Attack on Bitget that cost $388 million, and the subsequent demonstrative refusal by THORChain to block the hacker — two events that together create a fundamentally new discussion about the nature of decentralized finance. This is not just another hack, but a public test of where the proclaimed immutability of protocols ends and where responsibility to users begins. For professional market participants, it’s a top-tier signal: vulnerabilities in DeFi infrastructure in 2025 are not technical in nature, but architectural and managerial.
According to Bitget CEO Gracey Chen, the attacker acted methodically: two test transfers were carried out—classical reconnaissance of risk-control systems—about half an hour before the main fund withdrawal. This means the attacker already had information about the structure of the defenses or had the ability to test them without immediate response from the platform. $388 million is an amount comparable to the largest hacks in the sector’s history, including the Ronin Bridge attack ($292 million). After the theft was discovered, Bitget approached THORChain with a request to block the movement of funds. The protocol refused. According to CoinDesk data, about $6 million of the stolen funds were converted into Bitcoin via THORChain. It was this refusal, not the hack itself, that became the central point of the systemic contradiction.
THORChain was originally designed as a censorship-resistant cross-chain liquidity protocol. Its refusal to comply with Bitget’s request formally aligns with the stated principles. However, in the context of the protocol’s active use for money laundering from major hacks—where THORChain also appeared in the outflow of funds after the Bybit hack in early 2025—the “we are neutral” position is becoming less and less convincing to regulators and institutional partners. At the same time, a broader context should be considered: this very week, Chainlink released an updated version of CCIP—the cross-chain interaction protocol—with expanded application-side security controls. The timing coincidence is symptomatic: the security infrastructure market is responding to the growing frequency of attacks.
From the standpoint of benefit distribution, security solution providers win—specifically Chainlink with its CCIP, as well as auditing and insurance protocols in DeFi. Centralized exchanges with hybrid architectures, as well as protocols positioning themselves as fully censorship-resistant, lose: the reputational costs for THORChain in the institutional segment could be significant. The restaking sector, which according to CoinDesk is barely profitable even now, faces added pressure: incidents of this scale increase the due diligence requirements from liquidity providers.
The immediate impact on the market is moderate but directional. DeFi tokens tied to cross-chain liquidity and bridges show increased volatility in the short term. THORChain’s native token RUNE is under two-sided pressure: on one hand, the protocol confirms its functionality; on the other, it draws unwanted attention from regulators. Bitcoin in this context is the beneficiary: the hacker converted funds into BTC, indirectly underscoring its role as the ultimate safe-haven asset even within illicit operations. Overall sentiment in the DeFi sector is shifting toward protective stances.
A positive scenario would play out if the incident catalyzes adoption of industry standards for crisis coordination between protocols—so to speak, “allowlists” for emergency blocking of clearly criminal transactions. This would require voluntary coordination, precedents for which already exist in TradFi. Under such developments, DeFi infrastructure would gain additional institutional legitimacy, and Chainlink CCIP and similar solutions would effectively become the standard. The baseline scenario assumes tightening regulatory pressure on cross-chain protocols in the US and EU, a gradual decrease in liquidity in the anonymous swap segment, and an increase in the premium for audited, compliant DeFi solutions. The negative scenario is the introduction of forced sanctions against THORChain analogous to Tornado Cash, creating a precedent for regulatory action against any censorship-resistant protocol and triggering a chain reaction of liquidity outflows across the entire sector.
The key risks over the next few weeks are concentrated in several areas. First, possible OFAC sanctions actions against addresses or protocols related to fund withdrawals. Second, Bitget’s response: if the exchange initiates legal action or international pressure on THORChain’s key operators, this creates a precedent for liability for node providers of decentralized protocols. Third, the amount of funds that has not yet been moved: $382 million out of $388 are still in the process of laundering or storage, meaning the incident stream will continue. Liquidity volumes on THORChain, as well as regulatory statements from the SEC and FinCEN, should be closely monitored over the next two to three weeks.
The conclusion is unambiguous: the DeFi industry has again found itself facing a fundamental contradiction between technological idealism and operational reality. The attack on Bitget is not an anomaly, but a test of the system’s maturity. The market is starting to value not maximum decentralization, but the optimal combination of resilience and manageability. Protocols and exchanges that can offer this balance will gain an advantage in the next institutional cycle.
The material is for analytical purposes only and does not constitute an investment recommendation.