()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.

Bitget hack sparks dispute over THORChain’s permissionless design

Rony Roy
Edited by
News
Bitget hack sparks dispute over THORChain’s permissionless design - 1

THORChain has defended its permissionless design after Bitget asked the cross chain protocol to refuse service to addresses tied to the exchange’s $387.5 million security breach, opening a dispute over whether its network should block known stolen funds.

Summary
  • Bitget asked THORChain to block addresses linked to its $387.5 million security breach as stolen funds continued moving across chains.
  • THORChain said its emergency halt mechanisms protect the protocol but do not provide a system for selectively freezing individual addresses.
  • GoPlus Security challenged the comparison with Bitcoin and Ethereum, pointing to THORChain’s validator controlled vaults and documented pause mechanisms.
  • THORChain supporters argued that nodes participate in an automated process and stopping infrastructure would disrupt legitimate transactions as well.
  • Bitget is tracing stolen assets with security firms while gradually restoring withdrawals following the Sept. 24 breach.

THORChain said the network’s ability to halt during emergencies is a security mechanism designed to protect the protocol and does not amount to a system for selectively freezing individual addresses, according to its response to criticism surrounding the Bitget attacker.

THORChain rejects calls to block Bitget attacker addresses

The dispute began after Bitget CEO Gracy Chen said on Sept. 26 that addresses linked to the attacker had been publicly identified and were being actively tracked.

Bitget formally asked THORChain to refuse service to the addresses as investigators continued tracing funds moved after the Sept. 24 breach.

“Decentralization is a design principle, not a shield for facilitating known stolen funds,” Chen said. “The industry is watching.”

Bitget initially put the value of assets affected by the breach at $351.6 million before raising the figure to approximately $387.5 million after its investigation identified additional Zcash and TRON transactions.

The exchange said unauthorized transfers affected assets across Ethereum and several EVM networks, XRP Ledger, Zcash and TRON. XRP, ETH, USDT, ZEC, USDC, BNB, AVAX and TRX were among the assets involved.

Some of the stolen funds have since moved across chains. As crypto.news previously reported, AMLBot traced roughly 4 BTC linked to the breach into a Wasabi CoinJoin round after the assets moved from TRON through USDT0, Ethereum and THORChain before reaching Bitcoin.

THORChain pushed back against calls to stop the transfers by pointing to its permissionless structure. The protocol compared its role with networks such as Bitcoin, Ethereum and BNB Chain and questioned what responsibility those networks should bear when they process transactions involving known stolen assets.

Its latest response drew a distinction between an emergency network halt and selectively refusing transactions from individual addresses. THORChain argued that the emergency shutdown mechanisms exist to protect the protocol itself and are not equivalent to a blacklist that can be applied to individual users.

Security firms question THORChain’s decentralization argument

GoPlus Security challenged that explanation on Sept. 27, arguing that THORChain’s architecture gives its validator set powers that differ from those available to participants on Bitcoin and Ethereum.

The security firm pointed to THORChain’s threshold signature vault system, under which the active validator set collectively controls vaults and signs outbound transactions.

GoPlus argued that THORChain nodes can stop activity through documented pause mechanisms, per chain halts and coordinated votes. The firm contrasted that setup with Bitcoin and Ethereum, where users hold their own private keys and validators do not collectively custody assets in protocol vaults.

THORChain demonstrated its ability to stop network functions during its own security incident earlier this year.

A May 15 exploit drained approximately $10.7 million from one of the protocol’s five vaults after a malicious node operator exploited a weakness in its GG20 Threshold Signature Scheme. Automatic solvency checks detected an imbalance and halted signing and trading on several chains before node operators coordinated further shutdown measures.

The protocol later faced criticism over its GG20 fix after proposing to retain a patched version of the signing framework instead of replacing it immediately.

THORChain subsequently introduced version 3.19.0 as part of an 11 step restart plan. The upgrade included compromised vault quarantine and temporary keyshare checks before signing and other network services could resume.

Trading eventually resumed on June 23 after more than a month offline. THORChain said vaults and keyshares had been checked before swaps, signing, churning and liquidity provider functions were restored.

GoPlus cited the May response in arguing that THORChain should not directly compare its operating model with Bitcoin and Ethereum when discussing whether transactions can be stopped.

THORChain supporters dispute the comparison

Michael Perklin, a longtime crypto security executive and THORChain supporter, rejected GoPlus Security’s comparison, arguing that threshold signing does not mean node operators individually approve transactions.

Perklin said THORChain swaps should not be described as active signing decisions in which people choose whether to approve individual transfers. Under his explanation, node operators participate in an automated network process and can stop participating by taking their nodes offline.

He compared that option with Bitcoin miners or Ethereum validators switching off their machines to avoid processing transactions.

“In all 3, there is no active choice to sign, only an active choice to turn off the machine,” Perklin said.

Stopping infrastructure to prevent criminal transactions would stop legitimate transactions at the same time, he argued. Perklin described Bitcoin, Ethereum and THORChain as neutral public infrastructure whose operators should not be blamed for the actions of people using them.

The disagreement follows an earlier controversy involving THORChain and stolen assets from the 2025 Bybit hack. Attackers used the protocol extensively while converting stolen Ether into Bitcoin, with THORChain recording $2.91 billion in trading volume and roughly $3 million in fee revenue from the activity.

A THORChain core developer later left after a proposal to block transactions linked to the Bybit attacker failed to gain support from node operators.

Bitget continues tracing stolen funds

Bitget’s request comes as the exchange works with security firms and other crypto companies to trace and recover assets from the Sept. 24 breach.

Chen launched a recovery bounty offering a 5% reward for actions that successfully freeze stolen assets and another 5% for funds that are recovered. Circle and Tether had frozen approximately $318,000 in USDC and USDT linked to the incident as of Sept. 26.

Bitget said its investigation found that the attacker compromised a critical backend system within its wallet infrastructure and used it to trigger unauthorized transfers. The exchange said private keys were not compromised, while its cold wallets and the separate Bitget Wallet product were unaffected.

Independent cybersecurity firms Mandiant and SlowMist are supporting the investigation and fund tracing efforts.

The exchange has meanwhile started restoring withdrawals in phases after identifying and fixing the vulnerability. Bitcoin withdrawals were scheduled to resume on Sept. 28, followed by ETH on Sept. 29 and USDT on Sept. 30, with other tokens, fiat and peer to peer services scheduled for Oct. 2.