0x15f515ae15f5…15f515b1

ConfirmedSecurity519 vB106 sat/vB3 min decode

Bitget CEO Gracy Chen Calls Out THORChain Over Hack Response

Bitget CEO Gracy Chen attacked THORChain's decentralization defense after the protocol refused to block addresses tied to a $387.5 million breach, citing its own 39-day shutdown in a prior exploit.

Bitget CEO criticizes THORChain for inconsistent response to hacks
WitnessBitget CEO criticizes THORChain for inconsistent response to hacksAI-generated

Outputs

  1. Bitget lost an estimated $387.5 million in a September 24 breach spanning Ethereum, XRP Ledger, Zcash and TRON

  2. THORChain refused Chen's September 26 request to block attacker addresses, citing permissionless design

  3. THORChain halted its own network for roughly 39 days after a May 2026 exploit drained about $10.7 million from its vaults

Bitget CEO Gracy Chen has publicly criticized THORChain for refusing to block addresses tied to the September 24 security breach that cost the exchange an estimated $387.5 million, arguing the protocol's decentralization defense collapses under its own operational history.

The breach initially carried an estimated $351.6 million price tag. Investigators subsequently traced additional unauthorized transfers across Ethereum, XRP Ledger, Zcash, and TRON, revising the total to roughly $387.5 million. On September 26, two days after the attack, Chen formally asked THORChain to block the attacker's addresses moving stolen funds through its cross-chain swap infrastructure.

THORChain declined the same day. The protocol framed its refusal as a principled commitment to permissionless design, positioning itself as neutral infrastructure that cannot selectively censor participants.

The 39-day contradiction

Chen's core argument rests on THORChain's own conduct during a prior crisis. In May 2026, attackers drained approximately $10.7 million from the protocol's vaults. THORChain's response was to halt network operations entirely for roughly 39 days while its team patched the vulnerability and recovered.

That precedent, Chen contends, undercuts the decentralization defense. If the protocol can coordinate a month-long shutdown when its own treasury is at risk, then citing permissionless architecture as the reason for refusing to block addresses linked to a $387.5 million theft reads less like principle and more like selective convenience.

The distinction carries legal weight. Protocols that demonstrate the capacity for coordinated intervention — whether halting operations or filtering transactions — face a harder task arguing they function as purely neutral infrastructure beyond the reach of compliance obligations.

Stolen funds kept moving

The dispute played out while attacker funds continued flowing through THORChain with substantial volume. One tracked swap involved approximately $6.3 million in ETH exchanged for roughly 75.2 BTC.

Chen has linked the attack to patterns associated with North Korean cyber operations. Law enforcement investigations remain ongoing, and no attribution has been confirmed.

The throughput itself generated measurable market activity. THORChain's native RUNE token posted price gains in the days following the incident, with trading volumes lifted by both the controversy and the sheer volume of stolen assets being swapped through the protocol.

Regulatory implications

The episode lands amid intensifying regulatory scrutiny of cross-chain protocols and their role in laundering illicit proceeds. The Bybit hack earlier in the cycle drew similar attention to THORChain's function as a swap venue for stolen assets.

Chen's public complaint adds a documented data point for regulators constructing accountability frameworks around DeFi infrastructure. A protocol with a demonstrated history of network-level intervention — but declining address-level blocking when third parties bear the losses — presents enforcement agencies with a concrete test case for how far "fully decentralized" claims stretch.

For Bitget, the immediate operational priority remains recovery coordination with law enforcement across the four affected chains. For THORChain, the longer-term question is whether sustained use as a laundering rail for high-profile thefts forces the protocol's node operators and governance participants to adopt screening mechanisms — voluntarily or under compulsion — before regulators impose them from outside.

via Crypto Briefing (Source)

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering business strategy at Mempool Brief.

451 articles