NEAR Intents blocked over $50 million in transfers tied to the Bitget hack using its screening system. THORChain processed $6.3 million in ETH-to-BTC swaps from the hacker's wallet and refused Bitget's request to block the addresses.

THORChain's defense is that a network halt is an emergency mechanism to protect the protocol itself, not a tool for selectively freezing individual addresses. They point to their own May 2026 exploit, where roughly $10.7 million was stolen, and they still didn't blacklist the attacker's addresses. Their position: we're permissionless like Bitcoin and Ethereum. What responsibility do those base layers bear when they process stolen funds?

The counterargument is brutal. OKX founder Star Xu pointed out that THORChain halted its own network in May when its own funds were at risk, but won't act when someone else's funds are being laundered. GoPlus Security added that THORChain's assets sit in TSS vaults under validator control, meaning it's an intermediary, not a base layer, and it has the technical capacity to screen.

The uncomfortable truth is that THORChain has become a go-to laundering route. The Bybit attacker moved roughly $1.2 billion through it in 2025. The KelpDAO attacker swapped $175 million through it in April 2026, generating around $910,000 in fees for the protocol. THORChain's founder acknowledged earning $5-10 million in fees from the Bybit hack alone.