THORChain has rejected a formal request from Bitget CEO Gracy Chen to block addresses linked to the September 24, 2026 exploit that cost Bitget $388 million. The attackers routed millions in stolen ether and BNB through THORChain to swap them for native bitcoin. THORChain defended its decision by stating its permissionless design prevents selective censorship, drawing sharp criticism from industry figures like OKX founder Star Xu, who accused the protocol of hypocrisy for halting its network during its own May 2026 exploit.
Bitget request and issuer freezes
- ▪Circle and Tether successfully froze 218,023 USDT and 99,990 USDC, worth approximately $318,000 combined, from an attacker-linked address following the September 24, 2026 Bitget hack
- ▪THORChain rejected a public request made on September 26, 2026, by Bitget CEO Gracy Chen to block cryptocurrency addresses linked to the September 24, 2026 hack of the Bitget exchange
THORChain defense of decentralization
- ▪THORChain defended its refusal to block the hacker behind the September 24, 2026 Bitget breach by stating that the protocol is decentralized, permissionless, and does not censor transactions by design
- ▪THORChain compared its operational model to base-layer blockchains like Bitcoin, Ethereum, and BNB Chain, questioning what responsibility those networks bear when handling known stolen funds
- ▪THORChain clarified that its emergency halt mechanism is designed to protect the protocol during exploits and is not a tool for selectively freezing specific funds or individual swaps
Criticism of THORChain's model
- ▪Blockchain security firm GoPlus Security argued on September 27, 2026 that THORChain is not strictly decentralized and urged the protocol not to facilitate criminals to collect swap fees
- ▪OKX founder Star Xu criticized THORChain's comparison to Bitcoin, arguing that THORChain's validators jointly control assets in its vaults and have previously paused the network when their own funds were at risk
The Bitget hack and asset tracking
- ▪The hacker behind the September 24, 2026 Bitget breach used THORChain to swap stolen assets, including converting approximately 2,390 ether, worth $6.3 million, into 75.2 bitcoin on September 28, 2026
- ▪Bitget suffered a security breach on September 24, 2026, resulting in an estimated loss of $387.5 million to $388 million after attackers bypassed backend wallet security controls
- ▪Blockchain tracking firms TRM Labs and SlowMist's MistTrack reported that the attackers behind the September 24, 2026 Bitget breach first swapped stolen USDT and USDC into ETH and BNB to avoid issuer freezes
Bybit hack fallout
- ▪A former THORChain developer known as Pluto left THORChain following discussions about the routing of stolen Bybit funds through the network
- ▪Security experts pointed out that THORChain has been used to route stolen funds from other major exploits, including the $1.46 billion Bybit hack and the $292 million Kelp DAO exploit
Debatable claims
- ▪Bitget's User Protection Fund is sufficient to guarantee the safety of its users' assets
- ▪THORChain should block the cryptocurrency addresses linked to the Bitget hack
- ▪THORChain's past network halts undermine its claim of being a decentralized protocol
Story comments
Loading comments…