()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.

Bitget wants stolen funds blocked. Who can make a cross chain network comply?

Rony Roy
Edited by
Feature
Bitget wants stolen funds blocked. Who can make a cross chain network comply? - 1

Bitget has asked THORChain to refuse addresses linked to a $387.5 million wallet breach. THORChain says its emergency halt is for protecting the network, not selectively freezing a user’s swap. The two positions expose different kinds of control: an issuer can immobilise its own stablecoin, an exchange can close an account, and THORChain node operators can pause routes. None is a universal switch for stolen assets once they cross networks.

Summary
  • Bitget revised its September breach estimate from $351.6 million to about $387.5 million.
  • THORChain responded on Sept. 28 that a network halt is not a selective address freeze.
  • Circle and Tether reportedly froze 99,990 USDC and 218,023 USDT linked to the incident.
  • The two reported stablecoin freezes total 318,013 tokens, about 0.082% of the revised dollar loss.
  • A traced route moved through 4 blockchain stages before roughly 4 BTC reached a CoinJoin round.

The freshest dispute in Bitget’s recovery effort is a question of who controls the next transaction. CEO Gracy Chen called on THORChain to refuse service to addresses linked to the Sept. 24 breach. The protocol’s Sept. 28 public response distinguished the ability to halt its network from a mechanism that targets one address. GoPlus Security disputed the analogy THORChain drew with base chains, pointing to the validator set’s role in managing vaults and pausing network functions.

The dollar figure needs care. Bitget initially put the loss at $351.6 million, then raised its estimate to approximately $387.5 million after adding Zcash and TRON transactions identified in a fuller accounting. The revision is Bitget’s own estimate of assets moved to attacker-controlled addresses. It is not an independent final loss determination or a statement that another $35.9 million disappeared after the first disclosure. The company says customer balances remain intact and its protection fund will absorb the impact; those are company statements, not an independent audit of recovery.

There is no one entity called a cross chain network with authority over all of those assets. An attacker can hold a token whose issuer has a freeze function, exchange it for an asset without such an issuer, swap between native chains and seek a custodian willing to receive the proceeds. Each step leaves a different intervention point. Bitget’s request makes most sense when those points are separated.

The reported freeze is a small fraction of the revised loss

Bitget announced a recovery bounty of 5% for eligible efforts to freeze directly affected funds and another 5% for recovery. It said Circle and Tether had frozen 99,990 USDC and 218,023 USDT linked to the hack. At their dollar pegs, the two amounts sum to approximately $318,013. Divide that by $387.5 million and the reported freeze is about 0.082%, or roughly eight cents per $100 of the revised transferred-assets estimate.

That calculation is deliberately narrow. It does not say only $318,013 of the proceeds remains identifiable or that Bitget has recovered just that amount. The exchange says other affected assets have been frozen through partners but has not supplied an overall frozen-and-recovered total in the cited update. Its estimate covers multiple asset types and networks. A dollar-denominated numerator from two issuer actions and a broad incident denominator are useful for scale, not a complete recovery ledger.

The mechanisms are different too. A stablecoin issuer may have contract-level powers over a particular token. Freezing USDC at an address can prevent that address from sending the token under the issuer’s terms and controls. It cannot freeze native ETH or BTC merely because those assets were bought using USDC earlier. A centralised exchange can suspend a customer’s account or refuse a deposit tied to flagged addresses. It cannot reach into a self-custodied Bitcoin wallet outside its service. A protocol operator may halt some or all swaps, but that decision can interrupt innocent users alongside suspicious ones.

The strongest practical recovery method is therefore time-sensitive. Investigators identify addresses, follow swaps, pass information to the next issuer or custodial venue and obtain action while the asset is still within that party’s control. If a token has already been converted and withdrawn, the prior issuer’s freeze is too late for that leg. Tracking remains valuable, but tracing a coin and immobilising it are different achievements.

A swap passes through a vault, a consensus process and an outbound chain

THORChain’s technical description of native swaps starts when a user sends an asset, such as BTC, to a protocol vault on its native chain. Nodes observe that inbound transaction. The network prices the swap through its liquidity pools and prepares an outbound transaction in the destination asset. The vault’s outbound transfer is authorised using a threshold signature: multiple node participants contribute, while no one operator holds the whole key.

The protocol’s vault documentation is why the comparison with a simple wallet-to-wallet Bitcoin payment has limits. THORChain’s nodes collectively maintain infrastructure that receives the inbound asset and sends the outbound one. Individual nodes are not human clerks manually approving each swap. But the network does have operational settings that can pause activity on specified chains or globally. Those powers are described in THORChain’s network halt documentation.

A halt is a broad rule about processing. It can stop a route while a vault imbalance or exploit is investigated. An address blacklist is a narrower rule about who may use a route while other transactions continue. THORChain says the former exists and the latter is not its ordinary mechanism. GoPlus says the presence of node-controlled vaults and documented halts means the network is capable of taking responsibility for what passes through. The factual overlap is the ability to interrupt operations. The disagreement is whether that ability should become address-specific screening, and what modification to software and governance such screening would require.

If a swap is still waiting in a queue, a timely pause could interrupt processing before outbound settlement. If the outbound transaction has already settled on Bitcoin, a later halt cannot reverse Bitcoin history. If the inbound has already entered a vault and trading halts, the user may face a delay or a refund process governed by protocol rules. The exact result depends on the transaction state and the halt used. A phrase like “freeze the funds on THORChain” is too vague to explain which asset is held where at the moment of intervention.

The same analysis applies to alternative routes. Stopping one swap venue does not stop a wallet from attempting another bridge, exchange or direct sale. A response across the entire market requires many independent actors to act in time. It may still block meaningful amounts, but it is not a command one team can issue to all chains.

The four-Bitcoin trail crosses several kinds of control

AMLBot traced roughly 4 BTC linked to the incident into a Wasabi CoinJoin round, according to a Sept. 27 report. Its described path began with assets on TRON, moved through USDT0 to Ethereum, used THORChain for an exchange into Bitcoin and then entered a CoinJoin round. That is one observed route, not the route taken by all $387.5 million or proof that every receiving address belongs to the same person.

The path gives a useful intervention map. On a stablecoin leg, the token issuer may be able to act on an address if the contract and legal conditions allow it. During a bridge or cross-chain transfer, the operator’s actual design matters. At THORChain, network operators can affect swap availability under the protocol’s halt controls. At a custodial exchange, account operators may stop deposits or withdrawals. Once native BTC is controlled by an external wallet, THORChain no longer controls that wallet’s balance, even if the BTC came from its outbound vault.

A CoinJoin combines inputs and outputs in a transaction designed to make straightforward tracing harder. It does not necessarily make every coin permanently untraceable or prevent a later custodian from asking a depositor about the funds. The public trail cited by AMLBot shows why investigators race to coordinate across asset types. Each conversion can change which party has a direct technical lever and which data are visible.

There is a ratio worth resisting. Four BTC is a count of one routed tranche. It cannot be divided into the whole incident without a timestamped BTC price, and even that would show only the share of the reported loss in that particular traced leg. The analytical value lies in the sequence of control points, not a claim that those four coins stand for the full hack.

THORChain’s May halt proves one power and leaves another untested

THORChain halted functions after its own vault exploit on May 15, which was reported at roughly $10.7 million. Solvency checks identified an imbalance, and node operators later coordinated further measures. Crypto.news covered the 11-step restart plan and the eventual return of trading in June. The history disproves an absolute claim that THORChain cannot pause activity. Its documentation lists controls for chain-specific trading, signing and broader network functions.

It does not show that the system currently maintains a verified list of stolen-fund addresses and screens each inbound swap against it. Halting everyone is technically and economically different from refusing one identified user. A blacklist must specify which source addresses count, how wallets linked through transfers are added, who verifies evidence, who can appeal an incorrect entry and whether the rule applies to a token after it has changed hands. A mistaken designation could block an innocent holder. A narrow rule also invites the attacker to move funds to fresh addresses or use a different entry route.

GoPlus Security’s counterargument is strongest on governance. If a validator set already can coordinate a halt, it has some capacity to choose not to process a category of activity, even if the present mechanism is crude. THORChain’s answer is strongest on implementation. A broad emergency stop does not equal an existing selective freeze, and switching off a whole chain to block one address imposes a cost on unrelated swaps. These claims can coexist. Neither resolves the policy question of whether to add a screening rule and who would maintain it.

The May episode matters for a second reason. It shows how expensive a blanket interruption can be: trading did not simply resume the following block. Vault and key-share checks were part of the restart process, and liquidity users had to wait. A network security intervention to prevent more funds leaving an impaired vault is a different trade-off from a halt designed to intercept one external attacker’s route. The scale of harm to other users would have to be weighed in the latter case.

The same flagged address means different things on each chain

Bitget published primary receiving addresses for several networks, including EVM-compatible chains, XRP Ledger, Zcash and TRON, according to its recovery update. An address list is a starting set of observations, not a universal identity record. The same person can control many wallets, and a service can receive assets from many unrelated customers into one address. A screening policy that treats every address touched by a flagged wallet as equally culpable would quickly reach funds owned by people with no role in the breach.

The form of the address also changes the task. On Ethereum, an issuer may inspect a contract token balance at a particular account and exercise any freeze function the contract allows. On Bitcoin, a transaction spends specific outputs; there is no USDC-style token administrator to change the spendability of a native bitcoin. At an exchange, the relevant information may be the deposit attribution in the exchange’s own internal ledger, which an outside analyst cannot infer from a public wallet address alone. On a cross-chain swap, the incoming and outgoing addresses may be different because the vault receives the first asset and signs the second leg to a designated destination.

Suppose investigators identify a stolen USDT transfer on TRON and notify an issuer. A freeze before that balance is converted can hold that specific token. If it has already become ETH, the USDT action may block only what remains. If ETH enters a THORChain vault, a network pause could interrupt a pending swap but could also stop unrelated traffic; an address filter would need reliable criteria to recognize the deposit and rules for deciding what to do with it. If BTC has already left the vault, the opportunity to stop that specific outbound leg has passed. This is an illustrative sequence, not a reconstruction of every Bitget transfer.

The sequencing puts a premium on timestamps. A useful public record would show when Bitget first tagged an address, when a relevant service received notice, when funds arrived there, when an outbound transaction was broadcast and when any freeze took effect. A late warning is different from a service declining a timely request. Without those times, accusations that a named operator “let funds through” can imply knowledge and control that the record has not shown.

Address errors have costs too. Someone can receive a small transfer from an attacker without consent. A pool can mix balances from many participants. A reusable deposit address can represent a custodial service rather than a single customer. The more automated a filter, the more explicit its rules and review process must be. A halt may be blunt, but a blacklist that can be amended without evidence or recourse is another kind of operational risk.

A request is not a legal order or a protocol vote

Chen’s public request is an appeal to the THORChain community, not itself a court injunction or a network parameter change. It can alert nodes and interfaces to an address list. It can prompt an independent service to decline interaction. It does not automatically give Bitget authority over THORChain’s validator set. The network, for its part, can choose how it responds through its existing governance and software processes, subject to applicable law and the practical limits of its design.

The blockchain security dispute should not be collapsed into a yes-or-no claim about decentralisation. A decentralised network can still have switches for emergencies. A system with emergency switches can still lack a single operator who can reliably filter a particular address in every transaction. Control is divided between software rules, node coordination, vault signing and interfaces. Calling all of that either entirely permissionless or entirely controllable skips the actual question.

For investigators, a public address list is only the beginning. They need to distinguish a proven attacker address from a service deposit address that has received mixed funds, follow asset conversions and keep a time-stamped chain of evidence. A platform or issuer then needs to decide whether it has the technical ability and legal basis to act. A blanket statement that funds are “frozen” needs a denominator, an asset, a location and a date to mean anything measurable.

Bitget’s planned staged restart of withdrawals beginning Sept. 28 is a separate decision about its customer service and wallet security. It does not depend on THORChain granting the request. The exchange says Mandiant and SlowMist are assisting its investigation and that the vulnerability was fixed. Its schedule identified BTC first, then ETH, USDT and other services through Oct. 2. The status of each stage should be checked against live exchange notices, because a published schedule is not proof a given transfer has succeeded.

The decisive number will be recovered assets, not reported blocks

Bitget offers a 5% bounty for an eligible freeze and another 5% for an eligible recovery. That structure itself acknowledges two stages. A frozen balance at a token issuer may remain under investigation, while a recovered balance is returned or otherwise secured for the rightful party. Public dashboards may show suspicious addresses and token balances without establishing legal ownership or custody of assets. A company can claim customer accounts are whole even if it has not recovered the external assets, by using its own reserves or a protection fund.

THORChain could publish a proposal for selective address screening, keep its existing emergency tools, or reject any new control. The Sept. 28 statement documents its current position. A policy change would need code and governance details to show who decides which addresses are barred and how a false match is reversed. A full chain halt would be visible through network status and affect ordinary users, but it would not necessarily recover funds already paid out.

The more limited result is already visible: issuer freezes of approximately $318,013 in named dollar tokens against Bitget’s estimate of $387.5 million transferred. That ratio could rise as other issuers or exchanges act, or prove to be only a small part of a broader recovery that the exchange has not yet quantified. The evidence available on Sept. 28 supports neither a claim that no one can intervene nor a claim that the cross-chain route can be completely shut against the attacker.

An independently checkable recovery account would list assets by chain, the amount initially moved, the amount frozen, the amount actually returned and the valuation date. Until that exists, the clearest test of each actor’s power is a recorded intervention at a specific control point, followed by evidence that the targeted funds did not leave it.

What to watch

  • THORChain network settings. Check whether a chain halt, signing halt or new address-screening proposal actually appears.
  • Bitget’s tracing updates. A revised total and an asset-by-asset frozen or recovered tally would replace today’s partial accounting.
  • Issuer freezes. Circle and Tether actions can be counted separately from swaps stopped elsewhere.
  • Outbound swap records. A queued, refunded and completed transaction imply very different intervention opportunities.
  • Withdrawal notices. Confirm Bitget’s staged reopening against live platform status through Oct. 2.

FAQ

How much did Bitget say was stolen?

Bitget’s revised estimate was approximately $387.5 million after it included additional Zcash and TRON transactions. The company initially reported $351.6 million.

What did Bitget ask THORChain to do?

CEO Gracy Chen asked the protocol to refuse service to addresses linked to the breach. THORChain said its emergency network halt is not a tool for freezing individual addresses.

Can THORChain halt swaps?

Yes. Its developer documentation describes network and chain-specific halt settings, and the network paused operations after a May 2026 exploit. A broad halt is distinct from screening one address while processing others.

Who controls assets in THORChain vaults?

The network’s active node operators collectively participate in threshold signing for outbound transactions. No one node holds the entire signing key under the described design.

How much was frozen in USDC and USDT?

Bitget said Circle and Tether had frozen 99,990 USDC and 218,023 USDT linked to the attack. That is approximately $318,013 at the dollar peg, excluding any other freezes not quantified in the same update.

What share of the reported breach is $318,013?

It is approximately 0.082% of the revised $387.5 million estimate. The calculation compares a partial freeze tally with the incident estimate and is not a final recovery rate.

Can a halt reverse Bitcoin already sent out?

No. A later THORChain halt cannot reverse a completed transaction on the Bitcoin network. It may affect a swap still awaiting outbound settlement, subject to its stage and the relevant protocol settings.

Does a freeze mean Bitget recovered the assets?

No. Freezing immobilises a balance under a particular party’s control; recovery requires a further legal or operational process to secure or return it. This is educational analysis, not investment advice.

Disclaimer: This article is for information and educational purposes only and does not constitute financial or investment advice. Figures reflect regulatory filings and reporting available at the time of writing and change with each disclosure. Nothing here is a recommendation to buy, sell, or hold any security or asset. Always do your own research. Information is accurate as of September 28, 2026.