Bitget’s $387.5 million hack puts THORChain at the center of a censorship dispute

Bitget’s $387.5 million hack puts THORChain at the center of a censorship dispute

N
News Editor
2026-09-28 10:27:31
Bitget’s latest security breach has turned into a wider industry argument over what decentralized protocols should do when stolen funds pass through their systems. The exchange said it detected abnormal transfers from some hot and warm wallets at 2:31 a.m. Beijing time on Sept. 25, later raising its estimated loss from about $351.6 million to roughly $387.5 million after identifying previously uncounted Zcash and TRON assets. Around 103 million XRP, worth about $157 million at the time, made up the largest portion of the stolen assets. Part of the funds was later traced through THORChain, where some BNB was swapped into Bitcoin. Bitget CEO Gracy publicly called on THORChain to block transactions tied to flagged attacker addresses, arguing that decentralization should not be used to facilitate the movement of known stolen funds. THORChain declined, saying it is a permissionless decentralized network, much like Bitcoin, Ethereum and BNB Chain. The dispute intensified because THORChain itself paused operations after a May 15 vault exploit that led to the theft of about $10.7 million. Critics, including OKX founder Xu Mingxing and security firm GoPlus, say that history makes it harder to argue the protocol has no ability to intervene. At the same time, the case has exposed unresolved questions around who decides which addresses are malicious, how lists are maintained, and how legitimate users can be protected from false positives.

A major theft at Bitget has opened a broader argument across the crypto industry: if stolen funds move through a decentralized protocol, should that protocol step in and stop the transactions?

Bitget is the exchange that lost the funds, but part of the stolen assets was later routed through THORChain and swapped into Bitcoin, putting the cross-chain protocol under heavy scrutiny. Bitget asked for flagged attacker addresses to be blocked. THORChain refused. The clash gained even more attention because THORChain paused its own network months earlier when it suffered a theft.

How the Bitget theft unfolded

Bitget said its security system detected abnormal transfers involving some hot and warm wallets at 2:31 a.m. Beijing time on Sept. 25, after which the exchange suspended withdrawals. The platform first estimated the loss at about $351.6 million, then revised that figure to roughly $387.5 million after tracing more transactions.

According to Bitget, the increase reflected Zcash and TRON assets that had not been counted in the initial estimate, not a second attack. Among the stolen assets, about 103 million XRP, worth around $157 million at the time, represented the largest single portion.

The exchange’s current account of the attack is more complex than a simple stolen-private-key scenario. Bitget said the attacker compromised a critical backend system used by its wallet service, forged transaction data, and triggered the authorization process. The company added that cold wallets were not affected and that the investigation so far has ruled out private key leakage. A full forensic review is still underway, and the final technical details remain subject to the eventual investigation report.

Why THORChain became part of the story

After the assets left Bitget, the attacker began splitting and converting the funds. Blockchain security firm TRM Labs traced one route in which about $9.8 million in BNB moved out of Bitget through multiple addresses, with part of it entering THORChain and being exchanged for Bitcoin.

In that flow, THORChain was a cross-chain swap venue, not the cause of the Bitget wallet compromise. The protocol lets users swap native assets across different blockchains directly. For regular users, that is a cross-chain trading tool. For attackers, it can also serve as a fast route for converting stolen assets.

Bitget called for blocking. THORChain said no.

On Sept. 26, after attacker addresses had been publicly flagged, Bitget CEO Gracy urged THORChain on X to reject transactions tied to those addresses. She said decentralization should not be used as a justification for helping known stolen funds circulate.

THORChain did not comply. It said it regretted the Bitget theft, but stressed that it is a decentralized, permissionless network, like Bitcoin, Ethereum, and BNB Chain. THORChain also pushed back with a question of its own: if stolen funds pass through those networks, what responsibility should they bear?

The argument sharpened because of THORChain’s own history

Critics say THORChain cannot claim it has no ability to halt activity. On May 15 this year, a malicious node operator exploited a vulnerability in the GG20 threshold signature scheme and stole about $10.7 million from a THORChain vault. After that incident, an automatic safety mechanism paused signing and trading across six chains in about 52 minutes, and node operators later coordinated a network-wide shutdown through governance voting.

Trading did not gradually resume until late June, leaving the system paused for about five weeks. That history has led critics to ask a pointed question: if the network could stop when its own vault was at risk, why can’t it act when clearly flagged stolen funds from an outside incident move through the protocol?

OKX founder Xu Mingxing and security firm GoPlus have also challenged THORChain’s position. Their argument is that THORChain vaults require joint signatures from nodes and that the network has an emergency pause mechanism, so it should not be treated as directly comparable to the Bitcoin base layer.

Still, the ability to pause an entire network is not the same as having a mature system for blocking specific addresses. Who decides that an address belongs to a hacker? If stolen funds have moved through multiple hands, how do operators avoid harming legitimate users? Who updates the list, and who corrects mistakes? Those questions are not resolved simply because nodes can vote.

That is why the dispute around THORChain is no longer just about whether it can stop activity. The harder issue is whether a protocol with emergency intervention powers should create review or censorship rules for outside theft cases, and if so, who should control that process.

Exchanges are cooperating on tracing and freezes

The industry remains divided on whether THORChain should block the funds. On the narrower issue of tracing stolen assets, though, exchanges have already started working together.

Bitget said some affected assets have been frozen with help from industry partners. The exchange also launched a recovery bounty program, offering a 5% reward on the relevant amount for qualifying voluntary actions that directly lead to asset freezes or recoveries.

Bybit CEO Ben Zhou said his exchange was willing to help as well and updated the LazarusBounty platform to track the stolen funds from this case. Bybit has gone through a major theft of its own before, and the decision to open an existing tracking tool has turned past expressions of support between the two exchanges into more concrete recovery cooperation.

That kind of coordination can help flag addresses, share leads, and create opportunities to act when funds reach points where they can be frozen. Assets that have already moved into decentralized protocols such as THORChain are a different matter, and whether they can be stopped depends on the mechanisms and choices of those protocols themselves.

Can Bitget’s protection fund cover the loss?

Bitget said the loss falls within the scope of its Protection Fund and that user account balances are not affected. The fund consists of 5,500 BTC held across three wallet addresses. At the time of the incident, Bitget said that stash was worth about $464 million, which on the surface is higher than the current estimated loss of roughly $387.5 million.

But that does not mean the exchange can simply subtract the two numbers and conclude that $76.5 million would remain. The fund is denominated in BTC, so its dollar value changes with the market. The stolen assets also include XRP, ETH, and other tokens, which means the actual amount of the fund that may need to be used depends on how much is recovered, the prices required to replenish assets, and how the platform chooses to arrange the financing.

The gap between $464 million and $387.5 million shows that the buffer is not especially wide, but it is not the same thing as an already realized change in the fund’s balance. In a community livestream on the day of the report, Gracy said Bitget would continue to honor the security commitment it made when the protection fund was established in 2022. If the fund is used because of this incident, the exchange plans to replenish it back to the $300 million baseline within one week.

Who might be behind the attack

There is not enough public evidence at this stage to confirm the attacker’s identity.

Bitget said the methods used in the attack resemble tactics seen in past operations linked to North Korean hacking groups. Blockchain analytics firm Elliptic went further, assessing that the case is highly likely to be connected to North Korea. It cited links between fund addresses and cases previously attributed to North Korea, similarities in some laundering paths, and off-chain intelligence.

Even so, “highly likely” remains an analytical judgment, not a confirmed attribution. TRM Labs said similar cross-chain swaps and fund-splitting patterns are not unique to North Korean actors. As of the time its report was published, TRM had not formally attributed the case to North Korea. A final conclusion will require more complete technical forensics, fund tracing, and law-enforcement evidence.

What comes next

Bitget is still tracing and trying to recover the assets, and the identity of the attacker remains unresolved. For users, the more immediate questions are whether withdrawals will resume as planned and how the protection fund will be used and replenished.

For THORChain, the controversy is unlikely to fade just because the funds have moved on. The protocol still faces pressure to explain what situations its emergency pause mechanism is meant to cover and what rules nodes would use if flagged stolen funds appear again in the future.

This case may not produce an industry-wide answer right away. It has, however, pushed the question of whether decentralized protocols should intervene out of the realm of abstract principle and into the realm of concrete rules.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.