THORChain is back in the spotlight over whether it should intervene in transactions involving stolen assets.
According to blockchain data firm Bitquery, BNB and TRX stolen from Bitget were broken into dozens of transfers and sent through cross-chain routes to be swapped into Bitcoin. On Sept. 25 alone, 126.71 BTC was settled, and more than 80% of that flow went through THORChain. XRP was also moved out in batches, with THORChain identified as the destination as well.
Bitget publicly asked THORChain to deny service to the flagged addresses
On Sept. 26, Bitget CEO Gracy Chen said the attacker addresses had been publicly labeled and were under continuous tracking, and that Bitget had formally asked THORChain to refuse service to those addresses.
She wrote on X: "Decentralization is a design principle, not a shield that makes it easier to move known stolen funds. The whole industry is watching."
The post Chen cited came from SlowMist. SlowMist’s criticism also pointed directly at THORChain, saying the protocol was aware that the transactions it was handling came from a hacker tied to stolen assets and still did nothing. SlowMist then asked: "If, after every major crypto hack, attackers can keep using THORChain to move funds from ETH to BTC, from BNB to BTC, and across other chains, then the industry needs to seriously consider what responsibility THORChain should bear when it processes known stolen funds."
THORChain said it is a permissionless network, like Bitcoin and Ethereum
On Sept. 27, THORChain responded that it was "deeply saddened" by the incident, but said the protocol, like Bitcoin, Ethereum and BNB Chain, is a decentralized and permissionless network. It also asked what responsibility those networks should bear when known illicit funds move through them.
The argument was quickly challenged. OKX founder Star Xu said THORChain’s TSS-plus-validator structure does not amount to true decentralization and that, in substance, it remains an intermediary between chains, which makes it fundamentally different from Bitcoin and Ethereum.
Replying to X users who defended THORChain as decentralized, Xu added that when THORChain itself was hacked in May this year, node operators paused the network within minutes. In his view, that showed the protocol was not incapable of acting; it chose not to.
THORChain moved quickly when its own vault was hit in May
On May 15 this year, a THORChain vault was compromised, with losses of about $10.7 million. After ZachXBT and PeckShield raised alerts early that morning, the protocol’s automatic solvency monitoring triggered a network-wide halt. The Mimir governance module cut off transactions and signing at block height 26190429.
The shutdown lasted for more than five weeks. Trading resumed only on June 23, after the team had verified every node’s key shares one by one and migrated all vault assets.
That record has become part of the current argument: when the outflow involved the protocol’s own money, THORChain was able to stop the network, and did so quickly.
Earlier cases show the network was also paused during internal risk events
The May incident was not the only example.
In the summer of 2021, THORChain was hacked twice within two weeks, suffering losses of about $5 million and $8 million. On both occasions, the network was paused immediately, and users were fully reimbursed with treasury funds. Later, the project’s blog published "Hardening the THORChain Protocol," explaining how each node was given the unilateral ability to pause the chain and how large withdrawals could be throttled so funds could be kept in place during an attack.
In March 2023, the protocol also carried out a preventive shutdown for eight hours based only on a report of a "potential vulnerability." In January 2025, its ThorFi lending business faced a repayment crisis of about $200 million and was paused as well.
Its response looked very different when the money belonged to someone else
That history has sharpened criticism of THORChain’s handling of stolen funds linked to outside victims.
In February 2025, Bybit lost $1.46 billion to North Korea’s Lazarus Group. About $1.2 billion of that amount was laundered into Bitcoin through THORChain, accounting for more than 80% of the stolen funds. At the time, three validators voted to pause Ethereum-chain transactions in an attempt to cut off the flow, but the vote was overturned within 30 minutes. Core developer Pluto then resigned.
Founder JP Thorbjornsen later publicly acknowledged that he had "advised all nodes to continue processing transactions." In a later-deleted post, he put it more bluntly: "I forced all nodes to resume trading, and if they didn’t listen, I’d pull their bond, every one of them."
During that same week, THORChain collected about $3 million in fees from swaps tied to the stolen funds, while daily volume hit a record high for the protocol.
Mimir’s chain-wide pause function sits at the center of the dispute
A technical distinction has been central to the debate. THORChain may not be able to precisely blacklist a single address at the protocol level, but its Mimir system can halt the entire chain at any time. That function has repeatedly been used when the protocol’s own vaults were at risk.
For critics, the issue is not simply whether THORChain can censor a single wallet. It is whether the protocol is willing to use an existing chain-wide control when known stolen funds are moving through it.
That is also why the statement on its website that it "never censors transactions" has become another focal point in the controversy.
Supporters and critics are split over what decentralization should mean here
Supporters argue that a protocol able to block transactions on demand is, in effect, a permissioned system wearing a code-based shell, and could end up carrying compliance obligations comparable to those of Coinbase.
Critics counter that a protocol willing to shut itself down for more than five weeks to protect its own assets cannot convincingly tell a hacked exchange that it is as powerless as Bitcoin. TRM Labs went as far as calling THORChain the "bridge of choice" for North Korean money-laundering activity in May this year, adding that it had "consistently refused to disrupt illicit activity."
Bitget later offered a 5% bounty for help freezing the cross-chain funds
Bitget added another public appeal on the afternoon of Sept. 26, issuing a bounty notice saying THORChain could receive a 5% reward if it helped freeze funds the hacker had bridged through the protocol.
THORChain’s stance has kept the debate alive, with the central question unchanged: whether its invocation of decentralization matches the choices it has made when known stolen funds pass through the network.

