Invest1 publisher2 min readPublished
THORChain refuses to block Bitget-linked addresses despite pausing itself for a $10.7 million hack
THORChain turned down Bitget's request to block addresses tied to a suspected North Korean theft, though it paused its own chain over a $10.7 million hack in May. That pause showed its operators move fast when the loss is theirs. Exchanges downstream are left to screen what THORChain lets through.
The Investor · Invest desk

What happened
- Bitget CEO Gracy Chen made the request in public and said investigators had found similarities with earlier thefts, though Cointelegraph says that falls short of firm proof.
- Much of the $1.5 billion taken in the Bybit hack, which North Korean hackers are believed to have carried out, was swapped on THORChain.
- THORChain said in February 2025 that it had retired the admin key that would let it blacklist addresses, and Cointelegraph calls its present ability to do so unclear.
- RUNE, THORChain's native token, has risen 50% in a week, according to Cointelegraph.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- decision Exchanges that receive THORChain swap output have to decide whether to screen and freeze flagged funds themselves, since the protocol will not stop them at source and the funds stay traceable.
- constraint If the retired key was THORChain's only blacklist tool, honoring Bitget would take the kind of operator coordination used for the May pause, and using it once would end the claim that nobody can act.
- precedent A refusal followed by a 50% rise in RUNE tells other permissionless protocols that turning down an exchange's freeze request has so far cost their token holders nothing.
A pause halts every user at once. A blacklist stops named addresses and lets everyone else keep trading. THORChain has shown it can do the first: it coordinated to stop the chain very quickly after its own $10.7 million loss in May [7]. The second is the power it said it gave up, if the admin key it retired was the only way to do it [9]. In Cointelegraph's view, THORChain is not anywhere near as decentralized as Bitcoin or Ethereum [8].
The Bybit money that went through THORChain came from a $1.5 billion theft [5]. That theft was about 140 times the size of the May loss [13]. The operators moved fast for the smaller sum because it was their own.
Chen made her case in one line. "Decentralization is a design principle, not a shield for facilitating known stolen funds," she said [3]. Joel Valenzuela, defending the refusal, said: "If we let decentralized protocols to be bullied into setting a censorship precedent, or make it toxic to interact with permissionless protocols, then we lose to tyranny. Full stop." [11] Tay Vano, whom Cointelegraph describes as a cybersecurity expert, said the operators were "lying about the admin functionality they abuse regularly" [12].
If THORChain holds its line, token holders keep paying for the stance, and so far they are: RUNE is up 50% in a week [10]. Alternatively, the operators who paused the chain may turn out to be able to filter addresses too. In that case the refusal becomes a choice they own, and Chen's request is the public record of what they declined. Or the screening moves downstream. A THORChain swap is not a mixer, so the funds stay traceable after it [6], and the exchanges that receive the output can flag and freeze it themselves.
I think the third outcome is where the cost settles. THORChain is keeping its ability to coordinate for its own emergencies and not spending it on other people's thefts. Whichever venue receives the swapped funds pays for that choice by doing the screening. The counter-thesis is that traceability makes the refusal cheap for everyone: nothing is hidden, so the victim loses time and not much else. Cointelegraph's account reports no regulator or exchange acting against THORChain. If exchanges keep accepting THORChain output without extra checks and RUNE keeps its gain, then the neutrality costs nobody anything and the counterparty-risk argument is wrong.
What to watch
- Any regulator statement treating the routing of funds through THORChain as a sanctions or anti-money-laundering problem for the exchanges that use it.
- A THORChain disclosure, or outside evidence, showing whether its operators can still filter specific addresses after the admin key was retired in February 2025.