Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

THORChain May Face Legal Action After Bitget Hack Losses Land in Its Wallet

THORChain refuses to block stolen Bitget funds, citing decentralization. Legal experts debate whether the platform could face prosecution.

By mitch·7 min read
A split illustration showing a blockchain network beside a courtroom gavel, symbolizing the legal battle over decentralized finance.

Bitget lost $10.7 million to a hack of THORChain’s own funds. Now it wants THORChain to stop users from swapping those stolen funds — and THORChain is refusing, saying it is decentralized and has no control over transactions. The exchange is asking the platform to block the addresses tied to the stolen funds. THORChain has replied that it is decentralized and permissionless, just like Bitcoin, Ethereum, and BNB Chain. It also pointed out that the protocol was halted in May when $10.7 million of its own funds were exploited.

“THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain. What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?”

The Case Against Centralization

THORChain’s refusal raises a question that has bedeviled the industry for years: when a platform claims it is decentralized, how far can it go before it stops being decentralized? The company has retired its admin key, meaning it does not have an easy way to censor addresses even if it wanted to. That is the core of its defense: it has no control, so it cannot act.

Advertisement

But the defense cuts both ways. If THORChain can block addresses in some cases — as it did when its own funds were exploited in May — then it shows it has the power to intervene. Showing that power opens the door to claims that the platform is not truly decentralized. As Yuriy Brisov, a lawyer with D&A Partners, told Magazine, the moment a decentralized project shows it can block activity, it loses its strongest legal shield.

“Any amount of control makes any DeFi project weaker vis-à-vis any claimant,” Brisov said. He noted that in the Uniswap case, investors sued after buying 38 rugpull and scam tokens, but a judge dismissed the case in March. Uniswap’s defense was simple: it is decentralized and there is nothing it can do. That is the strongest defense for any DeFi protocol. If a platform shows it can block, control, or interfere, it opens itself to claims that it should have done more.

The Flip Side: NEAR Intents

The irony is that another platform, NEAR Intents, has taken the opposite approach. Its SHIELD program automatically blocks addresses linked to hacks, including the $50 million from the Bitget incident. NEAR Intents even turned down the 5% bounty Bitget was offering for doing so. The result is that Bitget thanked NEAR for blocking the addresses, while NEAR is now under fire from decentralization purists who argue it is not permissionless enough.

The contradiction is stark. Bitget praised NEAR for blocking its stolen funds, but NEAR’s critics argue that blocking addresses means the platform is not truly decentralized. The two positions cannot both be right. Either NEAR is decentralized and should not interfere, or it is centralized and should have blocked the addresses regardless.

Brisov framed the tension clearly. If a platform shows it has control, then it opens itself to claims about pump-and-dump schemes, volatility, or any other harm investors suffer. “Why do you use it in one case and not use it in another case?” he asked. “Why don’t you check all your token issuers on your platform? Why don’t they provide KYC forms like on any centralized exchange?”

The Uniswap Precedent

The Uniswap case is the cautionary tale here. Investors bought 38 rugpull and scam tokens and tried to sue. The judge dismissed the case in March. The dismissal rested on Uniswap’s argument that it is decentralized and cannot be held responsible for the actions of its users. That is the template for THORChain’s defense.

But the Uniswap case also contains the warning. When Uniswap showed it could block, control, or interfere, it opened itself to claims that it should have applied due diligence. The SEC and CFTC generally treat decentralized projects as exempt from liability for the actions of participants in their ecosystems — but only if they are truly decentralized. A platform that shows it can press a button to block an address has stripped itself of that protection.

The Technical Question

THORChain could upgrade its software to block certain addresses if it chose to. Whether it does so could matter legally. Brisov drew a sharp distinction between automatic systems and manual ones. An oracle that detects North Korean IP and blocks it automatically, with no person pressing a button, is fine. But a team that oversees the situation and presses the button manually creates a problem.

“From the legal point of view, even though it’s a good act and it benefits the community, it still makes the project not fully decentralized from the legal perspective,” Brisov said. That would strip THORChain of the protections that MiCA, the EU’s Markets in Crypto Assets laws, and the general understanding of the SEC and CFTC provide.

THORChain has argued that the May halt was triggered by an automated system and that it lacks the ability to block certain addresses. That is a possible defense, but it has not been tested in court. Any amount of control weakens a DeFi project vis-à-vis any claimant, according to Brisov. Even a small amount of control creates a vulnerability.

The Admin Key Question

THORChain retired its admin key in February 2025. That key would have allowed unilateral changes. With a hundred validators and no admin key, the platform argues it is decentralized. Brisov agreed, though he hedged. “More likely than not, but we can’t say that for sure. I would say yes.”

The key retired just 11 days before THORChain was used to swap around $1.2 billion of the funds stolen in the $1.46 billion hack of Bybit. That timing is notable.

Money Laundering Versus Receiving Stolen Goods

THORChain is not a mixer. You can take stolen Bitget funds and swap them through the platform, but when they come out the other end, they remain transparently linked to the Bitget hackers. That raises questions about whether THORChain is facilitating money laundering or simply receiving stolen goods.

Brisov does not see THORChain being liable for money laundering. “I don’t see how they can be liable for money laundering,” he said, noting that even Tornado Cash, which was designed to avoid US sanctions, was treated as a tool that could be used for illegal purposes. THORChain is different because its transactions are transparent.

Receiving stolen goods is a separate issue. If THORChain knew the funds were stolen and processed them anyway, it could face liability. But THORChain argues it has no control, so it cannot be complicit. The distinction matters legally.

What Happens Next

Bitget is not the first exchange to lose money to a hack. It is not the first to ask a DeFi platform to block the addresses of its attackers. But THORChain’s refusal sets a precedent. If it holds, then no DeFi platform can be forced to police its users’ transactions.

The legal landscape is still developing. The Uniswap case shows that decentralized platforms can win in court, but it also shows that showing control weakens the defense. THORChain’s position is that it has no control, so it cannot be forced to act. That is a coherent strategy, but it is also fragile. If THORChain ever upgrades its software to add blocking capabilities, it will have to choose whether to use them — and if it does, it will lose the decentralized shield.

For now, the dispute is unresolved. THORChain has refused to block the addresses, citing decentralization. Bitget has not announced any further action. The legal question — whether THORChain can be prosecuted for failing to block stolen funds — remains open.

The stakes are high. A ruling against THORChain could force other platforms to choose between policing their users and claiming decentralization. A ruling in favor of THORChain would confirm that platforms can refuse to act, even when an exchange asks them to protect its funds.

Here is how the positions stack up:

  1. THORChain refuses to block addresses, citing decentralization.
  2. Bitget asks THORChain to block addresses, citing the stolen funds.
  3. NEAR Intents blocks addresses automatically, and Bitget thanks it.
  4. Decentralization purists criticize NEAR for not being permissionless enough.
  5. The Uniswap case shows decentralized platforms can win in court, but showing control weakens the defense.

The dispute is a test case for the entire industry. If THORChain wins, decentralized platforms will have a stronger argument for refusing to police their users. If it loses, the pressure to centralize will grow. The outcome will determine how platforms handle stolen funds in the future.

For now, THORChain is sticking to its guns. It is decentralized, it says, and it cannot be forced to act. Whether that holds up in court remains to be seen.

Source material: “Could THORChain face prosecution over stolen Bitget funds?,” Cointelegraph.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.