Bitget CEO criticizes THORChain for inconsistent response to hacks

3 hours ago 3

Bitget CEO Gracy Chen isn’t buying THORChain’s decentralization defense. After the exchange lost an estimated $387.5 million in a September 24 security breach, Chen asked THORChain to block the addresses funneling stolen funds through its cross-chain protocol. THORChain said no, citing its permissionless design.

The hack and the ask

The breach hit Bitget on September 24, initially estimated at $351.6 million before investigators traced additional unauthorized transfers across Ethereum, XRP Ledger, Zcash, and TRON. The revised total landed at roughly $387.5 million.

Two days later, on September 26, Chen formally requested that THORChain block the attacker’s addresses. The protocol declined on the same day, framing its refusal as a principled stand for decentralization.

The 39-day problem

In May 2026, THORChain suffered its own exploit. Attackers drained approximately $10.7 million from the protocol’s vaults. THORChain’s response was to halt operations entirely for roughly 39 days while the team addressed the vulnerability and recovered.

Chen seized on that contradiction. If THORChain can shut down for over a month when its own funds are at risk, then citing decentralization as the reason for not blocking addresses linked to a $387.5 million theft starts to look less like principle and more like convenience.

Stolen funds kept flowing

While the debate played out, the attacker wasn’t waiting around. Stolen funds continued moving through THORChain’s infrastructure with notable volume. One tracked swap involved approximately $6.3 million in ETH exchanged for around 75.2 BTC.

Chen has linked the attack to patterns associated with North Korean cyber operations, though law enforcement investigations remain ongoing without confirmed attribution.

The market’s strange response

THORChain’s native RUNE token saw price increases in the days following the incident. Higher trading volumes driven by the controversy and the sheer throughput of stolen assets being swapped through the protocol appeared to boost market activity.

Regulatory pressure likely to follow

This incident arrives at a moment when regulators globally are already sharpening their focus on cross-chain protocols and their role in facilitating illicit fund flows. The Bybit hack earlier in the cycle drew similar attention to THORChain’s role as a swap venue for stolen assets.

Chen’s public criticism adds another data point that regulators can reference when building frameworks around DeFi accountability. If protocols can demonstrate selective intervention capabilities, it becomes harder to argue they’re purely neutral infrastructure immune to compliance obligations.

Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article