Bitget’s live tracker lists 2,377 attacker addresses, and 1,497 of them are marked as having moved funds through THORChain swaps so far.
THORChain is facing a fresh dispute over its handling of stolen funds after Bitget and security researchers publicly asked the network to block addresses linked to the September 24 exploit.
The argument has widened into a fight over whether a permissionless protocol can refuse known stolen assets without compromising the censorship resistance it claims to provide.
Bitget Asks THORChain to Block Attacker Addresses
Bitget confirmed on September 25 that $387.5 million went to attacker addresses, up from the initial $351.6 million after Zcash and Tron assets were added. The exchange disclosed the breach on September 24 and blamed a backend system in its wallet setup, not a stolen private key.
CEO Gracy Chen formally asked THORChain on September 26 to refuse service to those addresses. “Decentralization is a design principle, not a shield for facilitating known stolen funds,” she said, adding that “the industry is watching.”
The request followed reports that funds from the Bitget exploit were being sent through the protocol for cross-chain swaps. MistTrack wrote that nearly $1.2 billion from the 2025 Bybit hack had previously been traced through the network and argued that the industry should question what responsibility a protocol has when it knowingly processes funds tied to a major hack.
THORChain responded, saying that it is decentralized and permissionless like Bitcoin, Ethereum and BNB Chain, and asked what responsibility those networks would bear in the same situation. Bitget’s public tracker lists 2,377 attacker addresses holding the $378 million, and 1,497 of them are marked as having moved funds through THORChain.
The protocol’s response drew criticism from security researcher Taylor Monahan, who, in a debate with crypto enthusiast Joel Valenzuela, pushed back on the view that screening transactions is different from halting a network.
You may also like:
Valenzuela had written that halts and rollbacks have happened on most networks, including Bitcoin, but screening is another matter: “That’s actually censorship,” he said.
The researcher countered that the team has secretly reallocated assets before, then claimed it has failed to decentralize in seven years, had been hacked seven times, and was, according to her, built by North Korean IT workers.
Ethereum advocate Marius Kjærstad tagged the Grok chatbot to ask whether Monahan’s claims held up. It called them partly accurate, citing at least three exploits in 2021 worth roughly 416 million and a paused lending product with about $200 million in liabilities, but found no evidence for the North Korea claims or for rug pulls for operator profit.
Critics Point to the Network’s Own Halt in May
In May, THORChain validators reportedly halted the network within hours of a $10.7 million exploit in May, and trading and withdrawals stayed unavailable for roughly five weeks, until June 22. X account Satoshi Club wondered why a network that can pause for its own losses is now asking what responsibility it bears for another platform’s stolen funds.
Bitget has offered 5% bounties on frozen and recovered funds, and Chen thanked Circle and Tether for moving quickly to freeze about $318,000 linked to the hack. The exchange has also informed users that withdrawals, which had been stopped after the attack, would restart in phases, with BTC first on September 28 at 08:00 UTC.


