0x3f73c1dc3f73…3f73c1df
THORChain Rejects Bitget Request as $6.3M in Stolen Ether Crosses to Bitcoin
THORChain processed 27 swaps converting 2,390 ETH ($6.3M) into 75.2 BTC for a wallet tied to Bitget's Sept. 24 hack, rejecting CEO Gracy Chen's request to blacklist attacker addresses.

Outputs
THORChain processed 27 swaps converting about 2,390 ETH ($6.3M) into 75.2 BTC between roughly 03:55 and 06:23 UTC on Monday.
Bitget lost approximately $388 million in a Sept. 24 breach after an attacker bypassed exchange wallet security controls.
Bitget is offering a 5% bounty for efforts that freeze or recover the stolen funds.
THORChain rejected selective blacklisting, framing its network halt as an emergency protocol mechanism rather than an address-level freeze.
THORChain previously halted trading for about five weeks following a May vault exploit worth $10.7 million, resuming June 22.
THORChain processed 27 swaps converting about 2,390 ETH ($6.3 million) into 75.2 BTC on Monday, routing proceeds from the Sept. 24 hack of exchange Bitget through a permissionless swap layer that the protocol's operators say they will not selectively police.
A wallet identified by blockchain tracker Lookonchain as tied to the attacker submitted the orders between roughly 03:55 and 06:23 UTC, according to public transaction records reviewed by CoinDesk.
Most landed in 100 ETH batches worth approximately $265,000 each. All bitcoin payouts flowed to a single address. Four additional swaps involving 400 ETH sat pending at the time of review. Two of the 100 ETH orders failed to meet the minimum price and returned about 114 ETH to the sending wallet.
What did Bitget ask THORChain to do?
Bitget CEO Gracy Chen publicly pressed the protocol over the weekend to refuse service to the attacker's wallets, publishing addresses and offering a 5% bounty for any effort that freezes or recovers the stolen funds.
The exchange lost about $388 million after an attacker bypassed security controls protecting its exchange wallets on Sept. 24. The company has since said it identified and patched the vulnerability without describing the intrusion in technical detail.
"Our attacker addresses are publicly listed and actively tracked," Chen wrote on X. "We are formally asking @THORChain to refuse service to these addresses." She added: "Decentralization is a design principle, not a shield for facilitating known stolen funds."
Why did THORChain refuse?
THORChain's operators rejected selective blacklisting on Monday, drawing a distinction between network-wide emergency controls and address-level enforcement. The protocol's public response argued that halting trading to freeze one wallet or one transaction exceeds the scope of its shutdown mechanics.
"A THORChain network halt is an emergency security mechanism designed to protect the protocol," the project wrote. "A halt is not a selective freeze of specific funds or an individual swap."
The protocol pointed to its May precedent. THORChain operators coordinated a network shutdown after an attacker stole about $10.7 million from one of its own vaults. Trading resumed on June 22 after roughly five weeks. THORChain said the May attacker's addresses were never blacklisted, framing that intervention as protecting a compromised protocol rather than enforcing an outside exchange's blacklist.
How does THORChain's design complicate enforcement?
THORChain operates as a cross-chain swap layer, letting users exchange assets between blockchains without signing up at a centralized venue. An attacker holding stolen ether can route through the network and receive bitcoin in a separate wallet, bypassing any centralized exchange that might block the transfer. Every swap, however, leaves a public record that investigators can use to trace the funds.
THORChain's documentation describes settings that pause swaps across every connected blockchain or restrict activity on a specific chain such as Ethereum. Deploying either setting to exclude an attacker would interrupt unrelated users transacting on the same route.
What comes next?
Bitget's 5% bounty remains open. Chen's public appeal sets up a live test of whether decentralized swap protocols will absorb reputational and legal pressure from large centralized counterparties. THORChain faces a narrower near-term decision: whether to activate any chain-level restriction on Ethereum swaps or continue routing the attacker's transactions as public, traceable records.
via CoinDesk (Source)