Following a September 24 hack on crypto exchange Bitget that resulted in the theft of $387.5 million, a portion of the stolen assets is currently being converted into Bitcoin using THORChain, which has declined to block the transactions.
By utilizing THORChain, users can exchange a token from one blockchain for a token on another without undergoing any identity verification. Once the assets are converted into Bitcoin, freezing them becomes impossible for any company.
Bitget Asks THORChain to Turn the Hacker Away
The hacker’s wallet addresses are publicly known and actively monitored. In response, Bitget CEO Gracy Chen urged THORChain to reject these addresses.
“Decentralization is a design principle, not a shield for facilitating known stolen funds. The industry is watching,” she said.
According to blockchain analysis firm MistTrack, a similar scenario occurred previously. Following last year’s $1.46 billion Bybit exploit, approximately $1.2 billion was reportedly tracked moving through THORChain.
THORChain Says It Is No Different From Bitcoin
In response, THORChain defended its position, describing itself as a permissionless network accessible to anyone, much like Ethereum, Bitcoin, and BNB Chain.
“What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?” the team stated.
This statement questions the accountability of those foundational blockchains in processing recognized illicit funds, thereby deflecting pressures for THORChain to monitor or block such transactions.
The situation underscores the ongoing conflict within the crypto sector between THORChain’s permissionless cross-chain swap capabilities and broader industry calls for protocols to take action against publicly identified hacker wallets.
THORChain Has Hit Pause Before
Star Xu, the founder of competitor exchange OKX, dismissed THORChain’s comparison to Bitcoin as “False!” He pointed to an event in May where THORChain paused a vault after roughly $10 million was drained, according to the protocol’s own documentation.
“A network that can stop when its own funds are at risk, but refuses to do so when someone else’s funds are at risk, is not “like Bitcoin,”” the OKX executive slammed.
May was not an isolated instance. Network nodes acted quickly to halt operations following a hack in 2021, and in January 2025, participants voted to freeze the platform’s savings and lending offerings.
Additionally, a sanctioned nation, North Korea, previously leveraged THORChain to launder over $1 billion stemming from the Bybit incident. Investigators and Bybit itself determined that the Lazarus Group funneled the bulk of the February 2025 attack through THORChain to swap the assets into Bitcoin.
What Happens to Bitget Users
Bitget has assured customers that a $464 million protection fund will cover all users. Platform withdrawals are scheduled to resume on Monday, beginning with Bitcoin at 8:00 UTC.
Chen noted that North Korea was highly likely behind the security breach. Bitget is currently providing a 5% bounty for assistance in freezing the stolen capital.
Despite ongoing criticism over its refusal to blacklist the flagged wallets, THORChain’s native RUNE token has climbed more than 20% over the past 24 hours.
Frequently Asked Questions
How much was stolen in the Bitget hack?
Hackers stole $387.5 million from the crypto exchange Bitget on September 24.
Why is THORChain involved in the Bitget hack?
Part of the stolen funds is being converted into Bitcoin through THORChain, which allows users to swap assets across different blockchains without any identity checks.
What was THORChain’s response to the criticism?
THORChain defended its stance by comparing itself to base blockchains like Bitcoin, Ethereum, and BNB Chain, asking what responsibility those networks bear when handling known stolen funds.
How are Bitget users being protected?
Bitget stated that a $464 million protection fund covers every customer, with withdrawals restarting on Monday beginning with Bitcoin at 8:00 UTC.


