Particle.news
Download on the App Store

THORChain Refuses to Block Bitget Hacker as Millions Convert to Bitcoin

The decision exposes a growing clash over whether cross‑chain services should enforce blocks on tracked stolen funds or preserve permissionless swaps.

Overview

  • Bitget confirmed about USD 387.5 million was moved to attacker-controlled addresses in a Sept. 24 breach and began phased withdrawals with Bitcoin payouts restarting on Sept. 28 after security checks.
  • Bitget’s CEO publicly asked THORChain to refuse service to listed attacker addresses and launched a bounty program offering rewards for frozen or recovered funds.
  • On-chain records show a wallet linked to the attacker executed 27 THORChain swaps that converted roughly 2,390 ETH, worth about USD 6.3 million, into 75.2 BTC with all bitcoin sent to a single address.
  • THORChain says its emergency halt tools are meant to protect the protocol and cannot selectively freeze individual addresses; critics point to its threshold‑signature (TSS) vaults and the on‑chain Mimir pause system as mechanisms that give validators practical control over signing and halts while supporters say signing is an automated process not an active approval of specific transfers.
  • Forensic teams including Mandiant and SlowMist along with blockchain trackers continue tracing the flows, some stablecoins have been partially frozen by issuers, attribution signals point to VPN infrastructure used in past DPRK‑linked attacks but formal public attribution remains under investigation and regulatory pressure may grow if cross‑chain laundering persists.