BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

THORChain Refuses Bitget’s Request to Block Wallets Tied to Its $387.5 Million Hack

THORChain publicly stated it will not block wallets linked to the roughly $387.5 million Bitget hack, after Bitget requested that the network do so The protocol said a THORChain network halt

AnonymousCryptoCompass newsroom
September 28, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.
  • THORChain publicly stated it will not block wallets linked to the roughly $387.5 million Bitget hack, after Bitget requested that the network do so
  • The protocol said a THORChain network halt is an emergency security mechanism designed to protect the protocol as a whole, not a tool for selectively freezing specific funds or an individual swap
  • THORChain drew a contrast with its own May 2026 exploit, in which roughly $10.7 million was stolen from its liquidity pools, as context for how it has previously handled attacker-linked addresses

THORChain said in an official post on X at 06:36 UTC on September 28, 2026 that it will not block wallets tied to the hack that hit exchange Bitget for roughly $387.5 million in late September, after Bitget’s team had asked the protocol to intervene. The statement came as some of the stolen funds tied to the hack continued moving through THORChain’s swap infrastructure toward bitcoin.

THORChain explained that a network halt on its protocol is an emergency security mechanism intended to protect THORChain itself from systemic risk, not a mechanism for selectively freezing the funds of a specific wallet or blocking an individual swap. The protocol described its infrastructure as decentralized by design, without a centralized party capable of unilaterally blacklisting addresses the way a centralized exchange can.

The protocol pointed to its own May 2026 exploit, in which attackers stole roughly $10.7 million from THORChain’s liquidity pools, as a point of comparison for how it has approached attacker-linked addresses in the past, framing its response to Bitget’s request as consistent with that earlier precedent rather than a new policy adopted specifically for this incident.

The refusal highlights a recurring tension in decentralized finance between exchanges seeking to recover stolen funds after a hack and the permissionless, censorship-resistant design that many cross-chain protocols treat as a core value proposition. Centralized exchanges can freeze accounts and blacklist addresses at will, but protocols like THORChain that route swaps without custodying user funds or maintaining a centralized blacklist function are structurally limited in what they can do even when asked directly by a hacking victim.

Bitget has separately stood up its own fund-tracing dashboard and recovery bounty program to pursue the stolen assets through other channels, meaning THORChain’s refusal to intervene does not end the exchange’s broader recovery effort, even as it removes one potential avenue for stopping funds from moving further through cross-chain infrastructure.

The episode is likely to renew debate within the broader decentralized finance community over how much responsibility permissionless infrastructure providers bear for funds that move through their systems after a hack elsewhere, a question that recurs each time a major exchange breach sends stolen assets flowing through bridges and swap protocols that were never designed to police the origin of the transactions they process.

This post first appeared in THORChain Refuses Bitget’s Request to Block Wallets Tied to Its $387.5 Million Hack