Emergency controls on the project can stop wider network operations, but they lack the power to lock down a single address or a single transaction.

The May Shutdown

Trading on THORChain was stopped in May following a theft of around $10.7 million from one of its vaults by an attacker. It came back online June 22, some five weeks later. The addresses linked to that attacker were never placed on a blacklist.

Partial Orders

Two 100 ETH orders were only partly filled, returning about 114 ETH to the sending wallet.

What This Means

The position THORChain has taken matches what it has done before. When it stopped trading in May, the entire network was shut down, not just individual wallets. Its tools are designed to stop attacks across the whole network, not to police specific wallets.

The attacker’s addresses are listed openly. Stopping those addresses from being moved would halt the movement of funds taken without permission. Doing so would not affect anyone else’s ability to use the network, since it targets only those specific addresses.

The protocol’s refusal to act on specific thief addresses can be understood as well. The emergency controls were created to safeguard the system as a whole, not to target individual accounts that have been identified as belonging to thieves.

The Numbers

Event Date/Time
Bitget hack announced Sept. 24
THORChain May halt May
Trading resumed June 22
Swap activity Monday, 03:55–06:23 UTC

Monday’s move of $6.3 million in ether to bitcoin came from a choice made by someone. That person chose to swap their funds through THORChain’s network, and THORChain declined to block the transfer selectively.

Bitget’s bounty program for freezing or recovering the stolen funds remains active. The hacker’s addresses are known and available to see. Meanwhile, THORChain has made it plain that its emergency controls are not built for that purpose.

Where the paper stands

The paper backs disclosure requirements for hidden safety failures like this one and is against any regime that would freeze today’s leaders in place and lock out whoever would challenge them. THORChain’s refusal to selectively blacklist the hacker’s addresses is consistent with its past behavior: when it halted trading in May after a $10.7 million theft, it did so entirely, not by blocking individual wallets. The paper’s concern is the same as the protocol’s stated one — that targeted controls exist to protect the whole system, not specific accounts.

Readers should keep an eye on whether THORChain’s position changes in the future. The paper’s concern is not THORChain’s stance here but any broader rule that would make selective blacklisting impossible for any network, freezing today’s leaders in place and locking out whoever might challenge them.

Source material: “THORChain rejects Bitget request to block hacker as $6 million moves to bitcoin,” CoinDesk.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.