Particle.news

Bitget Asks THORChain to Block Hacker Wallets, Protocol Refuses

The dispute raises whether THORChain’s threshold‑signature vaults or low‑threshold emergency votes give validator committees effective custody or the power to halt swaps.

Overview

  • Bitget, which suffered an estimated $387.5 million breach on Thursday, Sept. 24, formally asked THORChain to refuse service to addresses tied to the attacker and THORChain declined, saying its emergency halt tools protect the protocol but do not blacklist individual wallets.
  • Security firm GoPlus published traced flows that it says show roughly 101.5 BTC and about 27.63 million XRP moving through THORChain during the incident and independent chain analysis found swaps that converted large blocks of ETH into BTC through the protocol.
  • THORChain uses GG20/threshold‑signature (TSS) vaults and an active validator set capped near 100 nodes that collectively authorize outbound transfers, and its documented emergency controls let a small number of node votes trigger pauses or Mimir parameter changes.
  • Supporters argue node operators only take part in an automated signing process and must stop their machines to halt activity, while critics say the shared signing committee and quick vote thresholds amount to distributed custody and create a real ability to block flows.
  • Bitget is restoring withdrawals in phases, offering recovery bounties and working with forensic firms such as Mandiant and SlowMist as exchanges, trackers and law enforcement continue tracing funds and observers note THORChain processed over $1 billion in suspected DPRK‑linked flows since 2023.