THORChain Rejects Bitget Blacklist Appeal as $387.5M Hack Ignites Neutrality Debate

bitget

Quick Read

  • Bitget suffered a 7.5 million security breach on September 24 across multiple chains.
  • Exchange CEO Gracy Chen publicly asked THORChain to blacklist attacker wallet addresses.
  • THORChain rejected the request, stating its emergency halt protects the protocol rather than selectively freezing funds.
  • Centralized issuers Circle and Tether successfully froze roughly 8,000 tied to the exploit.
  • Bitget initiated a staged withdrawal restoration starting September 28 following vulnerability patches.

A high-stakes clash between centralized crypto exchange security and decentralized infrastructure governance has reignited across the digital asset sector. Following a massive security breach on September 24 that left Bitget facing approximately $387.5 million in stolen assets, exchange leadership turned to cross-chain protocol THORChain with a direct demand: refuse service to wallet addresses linked to the attacker. THORChain’s blunt refusal to implement a targeted address blacklist has exposed a sharp philosophical rift over how permissionless networks should operate when criminal actors exploit public infrastructure.

The Breach and the Public Appeal

The incident began when attackers compromised a critical backend system within Bitget’s wallet infrastructure, triggering unauthorized transfers across Ethereum, EVM networks, the XRP Ledger, Zcash, and TRON. While Bitget confirmed that its private keys, cold storage, and Bitget Wallet product remained untouched, the initial damage assessment of $351.6 million was later revised upward to $387.5 million as investigators tracked additional cross-chain movements involving Zcash and TRON tokens.

With stolen funds actively moving across public chains—including AMLBot-tracked traces showing approximately 4 BTC routed through Wasabi CoinJoin after traversing USDT0, Ethereum, and THORChain—Bitget CEO Gracy Chen made a public appeal on September 26. Chen wrote on social media that attacker addresses were publicly tracked and formally asked THORChain to refuse service, emphasizing that decentralization should not act as a shield for facilitating stolen funds.

THORChain’s Defense of Network Neutrality

THORChain delivered its official response on September 28, rejecting the appeal outright. The protocol explained that its emergency halt mechanism is engineered strictly to protect the network architecture as a whole during an acute crisis, rather than functioning as a selective freeze tool for individual wallets or specific transactions.

“A THORChain network halt is an emergency security mechanism designed to protect the protocol. A halt is not a selective freeze of specific funds or an individual swap,” THORChain stated. The network pointed to its own May 2026 security incident—wherein an exploit drained roughly $10.7 million from liquidity pools—noting that attacker addresses were never blacklisted even during that system-level emergency.

Technical Scrutiny and Community Division

The protocol’s strict stance quickly drew pushback from security firms and industry observers. GoPlus Security argued that comparing THORChain’s architecture directly to Bitcoin or Ethereum misrepresents its actual level of decentralization. Because THORChain relies on a threshold signature vault system where active node operators collectively control vaults and sign outbound transactions, GoPlus contended that validators possess documented pause mechanisms and coordination tools that go beyond base-layer blockchains.

Conversely, crypto security executive and THORChain supporter Michael Perklin defended the protocol, asserting that threshold signing does not grant operators active transactional oversight. According to Perklin, node operators face a binary choice similar to Bitcoin miners or Ethereum validators: process transactions automatically or turn off the machine entirely.

This debate echoes historical friction within the network, including the 2025 Bybit hack where attackers routed billions in stolen Ether through THORChain without facing a retroactive blacklist. Meanwhile, centralized infrastructure entities have shown a willingness to act where permissionless protocols remain neutral; Circle and Tether successfully froze approximately $318,000 in USDC and USDT linked to the Bitget breach by September 26.

Bitget Recovery Operations and Staged Withdrawals

While the governance debate continues, Bitget is pursuing recovery through multiple channels. CEO Gracy Chen established a recovery bounty offering a 10% total reward split evenly between freezing assistance and actual fund recovery, while cybersecurity firms Mandiant and SlowMist assist ongoing investigations.

Simultaneously, Bitget has initiated a staged restoration of platform withdrawals following vulnerability remediation: Bitcoin withdrawals resumed September 28, followed by Ethereum on September 29, USDT on September 30, and remaining fiat and peer-to-peer services scheduled for October 2.

|
Contributor:Azat TV Editorial
|
Publisher:Azat TV

LATEST NEWS