0x6955911e6955…6955911b
THORChain Rejects Bitget Demand to Block Addresses After $387.5M Exploit
Bitget asked THORChain to block addresses linked to a $387.5M Sept. 24 exploit. A 9,999 XRP-to-BTC swap from a flagged wallet completed Sept. 27 after THORChain refused, citing permissionless design. OKX's Star Xu disputed the comparison.
Outputs
$387.5 million in assets moved to attacker-controlled addresses in the Sept. 24 Bitget incident
9,999 XRP-to-bitcoin swap from a flagged Bitget address completed at 3:14 a.m. ET on Sept. 27
Bitget offers 5% bounties for frozen funds and 5% for recovered funds, excluding court-ordered actions
OKX founder Star Xu argued on Sept. 26 that THORChain's threshold-signature scheme makes it an intermediary, unlike Bitcoin
A 2025 Bybit-hack dispute produced a passed-and-reversed Mimir vote to halt ETH-to-BTC swaps
Bitget CEO Gracy Chen formally asked THORChain to refuse service to addresses linked to a Sept. 24 exploit that moved approximately $387.5 million in attacker-controlled assets, but a 9,999 XRP-to-bitcoin swap from one of the flagged wallets still cleared THORChain at 3:14 a.m. ET on Sept. 27.
THORChain rejected the request in a Sept. 26 post, arguing that its cross-chain liquidity network operates under the same permissionless principles as Bitcoin, Ethereum, and BNB Chain. The protocol tagged Chen and OKX founder Star Xu in its response.
"THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain," the protocol's official account wrote. It added: "What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?"
What is Bitget asking THORChain to do?
Chen directed her request at a published list of addresses: "We are formally asking @THORChain to refuse service to these addresses." She framed decentralization as "a design principle, not a shield for facilitating known stolen funds."
Bitget has operated a live attacker-address API on bgblockchain.xyz since the incident and is offering bounties equal to 5% of eligible frozen funds and 5% of eligible recovered funds. The terms exclude any actions carried out under court orders, law enforcement requests, or other legal processes.
The 9,999 XRP swap moved through one of the addresses on Bitget's attacker list. THORChain's Midgard transaction index recorded the trade as successful and identified the corresponding bitcoin settlement.
Why does OKX's Star Xu disagree?
Xu pushed back on THORChain's comparison with Bitcoin, noting that the protocol's validators collectively control assets held in vaults through a threshold-signature scheme requiring multiple participants to authorize transactions.
"TSS distributes control among multiple parties, but distributing an intermediary does not eliminate the intermediary," Xu wrote.
THORChain's developer documentation describes network-halt controls that allow nodes to stop swaps involving a specific chain, halt outbound signing, or pause trading across all connected chains. Votes on those settings run through Mimir, the protocol's node-governance system. A chain-wide halt differs operationally from Chen's request to refuse service to particular addresses: halting ETH-to-BTC trading would also interrupt ordinary users on that route.
How does the dispute echo earlier events?
The exchange of public accusations mirrors the fault line that opened after the 2025 Bybit hack, when a vote to halt ETH-to-BTC swaps passed in the Mimir system before other validators reversed it. MistTrack, the tracking platform built by security firm SlowMist, said on Sept. 25 that it was observing Bitget exploit-linked funds entering THORChain for swaps and cross-chain transfers.
Bitget has framed the request as a service-level matter rather than a technical impossibility. THORChain's Mimir mechanism can, in principle, enforce broader halts if a supermajority of nodes agrees, but the protocol has rejected address-by-address blacklisting as inconsistent with its stated design. Validators now face a recurring decision: whether to intervene in individual cases or preserve permissionless routing at the cost of becoming a preferred laundering venue for large exploits.
The exchange's recovery effort depends on whether cross-chain tracing identifies centralized exchange endpoints where stolen assets can be frozen, rather than on protocol-level intervention at THORChain. Bitget's bounty window remains the primary economic lever short of a successful Mimir vote.
via x.com (Original)