Particle.news

THORChain Says It Couldn’t Quickly Block Bitget Hacker and Defends Protocol Neutrality

Co‑founder Chad Barraford says validator voting and pooled signing make fast, targeted freezes impractical without redesigning the network.

Overview

  • Late September 2026, attackers stole about $387.5 million from exchange Bitget and portions of the proceeds were routed through THORChain, prompting Bitget to ask the protocol to refuse service to attacker addresses.
  • THORChain declined to block the addresses and the project retired selective address blacklisting in February 2025, framing that choice as a neutrality policy against singling out wallets.
  • Barraford told interviewers on October 5–6 that the protocol has tools such as MakePause, which can pause a chain for roughly 720 blocks (about an hour), but reaching the two‑thirds validator votes needed for permanent changes typically takes days and can take up to two weeks.
  • Critics say THORChain’s threshold signature scheme pools signing authority over vaults and creates a different custody and censorship risk profile than Bitcoin or Ethereum, making the protocol more exposed to questions about who can stop transactions.
  • The debate highlights a tradeoff for users and exchanges between faster, centralized controls that can block laundering and THORChain’s current design that favors broad validator consensus; past incidents like ThorFi and ShapeShift show quicker centralized responses can limit laundering but require different governance choices.