THORChain refuses Bitget request to block hacker as $6.3m moves to bitcoin
THORChain declined to blacklist addresses tied to the $388 million Bitget hack, and CoinDesk traced 27 swaps converting about 2,390 ether into 75.2 bitcoin.
Key points
- CoinDesk found 27 successful swaps moving about 2,390 ETH into 75.2 BTC, all paid to one bitcoin address.
- Orders were submitted between roughly 03:55 and 06:23 UTC on Monday, mostly in 100 ETH batches worth about $265,000 each.
- Bitget lost about $388 million in a Sept. 24 breach and has offered a 5% bounty for freezing or recovering funds.
- THORChain said its emergency controls can halt network activity but cannot freeze a single address or swap.
- Two 100 ETH orders were only partly filled, returning about 114 ETH to the sending wallet.
A wallet linked to the Bitget hacker moved about $6.3 million in ether into bitcoin through THORChain on Monday, as the exchange pressed the swap network to block addresses holding stolen funds. CoinDesk's review of THORChain's public transaction records found 27 swaps marked successful, exchanging about 2,390 ETH for 75.2 BTC, with all the bitcoin payouts sent to a single address.
The records cover orders submitted between about 03:55 and 06:23 UTC on Monday from an Ethereum wallet that blockchain tracker Lookonchain identified as part of the attacker's activity. Most orders went in roughly 100 ETH batches, worth about $265,000 each. Four further swaps involving 400 ETH were marked pending in the response CoinDesk reviewed.
Swaps traced on public records
THORChain lets users exchange assets across different blockchains without opening an account at a centralised exchange. That means an attacker can send in stolen ether and receive bitcoin in another wallet without passing through an exchange able to block the transfer. The swaps stay publicly visible, however, so investigators can follow the funds across networks.
Bitget lost about $388 million in a Sept. 24 breach after an attacker bypassed security controls protecting its exchange wallets. The company has said it identified and fixed the vulnerability, though it has not publicly detailed how the attacker gained access. It published attacker addresses and offered a 5% bounty for eligible efforts that freeze or recover stolen funds.
Bitget pushes for a block
As the assets moved through other services, Bitget CEO Gracy Chen publicly asked THORChain over the weekend to refuse the transactions. She wrote on X that the attacker addresses are publicly listed and actively tracked, adding that decentralisation is a design principle rather than a shield for facilitating known stolen funds.
THORChain's public response on Monday defended its policy of allowing anyone to use the network and drew a distinction between its emergency shutdown controls and an address blocklist. The project said a network halt is an emergency security mechanism designed to protect the protocol, and that a halt is not a selective freeze of specific funds or an individual swap.
THORChain defends open access
Its operators do hold controls that can interrupt trading, according to the team. THORChain's documentation describes settings that stop swaps across every connected blockchain or restrict activity involving a particular chain, such as Ethereum. Using them would also interrupt other users' transactions on the affected routes.
The network used those emergency controls in May after an attacker stole about $10.7 million from one of its own vaults, the accounts holding assets used for swaps. Operators coordinated a shutdown while developers investigated and repaired the vulnerability, and trading resumed on June 22 after roughly five weeks. THORChain said the May attacker's addresses were never blacklisted, arguing that intervention protected a compromised protocol, whereas Bitget is asking it to reject funds stolen from an outside exchange.