Meta Force Space
BTC — ETH — SOL — XRP — BNB — DOGE —
← Back to the news

Bitget’s hack exposes a double standard on stolen funds

THORChain is being asked to block stolen funds. Why isn’t the same demand being made of the blockchains carrying them?

Summary
  • Bitget has called on THORChain to block addresses linked to its $387.5 million hack, raising questions over whether permissionless networks should intervene when stolen funds pass through them.
  • The stolen assets moved across several blockchains and services, including Ethereum, BNB Chain and THORChain, before portions were converted into Bitcoin.
  • THORChain can halt trading in emergencies, but broader intervention could disrupt legitimate users and require independent node operators to enforce new transaction restrictions.
  • Investigators have traced attacker controlled addresses across eight networks, showing that public transaction records can remain useful even as stolen funds move between chains.

Bitget has every reason to pursue the people behind its recent hack and recover the money. The exchange now puts the loss at approximately $387.5 million, and its users deserve restitution. The pressure being applied by Bitget and some inside the industry, however, raises questions about how responsibility gets assigned once stolen money starts moving.

Last week, Bitget CEO Gracy Chen asked THORChain to refuse service to identified attacker addresses. THORChain responded by pointing to Bitcoin, Ethereum and BNB Chain: what responsibility should those networks bear when the same stolen assets pass through them?

Crypto has spent years defending infrastructure that operates without discretionary gatekeepers. After a major theft, some panic and that infrastructure suddenly faces demands to acquire those powers. The industry needs a consistent explanation for where it draws the line.

The same money crossed other networks

According to Bitget’s account, the attacker exploited a vulnerability in a third-party security product, obtained internal credentials and submitted fraudulent withdrawal commands. The exchange says its private keys and cold wallets were unaffected.

The assets subsequently travelled through multiple networks and services.It was traced on BNB Chain and Ethereum through THORChain into Bitcoin. Those underlying blockchains continued processing transactions as the funds moved between attacker-controlled wallets.

The question posed to those within crypto is if Bitcoin miners and Ethereum validators reject those proceeds too? Treating transaction processing as endorsement of theft would extend responsibility across much of the infrastructure the attacker touched. Calling for selective intervention at the swap layer demands a stronger justification than the fact that the transaction was visible there.

THORChain is not identical to a base-layer blockchain. More specifically, it operates liquidity pools and vaults secured through threshold signatures, with groups of independent node operators authorizing outbound transactions. It does not give a single executive the power to suspend a customer.

A network halt is not an account freeze

THORChain’s governance process puts protocol changes through development, review and node adoption. A durable, protocol-wide wallet blacklist would require enforcement rules and sufficient participation from independent operators. Bitget is asking for a change to the network’s transaction rules, with consequences beyond this attacker.

Emergency controls also exist. THORChain describes chain-specific trading halts, signing halts and network-wide trading halts. A global trading halt stops swaps across every connected chain, interrupting legitimate users and the swap fees their activity generates. Narrower halts still affect everyone using the relevant chain.

Using those emergency powers whenever externally stolen funds arrive would give them a broader purpose. But realistically the case for doing so needs to account for the ordinary users caught in the shutdown, alongside the conditions for restarting.

Blocking one route leaves plenty of others

Roughly a dozen services were identified after the theft, including Uniswap, MetaMask Bridge and Swaps, LI.FI, Across, Stargate, deBridge, Relay, Mayan, Celer, PancakeSwap, and Circle’s Cross-Chain Transfer Protocol. These were routes used after the compromise, not the source of it.

Blocking one venue could delay an attacker or increase costs. It would not eliminate alternative routes, establish control over funds elsewhere or guarantee recovery. Permanent screening would also require decisions about who maintains the blacklist, what evidence qualifies and how mistakes are corrected. Those powers carry huge consequences for a permissionless network.

Meanwhile, public records are helping investigators. 28 attacker-controlled addresses were mapped across eight networks within hours. THORChain’s public transaction data gives investigators a trail to follow without requesting access to a private exchange ledger.

A portion of the funds were traced through TRON, Ethereum and THORChain into Bitcoin, then linked roughly four BTC to a Wasabi CoinJoin transaction. In that documented sequence, investigators followed the cross-chain swaps; the later CoinJoin complicated the connection between inputs and outputs. Passing through THORChain had not erased the trail.

For an industry with decentralization at its core, a practical division of responsibilities would be between independently operated infrastructure, public transaction records and intervention where assets can actually be controlled. Cooperation should be judged by better tracing, faster identification and money recovered.

Bitget deserves support in pursuing the stolen funds. Requiring an open network to become a discretionary gatekeeper is not a sustainable or practical answer. The question here is how many innocent users would pay for it.

Originally published by crypto.news on

Read the original on crypto.news ↗

Text and images are the property of crypto.news and are reproduced here with attribution and a link to the original publication.

More stories

All the latest news