BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

THORChain Rejects Bitget Hack Blacklist as Vitalik Weighs In

THORChain has declined a request to blacklist wallet addresses tied to the Bitget exchange hack, citing the protocol's commitment to censorship resistance, while Ethereum co-founder Vitalik B

AnonymousCryptoCompass newsroom
September 28, 2026
4 min read
NEWS
THORChain Rejects Bitget Hack Blacklist as Vitalik Weighs In
CryptoCompass editorial visual for defi coverage.

THORChain has declined a request to blacklist wallet addresses tied to the Bitget exchange hack, citing the protocol's commitment to censorship resistance, while Ethereum co-founder Vitalik Buterin separately weighed in on how Ethereum approaches similar questions of network neutrality.

THORChain Rejects Blacklisting Addresses Linked to the Bitget Hack

The decision puts THORChain at the center of a recurring tension in decentralized finance: whether permissionless infrastructure can, or should, selectively block funds tied to known exploits. THORChain's core design treats address-level neutrality as a protocol property, not an administrative setting. A blacklist would require either a hard fork or an off-chain governance mechanism capable of overriding liquidity routing, neither of which the protocol's node operators have historically been willing to adopt. For related coverage, see Bybit CEO Ben Rejects AI Layoff Excuses in Highlight Clip.

The refusal is not equivalent to endorsing the hack or its proceeds. It reflects the same logic applied in prior cases where hackers used THORChain to swap stolen BTC after other venues froze the relevant addresses. In each instance, THORChain's position has been that a cross-chain liquidity layer cannot function as a compliance enforcement layer without undermining the trustlessness that gives it value to legitimate users.

The Bitget hack was not an isolated incident. On-chain investigators had already linked a portion of the stolen funds to mixing activity; AMLBot traced 4 BTC from the Bitget hack to a Wasabi CoinJoin transaction, demonstrating the lengths to which attackers go to obscure fund flows before they reach a cross-chain bridge like THORChain.

KEY POINTS

  • THORChain node operators declined to implement address-level blacklisting for wallets linked to the Bitget hack.
  • Protocol neutrality and censorship resistance were cited as the rationale; blacklisting would require governance-level intervention that conflicts with the protocol's trustless design.
  • The refusal continues a pattern seen in prior hacks where THORChain served as a routing layer despite law enforcement and exchange pressure to block funds.

ZachXBT previously estimated THORChain exploit losses may exceed $10 million across related incidents, suggesting the protocol is a structurally attractive exit route for attackers operating across chains. Each refusal to blacklist reinforces that perception, regardless of intent.

Vitalik Buterin's Ethereum Comment Adds Context to the Neutrality Debate

Buterin's remarks on Ethereum, which the headline references but does not quote in full, land in the same governance territory. Buterin has written and spoken extensively about the distinction between Ethereum as a base layer remaining neutral and application-layer or social-layer actors choosing to act on known bad behavior. The precise framing of his latest comment is not available in the verified research for this article, and reconstructing it from paraphrase would be speculative.

What the two situations share is a structural question: at what layer of a decentralized stack does responsibility for handling stolen funds appropriately sit? THORChain's answer is that the protocol layer carries none. Ethereum's ongoing debate, which Buterin participates in, concerns whether validator-level or client-level coordination should ever be used for similar ends, and whether doing so would compromise the credibility of neutrality claims at the base layer. Ethereum remains the largest smart contract ecosystem by total value locked, making any shift in its neutrality posture consequential for DeFi protocols that depend on its infrastructure.

For users tracking hacked funds, the practical implication is that neither THORChain's refusal nor Ethereum's neutrality debate closes off recovery options at the protocol level. Recovery tends to occur through centralized exchange cooperation, on-chain tracing by firms like AMLBot or ZachXBT, or legal action against identifiable counterparties. The THORSwap wallet exploit illustrated this dynamic: the protocol itself was not modified, but off-chain coordination and bounty mechanisms provided a partial resolution path.

The more durable question for decentralized AI and compute infrastructure developers watching this space is whether governance modules, including on-chain voting systems that could theoretically implement address-level restrictions, will be treated as a feature or a flaw. Protocols that hardcode censorship resistance at the consensus layer gain credibility with neutral-infrastructure users; those that leave room for governance-level intervention may find that flexibility becomes a pressure point every time a high-profile hack moves funds through their liquidity pools. Ethereum's token market metrics reflect that base-layer credibility has market value, a signal that cross-chain protocols like THORChain are betting their own positioning on as well.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Read original article on aicryptocore.com