Bitget presses THORChain to block hacked funds, reigniting debate over protocol intervention

Bitget presses THORChain to block hacked funds, reigniting debate over protocol intervention

N
News Editor
2026-09-27 13:17:10
Bitget’s dispute with THORChain has sharpened after Bitget CEO Gracy publicly asked the cross-chain liquidity protocol to deny service to addresses tied to the exchange’s Sept. 24 hack. THORChain pushed back, saying it operates as permissionless infrastructure in the same way Bitcoin, Ethereum and BNB Chain do, and should not be singled out to perform censorship. The clash has turned attention to a harder question: whether THORChain’s node governance can selectively intervene, and if so, when it chooses to do it. The article traces how THORChain’s design lets native assets move across chains without wrapped tokens, making it possible for stolen assets to be converted into native BTC, where centralized issuers can no longer freeze or reverse transfers. On-chain tracking cited in the report says about 103 million XRP, worth roughly $157 million, has already been swapped out through THORChain, while most of the ETH has not yet moved. The report also contrasts two past governance episodes. In May 2026, THORChain coordinated a shutdown in about two hours after its own vault was exploited, keeping trading paused for 39 days. In the 2025 Bybit case, a vote to pause ETH trading briefly passed and was then overturned within minutes. That comparison has fueled criticism that the issue is less about technical limits than about willingness to act.

Bitget’s effort to contain funds tied to its recent hack has run into resistance from THORChain, putting the protocol’s governance model under fresh scrutiny.

Bitget presses THORChain to block hacked funds, reigniting debate over protocol intervention 2

On Sept. 26, 2026, Bitget CEO Gracy posted on X calling on THORChain to deny service to known attacker addresses linked to the exchange’s Sept. 24 security incident. She wrote that decentralization is a design principle, not a shield for giving known illicit funds a free pass.

THORChain answered that it could not comply. The protocol said it is permissionless infrastructure, like Bitcoin, Ethereum and BNB Chain, and those networks are not expected to carry out censorship when known stolen funds move through them. That defense has not satisfied critics, largely because THORChain has moved quickly to halt operations when its own system was under attack.

RUNE volumes jumped as hacked funds moved through the protocol

The report says the presence of stolen funds increased fee generation on THORChain, helping drive a visible rise in RUNE trading activity and price momentum. On the day of the public exchange, RUNE trading volume expanded fourfold.

THORChain allows native assets from different chains to swap directly through liquidity pools, without first converting ETH or other assets into wrapped representations. By skipping the wrapping layer, the system also avoids reliance on the issuers behind wrapped assets.

That matters because Circle and Tether can freeze USDC and USDT, but once stolen assets are converted into native BTC, there is no centralized issuer left to reverse the flow. According to the report, this is exactly the end state attackers want: no identity verification, no account-freeze step, and liquidity pools deep enough to process large swaps. XRP, ETH and BNB can all be exchanged into native BTC, which is harder to recover.

On-chain tracking cited in the article shows that roughly 103 million XRP, worth about $157 million, has already been swapped out through THORChain. The bulk of the ETH has not moved yet.

Bitget presses THORChain to block hacked funds, reigniting debate over protocol intervention 3

Each swap generates fees that are distributed to nodes and liquidity providers. The article points to this as one reason RUNE is highly sensitive to volume, and why the attackers’ route through the protocol became tied to the token’s market performance.

The dispute centers on TSS vaults and whether intervention is possible

At the center of the argument is THORChain’s Threshold Signature Scheme, or TSS, vault design. Under that setup, a group of nodes each holds a fragment of a key, and assets in the vault can only move once the required threshold is met. When enough signatures are assembled, the funds can be transferred out. In that sense, critics argue, there is still a governance layer that can be held accountable.

Exchanges and blockchain investigators have focused on that point. As framed in the report, THORChain acts as an intermediary between users and native blockchains, except that the intermediary is decentralized rather than centralized. THORChain has held to the view that it is neutral infrastructure and should not be expected to perform law-enforcement functions, pushing the issue back toward Bitcoin and Ethereum themselves.

The tension is straightforward: victims want interception, the protocol argues for neutrality, and outside observers ask who is responsible. The key distinction is between not reviewing transactions by default and lacking the ability to review them at all. In theory, the node set can refuse to sign. The real question is whether it wants to.

THORChain shut down for 39 days after its own May exploit

The article revisits a THORChain exploit on May 15 this year. Malicious nodes used a vulnerability related to threshold signatures to drain about $10.70 million from a single vault. After the protocol detected the issue, it stopped signing automatically. The community then coordinated a shutdown in about two hours, and trading remained paused for 39 days before resuming on June 23.

When the protocol itself was losing funds, node action was swift. The article says the voting threshold to pause a chain is not especially high: three votes are enough to make it effective, while four votes can reverse it. That history is presented as one of the clearest pieces of evidence in the debate over whether THORChain can intervene.

Bitget presses THORChain to block hacked funds, reigniting debate over protocol intervention 4

The Bybit case pointed to willingness, not technical limits

A separate example came in the 2025 Bybit case. Of the roughly $1.46 billion in stolen funds, research cited in the report estimated that about $1.2 billion was converted from ETH into BTC through THORChain, or around 85% of the total. During that episode, three validators voted to pause ETH trading, but the move was overturned within minutes by four votes.

Core developer Pluto later resigned. On the same day, the FBI issued a notice asking virtual asset service providers to block the relevant addresses. THORChain ultimately maintained its permissionless stance.

The comparison between the two episodes has sharpened the criticism. The article argues that the difference lies mainly in governance willingness rather than technical ability. So far, nodes have not launched a new vote to halt a chain in response to the Bitget incident.

Bitget’s reported loss was revised higher to about $387.5 million

The size of Bitget’s theft has been revised up from $351.6 million to about $387.5 million. That is still smaller than the Bybit case, but the report says the headline number is not the central issue. What matters more is how much has already passed through THORChain and whether nodes will move to trigger another halt vote.

At present, about $157 million has been confirmed as having been swapped out through THORChain, according to the article.

For RUNE holders, that leaves two pressures on the same ledger: a short-term surge in trading activity and a longer-running compliance narrative that now weighs on the protocol’s market perception.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.