Invest1 publisher3 min readPublished
Bitget presses THORChain to cut off the wallets holding its stolen $387.5 million
Bitget CEO Gracy Chen publicly asked THORChain to refuse service to the wallets that took $387.5 million, after Circle and Tether stopped nearly $318,000. Much of the rest now depends on a no-KYC swap protocol that has declined to block stolen funds in earlier hacks, including its own.
The Investor · Invest desk

What happened
- Bitget CEO Gracy Chen wrote on X early Saturday that the exchange is formally asking THORChain to refuse service to the attacker addresses.
- MistTrack said on September 25 that nearly $1.2 billion of the Bybit loot had moved through THORChain.
- Bitget is offering 5% of any funds frozen and 5% of any recovered, excluding actions taken under court orders or law-enforcement requests.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure With disclosed issuer freezes at about 0.08% of the loss, nearly all of the $387.5 million can still move through whichever swap route the attacker picks.
- constraint A protocol of 95 nodes with no admin key or controlling multisig has no single party able to grant Chen's request, so a freeze would need its operators to break with past practice.
- cost Bitget's bounty commits up to about $19.4 million to parties who act without being compelled, since freezes won through courts or police pay nothing.
A day after the breach, Circle and Tether had stopped nearly $318,000 of stablecoin movement tied to it [1][4]. Against $387.5 million, that comes to about 0.08% [2]. The haul also includes AVAX, BNB, ETH, TRX, XRP and ZEC, and Bitget says the assets sit at primary receiving wallets, with separate addresses for the XRP, Zcash and TRON holdings [3]. The loss estimate itself grew by $35.9 million once the Zcash and TRON transfers were counted [1][2].
Chen took the rest of the problem to THORChain, the permissionless cross-chain swap protocol that runs no know-your-customer checks [7]. "We are formally asking @THORChain to refuse service to these addresses," she wrote on X early Saturday [5]. She warned that "the industry is watching," and argued the protocol should not use "a design principle" to escape responsibility while "known stolen funds" pass through it [6].
The record she is arguing against is specific. In May, TRM Labs called THORChain "the bridge of choice" for laundering North Korea's largest heists, citing the roughly $1.5 billion Bybit theft of February 2025 and the nearly $300 million KelpDAO theft [10]. MistTrack said on September 25 that nearly $1.2 billion of the Bybit loot moved through THORChain, about 80% of the total [12][4]. The protocol did not freeze transactions even after its own $10.7 million vault exploit earlier this year [9].
Earlier Cryptopolitan reporting described THORChain as closer to code than to a company [18]. By the protocol's own account, it runs on 95 globally distributed nodes with no admin key and no controlling multisig [8], so no single signer can grant Chen's request. TRM noted that it "has consistently refused to block illicit activity" [11].
If the node set blocks the listed addresses, it breaks with that record, including the non-freeze on its own loss, and Bitget's letter becomes a template other exchanges can copy. If the attacker swaps through THORChain anyway, recovery of the non-stablecoin legs falls back on the bounty and on freezes at other venues. The attacker may also just hold. The funds are reported parked [3], and in that case the letter goes on the record before any swap happens. I think the second outcome is the likeliest, given what TRM and MistTrack describe. The case against that view is that Bitget has published a live tracing dashboard and an attacker-address API [17], so any node that serves these wallets does it with the list in hand. A Bitget update showing frozen totals far above the stablecoin figure, or THORChain nodes refusing the addresses, would show the view wrong.
Bitget's own money is going to cooperation it cannot compel. The bounty pays 5% of funds frozen and 5% of funds recovered, routed partly through Bybit's LazarusBounty channel [13], and it excludes anything done under a court order or a law-enforcement request [14]. On the full $387.5 million, 5% is about $19.4 million [3]. The reported terms do not say whether a dollar that is frozen and later returned pays out twice. Bitget says industry partners have already frozen some assets [14], and it is restarting withdrawals in phases, slower than usual because the incident spans several chains and tokens [15].
What to watch
- Any movement out of the parked receiving wallets, especially the Ethereum-side 0x770b...63ee address, onto a cross-chain route.
- First payouts under the 5% bounty, and whether they run through Bybit's LazarusBounty channel.
- Any further revision to the $387.5 million figure, which already rose once when Zcash and TRON transfers were counted.