Bitget disclosed a security breach that resulted in losses reported at $387.5 million. Following the hack, the exchange asked THORChain to block wallets connected to the attacker's funds. THORChain declined the request. The protocol said it does not censor transactions by design, framing the refusal as a matter of principle rather than technical limitation.
THORChain operates as a decentralized cross-chain liquidity network. It allows users to swap assets across different blockchains without relying on a centralized custodian. Its architecture depends on a distributed set of node operators who validate transactions according to protocol rules, not on any single company that can unilaterally intervene. That structure is central to how the network markets itself to users seeking alternatives to custodial exchanges.
The dispute highlights a recurring tension in decentralized finance. Exchanges and victims of hacks often want fast intervention to freeze or trace stolen assets before they can be laundered. Permissionless protocols, by contrast, are built specifically to avoid the kind of centralized control that would make such intervention possible. THORChain's response suggests it views blocking funds as incompatible with its core design, regardless of the circumstances prompting the request.
This is not the first time THORChain's approach to fund flows has drawn scrutiny. The network has previously been identified as a route used to move funds following other major hacks, drawing criticism from security researchers and exchanges alike. Supporters of the protocol argue that criticizing it for enabling fund movement misunderstands the nature of permissionless infrastructure, comparing it to blaming a public road for the actions of a getaway driver.
Critics take a different view. They argue that protocols with enough coordination among validators or node operators have some capacity to respond to clear cases of theft, even without full centralized control. They see THORChain's refusal as a missed opportunity to limit harm to hack victims, rather than a strict technical impossibility.
The debate now touches on broader questions facing the crypto industry. Regulators have increasingly pressed exchanges and infrastructure providers to demonstrate they can respond to illicit fund flows. Bitget's request, and THORChain's rejection of it, illustrate the gap between what regulators may expect and what genuinely decentralized protocols say they are able to deliver.
Bitget has not disclosed full details of how the hack occurred or what remediation steps it is taking for affected users. THORChain has not indicated any plan to reconsider its position in this case.
Market Impact
The immediate market impact centers on confidence in Bitget's security posture and on how exchanges more broadly plan to respond when stolen funds move through decentralized protocols. A loss of $387.5 million is significant enough to draw attention to Bitget's risk controls and could affect user trust in the exchange in the near term.
For THORChain, the episode may sharpen scrutiny of RUNE and the network's role in facilitating cross-chain swaps, particularly among exchanges and compliance-focused market participants. Continued association with laundering routes after major hacks could influence how other platforms and regulators treat THORChain-linked liquidity going forward, even as the protocol maintains its refusal is consistent with its founding design principles.
The standoff between Bitget and THORChain underscores an unresolved question for decentralized finance: whether permissionless networks can, or should, act when their infrastructure is used to move stolen funds.
Frequently Asked Questions
What happened to Bitget?
Bitget disclosed a hack resulting in losses reported at $387.5 million and asked THORChain to block wallets linked to the attacker.
Why did THORChain refuse Bitget's request?
THORChain said its network does not censor transactions by design, framing intervention as incompatible with its permissionless, decentralized structure.
Has THORChain faced similar requests before?
The network has previously been identified as a route used to move funds after other major hacks, which has drawn criticism from security researchers and exchanges.
What is the broader significance of this dispute?
It highlights the tension between decentralized protocols' censorship-resistant design and calls from hack victims and regulators for intervention against illicit fund flows.