- Attackers from the Bitget security incident are moving stolen funds across chains using THORChain, according to SlowMist’s MistTrack platform.
- Bitget CEO Gracy Chen formally requested THORChain reject transactions from identified attacker addresses, arguing decentralization should not shield illicit fund flows.
- THORChain responded that its permissionless design mirrors Bitcoin and Ethereum, questioning how much responsibility base-layer chains bear for processing known stolen assets.
Bitget Hackers Leverage THORChain for Cross-Chain Laundering, On-Chain Data Shows
Blockchain security firm SlowMist has confirmed that addresses linked to the recent Bitget security breach are actively utilizing THORChain to bridge and exchange stolen assets across multiple networks. The firm’s on-chain tracking platform, MistTrack, reported that the attackers have initiated cross-chain transactions through the decentralized liquidity protocol, a pattern that mirrors the movement of roughly $1.2 billion in funds stolen during the Bybit exploit earlier this year. MistTrack emphasized that the attacker addresses have been publicly identified and are under active surveillance by industry participants.
Debate Intensifies Over Decentralized Protocol Accountability
The development has reignited a contentious industry debate regarding the obligations of decentralized protocols when processing proceeds from known hacks. MistTrack argued that the principle of decentralization should not serve as an automatic justification for facilitating the movement of demonstrably stolen funds. The platform called for an industry-wide discussion on the responsibility protocols like THORChain should bear in such scenarios, suggesting that technical neutrality cannot fully absolve infrastructure providers of ethical or reputational considerations when handling illicit flows at scale.
Bitget CEO Demands Protocol-Level Intervention
Following MistTrack’s disclosure, Bitget CEO Gracy Chen issued a formal appeal to THORChain, urging the protocol to reject transactions originating from the flagged addresses. Chen stated that the addresses associated with the attackers had been publicly shared and were still being actively monitored. She contended that while decentralization is a foundational design principle, it should not be seen as “a shield to facilitate the movement of stolen funds with known origins.” Her statement underscores a growing expectation among centralized exchanges that decentralized infrastructure should implement screening or blocking mechanisms for sanctioned or hack-linked addresses.
THORChain Defends Permissionless Architecture
THORChain responded to the criticism by reaffirming its commitment to a decentralized and permissionless operational model, drawing a direct parallel to base-layer networks such as Bitcoin, Ethereum, and BNB Chain. While expressing regret over the Bitget attack, the team posed a rhetorical challenge: “How much responsibility should Bitcoin, Ethereum, and $BNB Chain bear when processing known stolen funds?” The response frames the issue as a systemic characteristic of censorship-resistant networks rather than a protocol-specific failing, resisting calls for transaction-level filtering.
Why This Matters
The clash between Bitget and THORChain highlights a deepening fault line in the crypto ecosystem: the tension between the ethos of permissionless, censorship-resistant infrastructure and the practical demands of asset recovery and regulatory compliance. As cross-chain bridges become critical arteries for liquidity—and for laundering—pressure is mounting on decentralized protocols to adopt some form of on-chain screening without compromising their core architecture. The outcome of this debate could shape future standards for bridge governance, influence how regulators treat decentralized protocols, and determine whether “code is law” remains an absolute defense when stolen funds traverse public rails.
Frequently Asked Questions
What is THORChain and why are hackers using it?
THORChain is a decentralized cross-chain liquidity protocol that enables native asset swaps between blockchains without wrapped tokens. Its permissionless design allows anyone to move funds across chains—including Bitcoin, Ethereum, and BNB Chain—without KYC or centralized approval, making it attractive for laundering stolen assets.
Can THORChain technically block the hacker addresses?
THORChain’s architecture is designed to be censorship-resistant; validators process transactions based on consensus rules, not identity. Implementing an address blocklist would require a governance vote and protocol upgrade, which contradicts its permissionless ethos and could set a precedent for future interventions.
Has this happened before with other major hacks?
Yes. SlowMist’s MistTrack previously documented that a significant portion of the approximately $1.2 billion stolen in the Bybit attack was also routed through THORChain, indicating a recurring pattern of high-profile exploit proceeds flowing through the same cross-chain infrastructure.

