Overview
- Bitget said a Sept. 24 security breach moved about $387.5–388 million to attacker‑controlled addresses after the attacker abused a third‑party security product to forge withdrawal commands.
- THORChain declined Bitget’s formal request to refuse service to listed attacker addresses, saying its emergency halts protect the protocol and do not provide a mechanism to freeze individual wallets or swaps.
- On‑chain analysis found a wallet linked to the attacker executed roughly 27 swaps that converted about 2,390 ETH (≈$6.3 million) into 75.2 BTC through THORChain as investigators tracked the flows.
- Bitget has begun phased withdrawal resumptions, reopened BTC withdrawals on Sept. 28, is using its Protection Fund to cover losses, and has launched 5% recovery bounties while Mandiant and SlowMist help trace funds.
- Security firms such as GoPlus say THORChain’s threshold signature (GG20/TSS) vaults and its Mimir voting parameters give node operators practical control to halt activity, a claim THORChain supporters dispute and one that raises regulatory and governance questions.