Another week, another nine-figure crypto hack, and another round of the sport that always follows one: figuring out who to blame for letting the money get away. This time a good share of the
Another week, another nine-figure crypto hack, and another round of the sport that always follows one: figuring out who to blame for letting the money get away. This time a good share of the anger landed on THORChain. After a breach drained hundreds of millions of dollars from the exchange Bitget in late September, some of the stolen funds moved across THORChain's cross-chain swap protocol, and Bitget's CEO publicly asked the network to refuse service to the attacker's wallets. THORChain declined. Cue the outrage.
Bitget’s users are understandably upset with the situation, but it's arguably the wrong place to direct their anger. The overlying issue at hand is whether a permissionless network can switch off a specific account at all, and whether we actually want one that can.
Start with the part everyone races past. Neutral tools get used by everyone, the good and the bad alike. Criminals use cash, cars, encrypted messaging, and lately AI, and we do not usually decide that roads and email are the villains of the story. The stolen Bitget funds did not only touch THORChain either. They also moved across Bitcoin, Ethereum, and BNB Chain, and passed through multiple swap and bridge services along the way. Nobody is demanding Bitcoin miners or Ethereum validators start hand-picking which transactions to reject, because base-layer neutrality is understood and accepted. A cross-chain swap layer sits in the same category. It moves value between chains for anyone who asks, which is the entire point of it.
So just block the bad wallet, then. If only it were a setting. The problem is that these networks do not ship with a magic filter for denying one address while everyone else keeps trading. The only lever that exists is blunt and total: freeze the whole thing for everyone, or run it for everyone. Selectively censoring a single participant is not a feature that got switched off in a moment of weakness. It was never built, on purpose, because the day you build means the network can censor anyone.
Even if that button existed, it would not have done much. The funds bounced through a dozen venues. Block one address on one protocol and it reroutes through the next one in seconds. What actually helps in a case like this is the opposite of censorship, which is transparency. Every swap on a public network is visible in real time, which is exactly why investigators named the attacker's wallets within hours and why exchanges and analytics firms can chase the money to the regulated on and off ramps, where freezes genuinely happen. Open rails aid recovery. Closed ones just push the problem somewhere darker.
None of this makes the discomfort disappear, and it should not. Permissionless really does mean permissionless, including for people you would give anything to stop. That is a genuine cost. The tradeoff is that you can have neutral infrastructure that nobody can weaponize against you, and accept that it will sometimes be used by those deemed to be bad actors. Or you can have infrastructure with a master switch, and hope the person holding that on-off button always agrees with you. There is no third option where the switch exists but only ever gets pulled on the guilty.
Bottom Line
The Bitget saga is not really a story about whether THORChain is the bad guy. It is a story about the off switch: who we would trust to hold one, and whether a financial system worth building is one where somebody, somewhere, gets to decide whose money is allowed to move. Blame the plumbing if it makes you feel better. The real issue is whether you actually want plumbing that can be shut off on you.