Blockchain AcademicsBlockchain Academics
THORChain Refuses to Block $387M in Bitget Hack Funds, Citing Decentralization

THORChain Refuses to Block $387M in Bitget Hack Funds, Citing Decentralization

Bitget CEO Gracy Chen publicly called on THORChain to freeze $387 million in stolen funds on September 26. THORChain declined, citing its commitment to decentralization and permissionless infrastructure. The refusal highlights the tension between asset recovery rights and the architectural...

Blockchain Academics NewsroomEdited by Wael RajabSeptember 27, 20263 min read
Share

THORChain Refuses to Block $387M in Bitget Hack Funds, Citing Decentralization

Bitget CEO Gracy Chen publicly called on THORChain to freeze stolen funds on September 26, after hackers siphoned approximately $387 million from the exchange and began routing assets through the decentralized cross-chain liquidity protocol. THORChain declined.

The refusal puts two foundational crypto principles in direct conflict: the right of hack victims to pursue asset recovery, and the architectural commitment of permissionless protocols to remain neutral infrastructure. THORChain's node operators have so far held firm, arguing that implementing a block on specific addresses would undermine the protocol's trustless design.

Chen pushed back sharply on that framing.

"Decentralization is a design principle, not a shield for facilitating known stolen funds."

Gracy Chen, CEO of Bitget

The argument carries weight, but so does the counterargument. THORChain's value proposition rests on the guarantee that no single party, including its own node operators, can unilaterally freeze or redirect user funds. The moment that guarantee becomes conditional, every user of the protocol faces a different risk calculus. Compliance with one recovery request opens the door to the next, and the one after that, whether the requestor is a hacked exchange or a government agency.

What makes THORChain's position harder to defend publicly is its own recent history. In May 2026, the protocol voluntarily paused operations after absorbing a $10 million loss of its own. That decision was framed as a protective measure for the protocol and its liquidity providers. Critics note the asymmetry: THORChain halted for $10 million when the pain was internal, but declines to act on $387 million when the victim is external.

The protocol's defenders draw a meaningful distinction. A self-imposed operational pause is an internal governance decision. Blocking specific user addresses based on an outside party's allegation is a categorically different act, one that requires THORChain to become an arbiter of which funds are "stolen" and which are not. If THORChain began honoring asset-freeze requests, it would need a process for evaluating them, a threshold of evidence, and a mechanism for appeal. Each of those steps introduces centralization. Regulators and law enforcement would quickly learn the address to send their own requests to.

The $387 million figure also raises questions about Bitget's own security posture. Cross-chain protocols like THORChain, which allow users to swap native assets across blockchains without wrapping or custodying them, are a predictable destination for stolen funds precisely because they are permissionless. Exchanges holding nine-figure balances have both the resources and the regulatory incentive to implement withdrawal monitoring that flags large outflows to known DEX aggregators and cross-chain bridges before funds clear. That Bitget's funds reached THORChain in volume suggests the breach moved faster than the exchange's incident response.

The broader pattern is well established. After the $625 million Ronin bridge hack in March 2022, stolen ETH and USDC moved through Tornado Cash within days. After the $100 million Harmony Horizon bridge exploit that June, funds cycled through multiple mixers and DEXs. In none of those cases did decentralized protocols comply with freeze requests, and in most cases compliance would have been technically impossible. THORChain's situation is different only in that it theoretically has a governance layer capable of acting. The fact that it chose not to will define how the protocol is perceived by both regulators and future institutional users.

For Bitget, the immediate priority is tracing where the funds went after leaving THORChain and whether any centralized exchanges received them. Centralized venues can and do freeze assets when presented with documented evidence of theft. That is where asset recovery efforts are most likely to yield results. THORChain was never going to be the solution.

Discussion

Loading comments...