THORChain reiterated on September 28 that it will not block funds linked to the Bitget hack, arguing that its architecture is permissionless and lacks any mechanism to censor or blacklist specific transactions. The statement came in direct response to a request from Bitget chief executive Gracy Chen, who had asked the protocol to deny service to the attackers in order to stop the movement of stolen assets, as reported the previous day by CriptoNoticias.
THORChain said the only tool available to it is a network-wide halt mechanism, which it described as an emergency security measure reserved for threats to the protocol itself. It said this function was never designed to freeze the funds of a specific third party while allowing the rest of the network to keep operating normally.
The protocol pointed to its own experience as evidence of consistency. THORChain suffered a theft of $10.7 million from its liquidity pools in May 2026, and the addresses tied to that attacker were never blocked, continuing to operate within the network afterward. THORChain said its support for arguments made by security specialist Michael Perklin reflects the same principle applied in that earlier case.
MistTrack pushes back
Security firm MistTrack, which detected that funds extracted from Bitget were being routed to THORChain for cross-chain transfers, disputed the protocol's framing of the issue. The firm's findings were part of the broader scrutiny THORChain has faced since the Bitget breach came to light.
THORChain has been at the center of this debate before. Last year's hack of Bybit, which resulted in losses of $1.46 billion, saw approximately $1.2 billion transit through THORChain, cementing the protocol's reputation as a common route for laundering stolen crypto assets.
Bitget's losses and recovery
Bitget has estimated its losses from the breach at $387.5 million. The exchange attributed the incident to a vulnerability in a third-party security product that granted attackers access to internal credentials, allowing them to extract XRP, ether, USDT and AVAX. According to reports, cold wallet private keys were not compromised in the breach.
The exchange began a gradual reactivation of withdrawals on September 28, starting with bitcoin on its main network and on BNB Smart Chain. Bitget said it maintains a 5% reward for the recovery of stolen capital and that client balances are backed by a fund worth $464 million. The exchange also said it will publish an internal security report during the current week.




