Bitget’s effort to contain funds tied to its recent hack has run into resistance from THORChain, putting the protocol’s governance model under fresh scrutiny.

On Sept. 26, 2026, Bitget CEO Gracy posted on X calling on THORChain to deny service to known attacker addresses linked to the exchange’s Sept. 24 security incident. She wrote that decentralization is a design principle, not a shield for giving known illicit funds a free pass.
THORChain answered that it could not comply. The protocol said it is permissionless infrastructure, like Bitcoin, Ethereum and BNB Chain, and those networks are not expected to carry out censorship when known stolen funds move through them. That defense has not satisfied critics, largely because THORChain has moved quickly to halt operations when its own system was under attack.
RUNE volumes jumped as hacked funds moved through the protocol
The report says the presence of stolen funds increased fee generation on THORChain, helping drive a visible rise in RUNE trading activity and price momentum. On the day of the public exchange, RUNE trading volume expanded fourfold.
THORChain allows native assets from different chains to swap directly through liquidity pools, without first converting ETH or other assets into wrapped representations. By skipping the wrapping layer, the system also avoids reliance on the issuers behind wrapped assets.
That matters because Circle and Tether can freeze USDC and USDT, but once stolen assets are converted into native BTC, there is no centralized issuer left to reverse the flow. According to the report, this is exactly the end state attackers want: no identity verification, no account-freeze step, and liquidity pools deep enough to process large swaps. XRP, ETH and BNB can all be exchanged into native BTC, which is harder to recover.
On-chain tracking cited in the article shows that roughly 103 million XRP, worth about $157 million, has already been swapped out through THORChain. The bulk of the ETH has not moved yet.

Each swap generates fees that are distributed to nodes and liquidity providers. The article points to this as one reason RUNE is highly sensitive to volume, and why the attackers’ route through the protocol became tied to the token’s market performance.
The dispute centers on TSS vaults and whether intervention is possible
At the center of the argument is THORChain’s Threshold Signature Scheme, or TSS, vault design. Under that setup, a group of nodes each holds a fragment of a key, and assets in the vault can only move once the required threshold is met. When enough signatures are assembled, the funds can be transferred out. In that sense, critics argue, there is still a governance layer that can be held accountable.
Exchanges and blockchain investigators have focused on that point. As framed in the report, THORChain acts as an intermediary between users and native blockchains, except that the intermediary is decentralized rather than centralized. THORChain has held to the view that it is neutral infrastructure and should not be expected to perform law-enforcement functions, pushing the issue back toward Bitcoin and Ethereum themselves.
The tension is straightforward: victims want interception, the protocol argues for neutrality, and outside observers ask who is responsible. The key distinction is between not reviewing transactions by default and lacking the ability to review them at all. In theory, the node set can refuse to sign. The real question is whether it wants to.
THORChain shut down for 39 days after its own May exploit
The article revisits a THORChain exploit on May 15 this year. Malicious nodes used a vulnerability related to threshold signatures to drain about $10.70 million from a single vault. After the protocol detected the issue, it stopped signing automatically. The community then coordinated a shutdown in about two hours, and trading remained paused for 39 days before resuming on June 23.
When the protocol itself was losing funds, node action was swift. The article says the voting threshold to pause a chain is not especially high: three votes are enough to make it effective, while four votes can reverse it. That history is presented as one of the clearest pieces of evidence in the debate over whether THORChain can intervene.

The Bybit case pointed to willingness, not technical limits
A separate example came in the 2025 Bybit case. Of the roughly $1.46 billion in stolen funds, research cited in the report estimated that about $1.2 billion was converted from ETH into BTC through THORChain, or around 85% of the total. During that episode, three validators voted to pause ETH trading, but the move was overturned within minutes by four votes.
Core developer Pluto later resigned. On the same day, the FBI issued a notice asking virtual asset service providers to block the relevant addresses. THORChain ultimately maintained its permissionless stance.
The comparison between the two episodes has sharpened the criticism. The article argues that the difference lies mainly in governance willingness rather than technical ability. So far, nodes have not launched a new vote to halt a chain in response to the Bitget incident.
Bitget’s reported loss was revised higher to about $387.5 million
The size of Bitget’s theft has been revised up from $351.6 million to about $387.5 million. That is still smaller than the Bybit case, but the report says the headline number is not the central issue. What matters more is how much has already passed through THORChain and whether nodes will move to trigger another halt vote.
At present, about $157 million has been confirmed as having been swapped out through THORChain, according to the article.
For RUNE holders, that leaves two pressures on the same ledger: a short-term surge in trading activity and a longer-running compliance narrative that now weighs on the protocol’s market perception.

