THORChain Rejects Bitget Request to Block Hacker Addresses
THORChain has declined a request from Bitget to block addresses linked to a $388 million hack, as the attacker successfully swapped $6.3 million in ether for bitcoin through the protocol.

A wallet associated with the recent Bitget security breach moved approximately 2,390 ether, valued at $6.3 million, into 75.2 bitcoin on Monday using the THORChain network. The transactions occurred despite public calls from Bitget for the protocol to blacklist the attacker's addresses.
Transaction records show 27 successful swaps executed between 03:55 and 06:23 UTC on Monday. Most of these orders were processed in batches of 100 ether, with all resulting bitcoin payouts directed to a single address. Four additional swaps involving 400 ether were marked as pending.
Bitget, which suffered a $388 million loss on September 24, had publicly requested that THORChain refuse service to the identified attacker addresses. Bitget CEO Gracy Chen stated on X that decentralization should not serve as a shield for stolen funds and offered a 5 percent bounty for efforts to recover or freeze the assets.
THORChain responded by clarifying that its emergency controls are designed for protocol-wide security rather than selective address blocking. The project stated that while it can halt network activity or restrict specific blockchains, it cannot freeze individual transactions or addresses.
The protocol previously utilized its emergency shutdown mechanism in May following a $10.7 million exploit of its own vaults. Trading was suspended for approximately five weeks during that incident while developers addressed the vulnerability. THORChain noted that the addresses involved in that exploit were never blacklisted.
The attacker encountered some friction during Monday's activity, as two 100 ether orders were only partially filled after failing to meet specified minimum price requirements, resulting in 114 ether being returned to the sender.



