THORChain and Stolen Funds: The Industry Still Needs Answers
After last year’s $1.46 billion Bybit hack, nearly $1.2 billion in stolen assets was reportedly routed through THORChain as the attackers moved funds across chains.
Now, after another major security breach at Bitget, the same pattern is appearing again: funds tied to the Bitget Exploiter are being sent into THORChain for swaps and cross-chain transfers.
The issue is no longer whether THORChain “knows” these funds are linked to hackers.
The attacker addresses have already been publicly flagged. Exchanges, blockchain security firms, AML teams, and the wider crypto industry are already tracking them.
The real question is this:
If a protocol knows that funds came from a publicly identified major hack and still processes large-scale cross-chain swaps, how should the industry treat that under the banner of “decentralization”?
Decentralization should not become a catch-all excuse for handling known stolen money.
If, after every major crypto hack, attackers can keep using THORChain as a bridge from ETH to BTC, BNB to BTC, and across other networks, the industry has to ask a harder question:
What responsibility should THORChain carry when it continues to move funds that are already known to be stolen?
$RUNE $BTC
After last year’s $1.46 billion Bybit hack, nearly $1.2 billion in stolen assets was reportedly routed through THORChain as the attackers moved funds across chains.
Now, after another major security breach at Bitget, the same pattern is appearing again: funds tied to the Bitget Exploiter are being sent into THORChain for swaps and cross-chain transfers.
The issue is no longer whether THORChain “knows” these funds are linked to hackers.
The attacker addresses have already been publicly flagged. Exchanges, blockchain security firms, AML teams, and the wider crypto industry are already tracking them.
The real question is this:
If a protocol knows that funds came from a publicly identified major hack and still processes large-scale cross-chain swaps, how should the industry treat that under the banner of “decentralization”?
Decentralization should not become a catch-all excuse for handling known stolen money.
If, after every major crypto hack, attackers can keep using THORChain as a bridge from ETH to BTC, BNB to BTC, and across other networks, the industry has to ask a harder question:
What responsibility should THORChain carry when it continues to move funds that are already known to be stolen?
$RUNE $BTC