Edited by Wu Blockchain, Grok, and others
On September 24, approximately $387.5 million was drained from Bitget's hot and warm wallets. Some of the funds subsequently began moving across chains. BNB, TRX, and later XRP were split into smaller amounts, routed through THORChain, and swapped for bitcoin.
According to Bitget, its private keys were not compromised, and its cold wallets were unaffected. Instead, the attackers breached the backend of its wallet infrastructure and manipulated transaction data, causing the exchange's own authorization and signing process to approve the transfers. The attack was detected at 18:31 UTC on September 24, but large-scale outflows continued until approximately 21:23, nearly three hours later. Some industry observers compared the incident with the 2025 Bybit hack: in that case, the signing interface was compromised; in this case, backend data was manipulated. The outcome was the same: the system signed transactions that differed from what it believed it was authorizing. Bitget said the attack methods strongly suggested the involvement of a North Korea-linked threat cluster.
Most of the stolen funds initially remained dormant. According to AMLBot's tracking on September 25 and 26, approximately 88% of the proceeds were sitting in inactive addresses. These included around 68,300 ETH spread across eight wallets on Ethereum mainnet, as well as substantial untouched holdings of XRP and ZEC. The assets actively moving were BNB, TRX, and some XRP. The objective was clear: convert assets more susceptible to freezing into native bitcoin.
THORChain served as part of that conversion process. Bitquery estimated that, by the morning of September 26, the swaps it could attribute had yielded approximately 126.71 BTC, worth about $10.6 million. Of that total, BNB swaps through THORChain produced approximately 51.26 BTC, while TRX routed to Ethereum through a bridge and then into THORChain produced approximately 48.05 BTC. Chainflip, Bridgers, and NEAR Intents also appeared in the fund flows during the same period. On September 26, AMLBot traced another transaction involving approximately 4 BTC: TRX was converted into USDT, bridged to Ethereum, and then swapped for BTC through THORChain before entering Wasabi CoinJoin. In other words, THORChain was not the final destination. It was an intermediate step in converting stolen assets from multiple chains into bitcoin.
Past incidents resurfaced as well. MistTrack said that, following last year's approximately $1.46 billion Bybit hack, nearly $1.2 billion in stolen funds passed through THORChain during cross-chain transfers. This time, the Bitget attackers' addresses had already been made public and were being monitored by security firms and exchanges, yet the funds were once again entering the same protocol for conversion.
On September 26, Bitget CEO Gracy Chen publicly called out THORChain. She said the attackers' addresses had been disclosed and remained under continuous monitoring, and formally requested that THORChain deny service to those addresses. "Decentralization is a design principle, not a shield for facilitating the movement of known stolen funds. The entire industry is watching."
THORChain's official response was brief. It expressed deep sorrow over the incident, then said that, like Bitcoin, Ethereum, and BNB Chain, it was decentralized and permissionless. It posed a question in return: What responsibility should Bitcoin, Ethereum, and BNB Chain bear when processing known stolen funds?
OKX founder Star rejected that comparison. His first argument concerned the mechanism: THORChain uses a threshold signature scheme, or TSS, under which a selected validator set collectively controls the underlying assets held in its vaults. Once the signing threshold is met, those assets can be moved. From a custody perspective, he argued, THORChain is an intermediary between users and native blockchains, rather than a base-layer consensus network like Bitcoin or Ethereum. "Distributing an intermediary across many participants does not stop it from being an intermediary."
His second argument concerned precedent. In May this year, approximately $10.7 million was stolen from THORChain's own vaults. Nodes quickly halted the network, which remained offline for roughly 39 days. Star's point was that THORChain could stop when its own funds were stolen, but claimed it could not when someone else's funds were involved. If it can halt, it is not Bitcoin. Bitcoin cannot be halted. THORChain can; this time, it chose not to.
The criticism broadly followed these lines. MistTrack and Bitget wanted service denied to the attackers. Star challenged THORChain's characterization of itself, pointing to both its collective control over assets and its record of halting the network. Within the community, the 39-day shutdown became the most frequently repeated point. As one comment put it: when your funds are stolen, you pull the plug; when Bitget's funds are stolen, you invoke permissionlessness.
The other side rejected the characterization that THORChain was "helping hackers launder money." Its arguments were similarly focused. There are no accounts at the protocol layer: anyone can send assets to a vault, and if the memo is correctly formatted, nodes process the outbound transaction according to the rules. Requiring service to be denied would mean requiring validators to censor a set of addresses. Who determines the list? What standard of evidence applies? What happens with the next transaction? Those questions remain unanswered. Others noted that the stolen funds also passed through Uniswap, 1inch, Chainflip, and FixedFloat, rather than THORChain alone. In their view, the root cause was the compromise of the exchange's hot-wallet signing process, and a downstream, open protocol should not be singled out for blame.
Another distinction is often blurred: the protocol and its frontends are not the same thing. Some participants in the discussion noted that THORChain had previously said address screening could be implemented at the official interface while the underlying protocol remained permissionless. If Bitget was asking for signing to be stopped at the protocol layer, that would be different from blocking access through an interface. Supporters argued that conflating these two layers amounted to using the outcome of the hack to justify censorship.
Both sides ultimately ran up against the same technical fact: THORChain's outbound transactions must be signed by validators using threshold signatures. One side argued that transactions permitted by the rules should be signed. The other argued that THORChain had already demonstrated its ability to coordinate a halt, making this a question of willingness rather than capability.
What Exactly Is THORChain?
At a Cosmos event in Berlin in 2019, Australian John-Paul Thorbjornsen, known as JP Thor, and American developer Chad Barraford built a demonstrable prototype for cross-chain swaps. RUNE was subsequently issued, while the official mainnet launch did not come until 2022. In its early years, the project consistently maintained that it had no founders, only contributors. JP himself drove development for nearly six years through a fictional persona, "Leena," before revealing his identity in 2024. Following a series of hacks in 2021, the U.S. company Nine Realms took over development and operations and remained the principal team doing that work for an extended period.
THORChain enables cross-chain swaps of native assets. A user sends assets on Chain A to a vault address on that chain, with a transaction memo specifying the destination chain, target asset, and recipient address. The protocol executes the swap internally through liquidity pools, then sends actual native assets from a vault on the destination chain. A user swapping BTC for ETH receives ETH on Ethereum. For attackers, the appeal is straightforward: ETH, BNB, TRX, and XRP can be converted into bitcoin without passing through an exchange that requires KYC.
RUNE is the settlement asset. Every pool pairs an asset with RUNE. A swap between two non-RUNE assets therefore involves two underlying steps: first into RUNE, then from RUNE into the target asset. Users do not need to hold RUNE themselves. Funds are held in vaults across the supported chains rather than by a single operator. A vault's private key is never assembled in full; instead, nodes collectively control it through distributed key shares using TSS. No single node can take the funds. An outbound transfer requires signatures from approximately two-thirds of the nodes assigned to that vault. Nodes must bond RUNE to join the validator set, whose membership rotates. Misconduct can result in the bonded assets being slashed.
THORChain is therefore neither a conventional AMM nor Bitcoin. From the user's perspective, it functions as a permissionless swap service: no account is required, and assets can simply be sent to a public address. From the asset-custody perspective, however, a group of participants does collectively hold native assets across multiple chains. This is the layer Star was referring to when he argued that the intermediary still exists. THORChain's own position is that there is no company to receive a delisting demand and that the protocol merely checks whether transactions comply with its rules. The May shutdown demonstrated that the network can be paused when nodes coordinate. These two descriptions can both be true, which is why the dispute persists.
Several developments appear likely from here.
First, the protocol is unlikely to change its rules specifically for this set of addresses. Its official response has already redirected the question of responsibility toward Bitcoin and Ethereum. Introducing a protocol-level blacklist would amount to conceding that THORChain is not the kind of infrastructure it has long claimed to be. A more likely outcome is that frontends, aggregators, and wallets introduce their own restrictions while the underlying protocol continues operating.
Second, pressure will fall on the nodes, rather than on statements published by the project. Someone must sign outbound transactions. If more institutions substantiate the alleged North Korean connection, validators could face sanctions and enforcement risks, rather than merely public criticism. Nodes could choose to continue signing, delay signing, or decline to cooperate in outbound transfers. That would not require a code change, but it would require enough members of the validator set to take the same position. May's events already demonstrated that such coordination is possible.
Third, the funds will not stop at THORChain. CoinJoin activity has already been observed. As scrutiny of THORChain intensifies, the attackers are likely to split transactions into smaller amounts or switch to channels such as Chainflip before moving into mixing services. Tracing will continue, but freezing the funds will become increasingly difficult. The bulk of the ETH and most of the XRP remain dormant for now. Those holdings will be the focus of the next phase.
Fourth, regulators and exchanges are likely to take a firmer stance on claims of cross-chain neutrality. First Bybit, now Bitget: with the same channel appearing in publicly documented flows of stolen funds twice, centralized exchanges, blockchain analytics firms, and authorities in some jurisdictions will find it increasingly difficult to treat it as merely a neutral technology. The DeFi side, in turn, will continue to insist that the first question should be why an exchange's own signing process could be used to drain hundreds of millions of dollars.
Follow us
Twitter: https://twitter.com/WuBlockchain
Telegram: https://t.me/wublockchainenglish
