BLOCKCHAIN AI.NEWS

Infrastructure

THORChain Says It Never Blacklisted the Thief Who Took Its Own $10.7 Million

Bitget asked the cross-chain protocol to refuse service to its attacker's addresses. THORChain answered that a halt is an off switch, not a filter, and offered its own May robbery as the proof. Its documentation lists about thirty halt keys. The only ones scoped to a single address are for smart contracts, not swaps.

Editorial illustration: frosted glass spheres flow through a chrome pipeline past a single gold-lit lever, toward an empty blue-lit slot further down the line
✓ Reported first by crypto.news (Sep 27) and again (Sep 28) · Statements read in full from Gracy Chen, GoPlus Security, Michael Perklin and THORChain · Halt controls from THORChain's developer docs, node emergency procedures and Exploit Report #1 · FBI notice I-022625-PSA

On September 26, two days after attackers moved about $387.5 million out of Bitget's wallets, chief executive Gracy Chen made a public request of THORChain. "Our attacker addresses are publicly listed and actively tracked," she wrote. "We are formally asking @THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds."

THORChain's account answered at 06:36 UTC on September 28. "A halt is not a selective freeze of specific funds or an individual swap," it said. Then it offered its own robbery as evidence: "During the May 2026 exploit that resulted in $10.7M stolen from the liquidity pools, the attackers addresses were never blacklisted and therefore never prevented from swapping on THORChain." The protocol, it added, "is permissionless and doesn't censor by design."

In other words, the network that would not filter Bitget's thief says it did not filter its own.

What Bitget is tracing

Bitget's incident update puts the confirmed total at approximately $387.5 million, up from an initial $351.6 million after Zcash and TRON transfers were added to the count. The exchange says the revision reflects better accounting and not further theft.

How much of that has gone through THORChain is a matter of whose tracing you read. AMLBot followed one route from a Bitget-linked TRON wallet: TRX to USDT, across to Ethereum, into roughly 145 ETH, "then sent through @THORChain to ~4.59 BTC," of which about 4 BTC entered a Wasabi CoinJoin round. GoPlus Security's figures are far larger: about 101.5 BTC, which it values near $8.5 million, already out through THORChain, and about 27.63 million XRP, near $43 million, "mid-swap into BTC." Neither Bitget nor THORChain has confirmed those numbers. Circle and Tether had frozen about $318,000 in stablecoins as of September 26, crypto.news reported.

The off switch is documented

GoPlus's argument is that THORChain is not built like the base layers it compares itself to. Swapped funds sit in vaults controlled jointly by the active node set, and every outbound payment has to be produced by those nodes through a threshold signature. "Releasing stolen funds is an active signing event," the firm wrote, "not 'neutral ordering we cannot stop.'"

The controls it cites are in THORChain's own manuals. The emergency procedures for node operators describe make pause as "the big red button that stops everything," good for 720 blocks, about an hour, and carry the motto "Halt Earn, Halt Often!" The developer documentation lists halts for trading, signing and chain observation, per chain or network-wide.

THORChain's own report on the May 15 exploit shows them in use. Automatic solvency checks halted signing and trading on six chains within about 52 minutes. Then "approximately 18-20 nodes stacked pauses," and node votes halted trading, signing, chain observation and churning. Churning was paused, the report says, "to prevent the malicious node from exiting the network and to block any additional malicious nodes from entering." Trading stayed off for more than a month and resumed on June 23, according to crypto.news, so for that stretch nobody was swapping, blacklisted or not.

The same report says operational settings such as a trading or signing halt "require only 3 nodes to activate," with four able to overturn and five to reinstate. The node-operator page says of halt votes that "a supermajority is required." The two documents do not agree, and THORChain has not said which governs.

What THORChain's documents say can be stopped

ControlScopeTrigger
make pauseWhole network, 720 blocks, stackableOne node, once per churn cycle
HALTSIGNING<CHAIN>Outbound signing on one chain; payments queueNode votes
HALT<CHAIN>TRADINGSwaps on one chain; refunds onlyNode votes
HALTTRADINGSwaps on every chainNode votes
HaltWasmDeployer-<ADDRESS>All App Layer contracts deployed by one addressNode votes
Refuse a swap by sender or destinationOne addressNot in the documented list
Sources: THORChain developer documentation, emergency procedures and Exploit Report #1. The last row is the Desk's reading of the published halt list, not a statement by THORChain about its code.

So both sides are describing the same machine accurately. The documented halts work on chains and on the whole network. The one family of keys that names an address applies to smart contracts on THORChain's App Layer, by deployer or by contract. Nothing in the published list refuses a swap because of where it came from or where it is going. What GoPlus actually proposes is the blunter tool: "a per-chain halt / outbound reject" on attributed addresses, which it says "fits THORChain's own 'funds-at-risk' emergency framework." The emergency page defines that category as a vulnerability or attack that "threatens the security of funds in liquidity pools/vaults or anything that poses an existential risk to the protocol." Whether someone else's stolen funds passing through count is the entire disagreement.

The case for leaving it on

THORChain's statement pointed to a reply by Michael Perklin, whom crypto.news describes as a longtime crypto security executive and THORChain supporter. He called the GoPlus comparison "cherry picking at best, a false equivalency at worst." Bitcoin miners, Ethereum validators and THORChain node operators can all unplug, he wrote: "In all 3, there is no active choice to sign, only an active choice to turn off the machine." They don't, he argued, because stopping hundreds of criminal transactions would also stop millions of legal ones.

Three validators tried it in 2025

This argument has been run before, with larger sums. After the February 2025 Bybit theft, the FBI attributed the roughly $1.5 billion loss to North Korea and encouraged "RPC node operators, exchanges, bridges, blockchain analytics firms, DeFi services, and other virtual asset service providers to block transactions with or derived from" a published list of addresses.

According to crypto.news's reporting at the time, three validators voted to halt Ethereum trading, and developer Oleg Petrov confirmed the vote was reverted "within minutes." Core developer Pluto announced his departure without giving a reason. Founder John-Paul Thorbjornsen said none of the listed addresses had ever interacted with THORChain, and drew a line: "I will support my nodes to run a static deny list on OFAC/FBI lists if they feel comfortable, but I will not support a non-authority 3rd party dynamically updating the list at the protocol level."

What that episode earned THORChain depends on the counter. Crypto.news reported $2.91 billion in volume and about $3 million in fees over five days. GoPlus now cites roughly $5.9 billion and $5.5 million for the ten days it says the laundering took, figures crypto.news notes have not been confirmed in THORChain's disclosures. MistTrack, in the post Chen was quoting, says nearly $1.2 billion of the stolen funds was "reportedly traced" through the protocol. These measure different things over different periods and should not be added together or compared directly.

The list that doesn't exist yet

Thorbjornsen's 2025 condition was an official list. For Bitget there isn't one. Bitget has not publicly confirmed who attacked it; crypto.news reported that the exchange described preliminary IP and VPN similarities to earlier North Korean activity, with attribution unconfirmed. The Desk found no FBI or OFAC notice naming Bitget attacker addresses as of publication. The addresses Chen wants refused come from Bitget and from private tracing firms, which is the kind of source Thorbjornsen said he would not accept.

GoPlus's closing demand is for action on "FBI- and OFAC-attributed DPRK addresses and funds." That describes Bybit. It does not yet describe Bitget.

The Take

THORChain deserves some credit for consistency. A protocol that declined to blacklist the person who robbed it is not applying one rule to itself and another to Bitget. But its statement blurs "cannot" and "will not." The documents show a network that can stop a chain's outbound payments by node vote, that has done so, and that once paused churning to keep a malicious node from leaving. There is no address filter for swaps because node operators have not built one, and when three of them reached for the blunt version in 2025 they were overruled in minutes. That is a decision, and it should be defended as one. The critics have their own gap. Until a government publishes a list, they are asking THORChain to act on private labels, and the founder told them nineteen months ago what he thought of that. If the FBI names Bitget's attacker, the excuse he left himself runs out.

More on the subject