Particle.news

THORChain Refuses To Block Bitget Hacker as Millions Convert to Bitcoin

The decision sharpens a dispute over whether cross‑chain networks with validator‑controlled signing can or should stop known stolen funds from moving between blockchains.

Overview

  • Bitget said a Sept. 24 security breach moved about $387.5–388 million to attacker‑controlled addresses after the attacker abused a third‑party security product to forge withdrawal commands.
  • THORChain declined Bitget’s formal request to refuse service to listed attacker addresses, saying its emergency halts protect the protocol and do not provide a mechanism to freeze individual wallets or swaps.
  • On‑chain analysis found a wallet linked to the attacker executed roughly 27 swaps that converted about 2,390 ETH (≈$6.3 million) into 75.2 BTC through THORChain as investigators tracked the flows.
  • Bitget has begun phased withdrawal resumptions, reopened BTC withdrawals on Sept. 28, is using its Protection Fund to cover losses, and has launched 5% recovery bounties while Mandiant and SlowMist help trace funds.
  • Security firms such as GoPlus say THORChain’s threshold signature (GG20/TSS) vaults and its Mimir voting parameters give node operators practical control to halt activity, a claim THORChain supporters dispute and one that raises regulatory and governance questions.