Leadership1 publisher2 min readPublished
Bitget presses Thorchain to shut out the hackers behind its $387.5 million loss
Bitget CEO Gracy Chen asked Thorchain to refuse service to the hackers behind a theft the exchange now puts at $387.5 million. After the Bybit breach, Thorchain's validators reversed a trading halt within 30 minutes, so recovery plans have little reason to count on the protocol's help.
The Board Room · Leadership desk

What happened
- Bitget now estimates that about $387.5 million was moved to attacker-controlled addresses, up from the roughly $351 million it cited two days earlier.
- CEO Gracy Chen wrote on X on Saturday that Bitget was formally asking Thorchain to refuse service to the attacker addresses, which she said are publicly listed and tracked.
- Several reports say tens of millions of dollars in XRP went into Thorchain vaults, and another tens of millions was swapped for bitcoin and scattered across many addresses.
- Thorchain's official account replied that the protocol is permissionless like Bitcoin, Ethereum and BNB Chain, and asked what responsibility those networks bear for known stolen funds.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- precedent Thorchain's validators have already turned aside a request made with the FBI asking, so a private exchange's public plea starts with less weight behind it.
- constraint With the attacker spread across several other services, a Thorchain block would at best slow the laundering, so Bitget's recovery cannot rest on one protocol's vote.
- decision Exchanges setting breach reserves this quarter have little in this record to justify booking protocol cooperation as a recovery; funds that reach these rails are better counted as lost.
According to Bitcoin.com News, Thorchain has faced this request before, with the FBI behind it. The protocol was used to move $1.2 to $1.5 billion in stolen funds from the Bybit breach [7], roughly three to four times what Bitget says it has lost [2]. The FBI asked the industry to block DPRK-linked addresses, and three of Thorchain's validators voted to halt ETH trading [8]. Four validators reversed that half an hour later and the network kept running. A developer quit [9].
Thorchain does have its own halt powers. The protocol can halt the entire system, and its nodes can pause trading [11]. After the May 2026 GG20 exploit drained about $10.7 to $11 million from one of its vaults, operators paused the network and kept it down for weeks while they patched [12]. For a loss from its own vault of about $11 million, Thorchain stayed down for weeks. For Bybit's stolen funds, more than $1 billion, a halt on ETH trading lasted 30 minutes [7][9][12].
Chen's post argued that the principle has a limit. "Decentralization is a design principle, not a shield for facilitating known stolen funds," she wrote [3]. Replies to her thread made the skeptic's case. "Would you get mad at the highway that the bank robber used to escape?" one respondent wrote [13]. The analogy leaves out that Thorchain has operators who can close it [11]. In my view, its neutrality is a position the validators choose each time they decline to vote a halt, and Bitget's public pressure is aimed at that vote.
Even a yes from those validators would close only one route. The attacker is also reportedly moving funds through Chainflip, Uniswap, 1inch Fusion, Stargate, Across and Relay [5], seven named services counting Thorchain [3]. Some Thorchain front ends have screened sanctioned or flagged addresses for years, but that screening can be bypassed [14].
Bitget's own count changes by the day: its estimate rose by $36.5 million, about 10 percent, in the two days after the hack [1]. An exchange that books Thorchain's cooperation as a recovery line this quarter is relying on a vote that went the other way under FBI pressure.
The report does not describe any validator vote on Bitget's addresses. Bitcoin.com News judged that if Thorchain could not block the Bybit funds, or its validators chose not to, it likely will not happen this time either [15].
What to watch
- Any Thorchain validator vote to halt trading or refuse the addresses Bitget has published, and how long such a halt holds.
- Further revisions to Bitget's estimate beyond $387.5 million as the exchange traces the transfers.
- Whether any of the other services the attacker is using, such as Chainflip or Across, act on Bitget's address list.