A wallet linked to the Bitget attacker swapped about 2,390 ether for 75.2 bitcoin through THORChain on Monday, a move worth roughly $6.3 million based on the prices cited in CoinDesk’s report. The transfers took place as Bitget pressed the cross-chain swap network to block addresses holding stolen funds.
CoinDesk said its review of THORChain’s public transaction records found 27 swaps marked successful, converting about 2,390 ETH into 75.2 BTC. All bitcoin payouts were sent to one address. Four additional swaps involving 400 ETH were marked pending in the response reviewed by the publication.
Orders were submitted over a narrow window on Monday
The records covered orders submitted between about 03:55 and 06:23 UTC on Monday from an Ethereum wallet that blockchain tracker Lookonchain identified as part of the attacker’s activity. Most of the orders were sent in batches of roughly 100 ETH, worth about $265,000 each at the prices referenced in the report.
THORChain allows users to swap assets across different blockchains without opening an account at a centralized exchange. In practice, that means an attacker can send stolen ether into the network and receive bitcoin in another wallet without routing the transfer through an exchange that might block it. The swaps still remain visible on public ledgers, which lets investigators trace the funds across networks.
Bitget asked THORChain to refuse service to attacker addresses
Bitget said it lost about $388 million in a Sept. 24 breach after an attacker bypassed security controls protecting the exchange’s wallets. The company later said it had identified and fixed the vulnerability, but it has not publicly explained how the attacker gained access.
The exchange published attacker addresses and offered a 5% bounty for eligible efforts that freeze or recover stolen funds. As the attacker moved assets through other services, Bitget CEO Gracy Chen publicly called on THORChain over the weekend to reject the transactions.
She wrote on X: “Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds.”
THORChain said its halt tools are not an address blacklist
THORChain responded publicly on Monday, defending its policy of allowing anyone to use the network and drawing a line between emergency shutdown controls and selective blocking of specific addresses.
The project wrote: “A THORChain network halt is an emergency security mechanism designed to protect the protocol. A halt is not a selective freeze of specific funds or an individual swap.”
The team said operators do have controls that can interrupt trading. According to THORChain documentation cited in the report, those settings can stop swaps across every connected blockchain or restrict activity involving a particular chain, such as Ethereum. Using those controls would also interrupt transactions by other users on the affected routes.
Project pointed to its May incident as a contrast
THORChain said it used emergency controls in May after an attacker stole about $10.7 million from one of its own vaults, the accounts that hold assets used for swaps. Operators coordinated a shutdown while developers investigated and repaired the vulnerability. Trading resumed on June 22 after roughly five weeks.
According to THORChain, the addresses tied to that May attacker were never blacklisted. The project framed that intervention as a response to a compromised protocol, while Bitget is now asking it to reject funds stolen from an outside exchange.
Some orders were only partially filled
Monday’s swap records also showed the attacker running into trading limits. Two 100 ETH orders were only partly filled after portions of the trades failed to meet their specified minimum price, sending about 114 ETH back to the originating wallet.

