THORChain Rejects Bitget Request as Hacker Wallet Swaps About $6.3M in ETH for BTC

THORChain Rejects Bitget Request as Hacker Wallet Swaps About $6.3M in ETH for BTC

N
News Editor
2026-09-28 12:13:09
A wallet tied to the Bitget attacker swapped about 2,390 ETH for 75.2 BTC through THORChain on Monday, according to CoinDesk’s review of public transaction records. The transfers were worth roughly $6.3 million based on the prices cited in the report. CoinDesk identified 27 successful swaps, while four additional swaps involving 400 ETH were still marked pending in the response it reviewed. All bitcoin payouts were sent to a single address. The activity came after Bitget, which said it lost about $388 million in a Sept. 24 breach, asked THORChain to block publicly identified attacker addresses. The exchange also offered a 5% bounty for eligible efforts that freeze or recover stolen funds. Bitget CEO Gracy Chen said on X that decentralization should not be used as cover for moving known stolen assets. THORChain declined the request. The project said its emergency halt tools are meant to protect the protocol and cannot be used as a selective freeze on a specific address or individual swap. Its documentation says operators can stop swaps across all connected chains or restrict activity on a specific chain such as Ethereum, but doing so would also disrupt other users’ transactions.

A wallet linked to the Bitget attacker swapped about 2,390 ether for 75.2 bitcoin through THORChain on Monday, a move worth roughly $6.3 million based on the prices cited in CoinDesk’s report. The transfers took place as Bitget pressed the cross-chain swap network to block addresses holding stolen funds.

CoinDesk said its review of THORChain’s public transaction records found 27 swaps marked successful, converting about 2,390 ETH into 75.2 BTC. All bitcoin payouts were sent to one address. Four additional swaps involving 400 ETH were marked pending in the response reviewed by the publication.

Orders were submitted over a narrow window on Monday

The records covered orders submitted between about 03:55 and 06:23 UTC on Monday from an Ethereum wallet that blockchain tracker Lookonchain identified as part of the attacker’s activity. Most of the orders were sent in batches of roughly 100 ETH, worth about $265,000 each at the prices referenced in the report.

THORChain allows users to swap assets across different blockchains without opening an account at a centralized exchange. In practice, that means an attacker can send stolen ether into the network and receive bitcoin in another wallet without routing the transfer through an exchange that might block it. The swaps still remain visible on public ledgers, which lets investigators trace the funds across networks.

Bitget asked THORChain to refuse service to attacker addresses

Bitget said it lost about $388 million in a Sept. 24 breach after an attacker bypassed security controls protecting the exchange’s wallets. The company later said it had identified and fixed the vulnerability, but it has not publicly explained how the attacker gained access.

The exchange published attacker addresses and offered a 5% bounty for eligible efforts that freeze or recover stolen funds. As the attacker moved assets through other services, Bitget CEO Gracy Chen publicly called on THORChain over the weekend to reject the transactions.

She wrote on X: “Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds.”

THORChain said its halt tools are not an address blacklist

THORChain responded publicly on Monday, defending its policy of allowing anyone to use the network and drawing a line between emergency shutdown controls and selective blocking of specific addresses.

The project wrote: “A THORChain network halt is an emergency security mechanism designed to protect the protocol. A halt is not a selective freeze of specific funds or an individual swap.”

The team said operators do have controls that can interrupt trading. According to THORChain documentation cited in the report, those settings can stop swaps across every connected blockchain or restrict activity involving a particular chain, such as Ethereum. Using those controls would also interrupt transactions by other users on the affected routes.

Project pointed to its May incident as a contrast

THORChain said it used emergency controls in May after an attacker stole about $10.7 million from one of its own vaults, the accounts that hold assets used for swaps. Operators coordinated a shutdown while developers investigated and repaired the vulnerability. Trading resumed on June 22 after roughly five weeks.

According to THORChain, the addresses tied to that May attacker were never blacklisted. The project framed that intervention as a response to a compromised protocol, while Bitget is now asking it to reject funds stolen from an outside exchange.

Some orders were only partially filled

Monday’s swap records also showed the attacker running into trading limits. Two 100 ETH orders were only partly filled after portions of the trades failed to meet their specified minimum price, sending about 114 ETH back to the originating wallet.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.