In a recent development that has captured the attention of the cryptocurrency community, THORChain has turned down a request from the exchange Bitget to block a malicious actor who is currently moving a sizable portion of stolen assets into Bitcoin. The request came after Bitget reported that a hacker, who is believed to be responsible for a massive theft amounting to $387.5 million, was using THORChain’s cross‑chain liquidity protocol to convert the illicit proceeds into other digital currencies, thereby obscuring the trail and complicating any potential recovery efforts. Bitget’s appeal was straightforward: they asked THORChain to stop servicing the wallet addresses that were tied to the theft, effectively freezing the hacker’s ability to continue swapping the stolen tokens.
THORChain, however, responded that it could not comply with the request. The decentralized nature of the protocol means that no single entity has the authority to block specific addresses or transactions without consensus from the network’s participants.
THORChain’s governance model is built around open access and permissionless operation, principles that are designed to prevent censorship and ensure that anyone can use the platform, regardless of the source of the funds. The incident highlights a broader tension within the decentralized finance (DeFi) ecosystem between the ideals of open, permissionless finance and the practical need for security and regulatory compliance. While decentralized protocols like THORChain pride themselves on being resistant to external control, this very characteristic can also make them attractive to bad actors seeking to launder stolen assets.
In this case, the hacker leveraged THORChain’s ability to perform seamless cross‑chain swaps without the need for a centralized intermediary, moving a large amount of Ethereum (ETH) into Bitcoin (BTC) in a series of transactions that were difficult to intercept. According to data compiled by CoinDesk, the hacker executed 27 successful swaps that transferred approximately 2,390 ETH into 75.2 BTC. These swaps were conducted over a short period, indicating a rapid conversion strategy designed to reduce the time window in which the stolen funds could be identified and seized. The conversion of ETH—a highly liquid and widely used token—into BTC, the most established cryptocurrency, further complicates tracking efforts because BTC’s extensive network and high transaction volume can mask illicit movements.
The $6 million value of the Bitcoin that was ultimately received by the hacker underscores the scale of the operation. While the total amount of ETH moved was substantial, the conversion rate at the time of the swaps resulted in a Bitcoin valuation that reflects both market conditions and the strategic timing of the trades.
This conversion also demonstrates the efficiency of THORChain’s automated market maker (AMM) model, which can execute large swaps with minimal slippage, a feature that is appealing not only to legitimate traders but also to those attempting to obscure the provenance of stolen assets. Industry experts have weighed in on the implications of THORChain’s decision. Some argue that the protocol’s refusal to block the addresses is a necessary adherence to the principles of decentralization, emphasizing that any form of selective censorship could set a dangerous precedent.
Others contend that there should be mechanisms within decentralized networks to address extreme cases of criminal activity, suggesting that community‑driven governance could be used to flag and isolate malicious actors without compromising the overall openness of the system. The broader crypto community is also watching how regulators might respond to such incidents. Authorities in several jurisdictions have expressed concerns about the difficulty of tracing funds that move across multiple blockchains via decentralized bridges.
The ability of platforms like THORChain to facilitate rapid, cross‑chain conversions without a central point of control challenges traditional anti‑money‑laundering (AML) frameworks, prompting calls for new regulatory approaches that can address the unique characteristics of DeFi. In the meantime, Bitget continues to pursue other avenues to mitigate the damage caused by the theft. The exchange has increased its monitoring of suspicious activity, enhanced its internal security protocols, and is cooperating with law enforcement agencies to trace the remaining stolen assets.
While the request to block the hacker’s addresses on THORChain was denied, Bitget’s efforts illustrate the growing responsibility that centralized exchanges feel to protect their users and the broader ecosystem. The incident serves as a cautionary tale for both users and developers within the cryptocurrency space.
For users, it underscores the importance of employing robust security measures, such as hardware wallets and multi‑factor authentication, to protect against large‑scale breaches. For developers and protocol designers, it highlights the need to consider how decentralized tools can be misused and what safeguards—if any—can be built into the system without undermining its core values. Looking ahead, the conversation around governance, security, and compliance in DeFi is likely to intensify. As more sophisticated attacks emerge and as the value locked in decentralized platforms continues to grow, stakeholders will need to find a balance that preserves the innovative spirit of permissionless finance while addressing the legitimate concerns of regulators, exchanges, and users alike.
The THORChain‑Bitget episode is a clear illustration of the challenges that lie at the intersection of technology, law, and ethics in the rapidly evolving world of digital assets.