This Is the Second Time a Nine-Figure Hack Has Turned Into $BTC Through the Same Door The last time this exact route got used, $900 million disappeared through it too. On September 24, Bitget lost $387.5 million in a backend breach that investigators linked to North Korea-style techniques, with stolen assets spanning Ethereum, XRP Ledger, Zcash and TRON. Two days later, CEO Gracy Chen publicly asked THORChain, a decentralized cross-chain exchange, to block the attacker's already-identified wallets. THORChain refused: "A halt is not a selective freeze of specific funds or an individual swap," it said, comparing itself to Bitcoin and Ethereum. On Monday, the attacker used THORChain anyway, swapping 2,390 ETH into 75.2 $BTC, worth about $6.3 million, across 27 transactions. This isn't THORChain's first time in this position. When Bybit lost $1.4 billion in February 2025, still crypto's largest hack ever, roughly 72% of the stolen ETH, about $900 million, moved through THORChain and out into Bitcoin the same way. Security firm GoPlus argues the "can't intervene" defense doesn't hold up: THORChain's own documentation describes validator votes and chain-specific pause controls that Bitcoin and Ethereum simply don't have. THORChain's counter is consistency, not innocence: when it lost $10.7 million to its own exploit in May, it never blacklisted those addresses either. Neither side is lying. THORChain's rule really is the same for everyone, including itself. But a protocol that turns two of crypto's biggest hacks into Bitcoin isn't a coincidence, it's a routing decision. The real question isn't whether THORChain can technically intervene. It's whether "permissionless" and "the preferred getaway route into Bitcoin" can keep meaning the same thing. #BTC Price Analysis# #CMC Quest: Earn Rewards# #Macro Insights#