TLDR
- Bitget asked THORChain to block addresses linked to its $387.5 million security breach.
- THORChain refused, saying its emergency halt tools are not meant to freeze individual addresses.
- GoPlus Security argued that THORChain’s validators can pause the network, unlike Bitcoin and Ethereum.
- THORChain supporter Michael Perklin said node operators take part in an automated process and do not approve transfers.
- Bitget is restoring withdrawals in phases, starting with Bitcoin on Sept. 28.
Bitget has asked THORChain to block addresses linked to its $387.5 million security breach. THORChain has refused, saying its permissionless design does not allow it to freeze individual addresses.
The dispute started after Bitget CEO Gracy Chen said on Sept. 26 that addresses tied to the attacker had been publicly identified and were being tracked. The exchange then formally asked THORChain to refuse service to those addresses.
“Decentralization is a design principle, not a shield for facilitating known stolen funds,” Chen said. “The industry is watching.”
Bitget first put the losses at $351.6 million. It later raised the figure to about $387.5 million after finding more Zcash and TRON transactions.
The breach affected assets on Ethereum, several EVM networks, XRP Ledger, Zcash and TRON. Stolen tokens included XRP, ETH, USDT, ZEC, USDC, BNB, AVAX and TRX.
Some funds have already moved across chains. Blockchain tracker AMLBot traced about 4 BTC from the breach into a Wasabi CoinJoin round after the funds passed through TRON, USDT0, Ethereum and THORChain.
THORChain Defends Its Permissionless Design
THORChain compared itself to Bitcoin, Ethereum and BNB Chain. It asked what responsibility those networks have when they process transactions involving stolen assets.
The protocol said its emergency halt tools exist to protect the network itself. It said those tools are not a blacklist that can be used against individual users.
GoPlus Security challenged that view on Sept. 27. The firm said THORChain’s validators collectively control vaults and sign outbound transactions through a threshold signature system.
GoPlus also pointed to documented pause mechanisms, per chain halts and coordinated votes. It said Bitcoin and Ethereum users hold their own private keys, and validators there do not hold assets in shared vaults.
The firm cited THORChain’s response to its own exploit this year. On May 15, an attacker drained about $10.7 million from one vault, and automatic checks halted signing and trading on several chains. Trading did not resume until June 23.
Supporters Push Back on the Comparison
Michael Perklin, a longtime crypto security executive and THORChain supporter, disagreed with GoPlus. He said node operators do not approve individual transfers but take part in an automated process.
“In all 3, there is no active choice to sign, only an active choice to turn off the machine,” Perklin said. He added that shutting down infrastructure would also stop legitimate transactions.
This is not the first time THORChain has faced this question. During the 2025 Bybit hack, attackers used the protocol to convert stolen Ether into Bitcoin, creating $2.91 billion in trading volume and about $3 million in fees.
A THORChain core developer later left after node operators rejected a proposal to block transactions linked to the Bybit attacker.
Bitget said the attacker compromised a key backend system in its wallet infrastructure. Private keys were not compromised, and its cold wallets and the separate Bitget Wallet product were not affected.
Mandiant and SlowMist are helping with the investigation. Chen has offered a 5% bounty for freezing stolen assets and another 5% for recovered funds.
Circle and Tether had frozen about $318,000 in USDC and USDT linked to the breach as of Sept. 26.
Bitget is now restoring withdrawals in phases. Bitcoin withdrawals were set to resume on Sept. 28, followed by ETH on Sept. 29 and USDT on Sept. 30. Other tokens, fiat and peer to peer services are scheduled for Oct. 2.



