0x6f26f8f96f26…6f26f8fc

ConfirmedRegulation & Policy832 vB113 sat/vB4 min decode

THORChain Faces Legal Exposure Over Bitget Hack Flows

THORChain refuses to block $387.5M in Bitget hack flows. Lawyer Yuriy Brisov explains why money laundering charges face doctrinal hurdles — but control is the real risk.

Could THORChain face prosecution over stolen Bitget funds?
WitnessCould THORChain face prosecution over stolen Bitget funds?AI-generated

Outputs

  1. Suspected North Korean hackers stole $387.5 million from Bitget; Bitget CEO Gracy Chen demanded THORChain refuse service to the linked addresses.

  2. THORChain retired its admin key in February 2025, 11 days before the $1.46 billion Bybit hack, after which roughly $1.2 billion in stolen funds was swapped on the protocol.

  3. Lawyer Yuriy Brisov argues immutable smart contracts are not sanctionable property under US law, citing the Tornado Cash ruling, but says any demonstrated control exposes a DeFi protocol to broader liability claims.

THORChain has refused to block addresses linked to the $387.5 million Bitget hack, reigniting a legal debate over whether decentralized protocols can be held liable for processing stolen funds.

After suspected North Korean hackers drained crypto exchange Bitget last week, investigators quickly flagged and traced the recipient addresses. Bitget CEO Gracy Chen then demanded that THORChain, the decentralized cross-chain swaps protocol, "refuse service to these addresses."

THORChain declined. "THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain," the protocol said in a statement. "What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?"

The stance carries weight because THORChain claims it cannot comply even if it wanted to. The protocol retired its admin key in February 2025 and says it has no straightforward mechanism to censor addresses. Critics note the protocol was halted in May after $10.7 million of its own funds were exploited — an intervention THORChain says was triggered by an automated system.

This is not the first time THORChain has sat at the center of such a dispute. The protocol was used to swap roughly $1.2 billion of the funds stolen in the $1.46 billion hack of Bybit in February 2025. The admin key had been retired just 11 days before that attack.

NEAR Intents took the opposite approach. Its automated SHIELD program blocked addresses tied to the Bitget hack from swapping $50 million on the platform, and it declined the 5% bounty Bitget offered for doing so. That decision has drawn criticism from decentralization advocates who argue the platform is not sufficiently permissionless.

A defense that cuts both ways

To unpack the legal questions, the legal stakes are best understood through Yuriy Brisov of D&A Partners, a crypto lawyer who addressed the issue directly. In his view, whether "we are decentralized" works as a legal defense depends entirely on the actual level of decentralization — and every act of intervention weakens it.

"When they block some addresses — they show that their nodes aren't truly decentralized," Brisov said. "Their only protection is 'we are decentralized.'"

He pointed to the Uniswap case as precedent. Investors sued Uniswap after buying 38 rugpull and scam tokens; a judge dismissed the case in March. The dismissal reinforced what Brisov calls the strongest defense available to any DeFi protocol: genuine inability to act.

The calculus flips once a protocol demonstrates control. "If you show that you have control over assets, then you potentially open yourself to all potential claims regarding pump-and-dump schemes, volatility, or any other potential claims of any investors who somehow have been damaged," Brisov said. Claimants can then ask why control was exercised in one case and not others, and why the platform does not impose KYC and due diligence obligations like a centralized exchange.

By that logic, NEAR Intents' manual-looking intervention could create exposure — but Brisov draws a sharp distinction based on how the control operates. SHIELD identifies addresses associated with known hacks on public blockchains and blocks them automatically, with no compliance team pressing buttons. "Definitely" more likely to be seen as decentralized, he said, calling it a smart solution he recommends to all DeFi companies.

On THORChain's retired admin key and its roughly hundred validators, Brisov was measured. "More likely than not, but we can't say that for sure," he said.

Money laundering is the wrong frame

Prosecutors would struggle to build a money laundering case against THORChain, Brisov argued, because the protocol does not obscure anything. Swapped funds emerge from THORChain still transparently linked to the Bitget hackers. Nor is THORChain a mixer.

The deeper obstacle is doctrinal. American law treats something as either property or not property, and money laundering requires illegally moving property through legal channels. Immutable smart contracts fail that test: nobody owns or controls them. That reasoning carried the day in the Tornado Cash litigation, where the protocol's developers proved they had no control over the smart contracts and a court found immutable smart contracts are not sanctionable property under OFAC sanctions.

Still, Brisov sees unresolved exposure. "After the Bybit case, they seriously opened themselves for potential claims," he said, noting that enforcement may simply take time — the Bybit hack occurred roughly 18 months ago.

The May protocol halt remains THORChain's weakest point. Brisov acknowledged that an automated trigger "might be" a valid defense, but stressed it has never been tested in court. "Any amount of control makes any DeFi project weaker vis-à-vis any claimant," he said. Under frameworks like the EU's Markets in Crypto Assets regulation, and the general posture of the SEC and CFTC, full decentralization shields a protocol from liability for its participants' actions — partial decentralization does not.

For now, no enforcement action has been filed against THORChain over the Bitget or Bybit flows. Whether regulators accept the retired admin key and automated halts as proof of genuine permissionlessness will likely shape the next wave of DeFi liability claims.

via Cointelegraph (Source)

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering business strategy at Mempool Brief.

413 articles