header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

Stolen funds from Bitget were not intercepted by THORChain, highlighting inconsistent suspension standards among decentralized protocols.

Read this article in 9 Minutes
RUNE also surged due to increased fee revenue.
TL;DR
· On September 26, Bitget CEO publicly demanded that THORChain refuse to provide services to flagged attacker addresses. THORChain responded that the protocol, like Bitcoin and Ethereum, is permissionless and should not bear censorship responsibility alone.
· The core of the dispute is whether node governance can selectively intervene. After the protocol's self-theft in May this year, the community coordinated a shutdown of 39 days within about two hours. In the 2025 Bybit case, a pause vote briefly passed and was then overturned.
· Related targets: RUNE, Bitget User Protection Fund, Bitcoin as the endpoint for converting stolen funds, and similar cross-chain liquidity protocols.


On September 26, 2026, Bitget CEO Gracy posted on X, demanding that THORChain refuse to provide services to known attacker addresses from the platform's September 24 theft. Decentralization is a design principle, not a shield to greenlight known stolen funds.


THORChain also responded, saying no, the protocol, like Bitcoin, Ethereum, and BNB Chain, is permissionless. When known stolen funds flow through these networks, they likewise cannot be required to bear censorship responsibility. But this argument is clearly not very acceptable, because when THORChain itself was stolen from, it stopped quite quickly.


Absurdly, because of the involvement of stolen funds, RUNE fees increased, which also led to a clear surge in RUNE volume.


对质当日 RUNE 成交放大四倍


On the day of the confrontation, RUNE trading volume expanded fourfold


How unwrapped cross-chain became an exit for stolen funds


THORChain allows native assets from different chains to be swapped directly in liquidity pools, without first wrapping ETH into a mapped asset. This step skips the wrapping process, and also skips the issuer behind the wrapped asset.


The consequences are direct. Circle and Tether can freeze USDC and USDT, but once stolen assets are swapped into native BTC, there is no centralized entity that can press the return key.


This is exactly the endpoint hackers want. No real-name verification, no account freezing step, pools deep enough to absorb large amounts, and XRP, ETH, and BNB can all be swapped into hard-to-recover native BTC. On-chain tracking shows that about 103 million XRP (about $157 million) has already been cashed out through THORChain, while the bulk of ETH has still not moved.


ETH 未动额仍高于已兑比特币


ETH unmoved amount still higher than redeemed Bitcoin


Each swap generates fees that flow to nodes and liquidity providers. This is why RUNE is sensitive to volume, and where the attacker's path is tied to the token price.


The TSS vault controversy: is it more like Bitcoin or more like a trading platform


THORChain's vaults operate on a threshold signature (TSS) mechanism. A group of nodes each holds a key fragment, and only when enough of them come together can funds be moved out of the pool. Once the threshold is reached, funds can be moved, with an accountable governance layer behind it.


This is where the skepticism from trading platforms and on-chain trackers lands. The protocol acts as an intermediary between users and native chains, only it has decentralized the intermediary. THORChain officially insists it is permissionless infrastructure and should not be asked to play an enforcement role, tossing the problem back to Bitcoin and Ethereum.


The victims want to intercept, the protocol wants neutrality, and third parties want accountability. The tension among these three forms the complete structure of this debate.


The key to the disagreement is that "not reviewing individual transactions by default" and "lacking the ability to review" are two different things. Node collectives could theoretically refuse to sign. The question is whether they are willing to.


Self-theft shutdown for 39 days, yet Bybit's vote was overturned


On May 15 of this year, malicious nodes exploited a threshold signature-related vulnerability to drain approximately $10.7 million from a single vault. The protocol automatically detected this and stopped signing. The community coordinated a shutdown within about two hours, and trading was suspended for 39 days until resuming on June 23.


When the protocol itself was bleeding, nodes acted quickly. The voting threshold to halt a chain is not high—3 votes to take effect, 4 votes to revoke. This is the hardest piece of evidence for judging "whether they can intercept."


The 2025 Bybit case presents another side. Of the approximately $1.46 billion in stolen funds at the time, research estimates that about $1.2 billion was swapped from ETH to BTC through THORChain, accounting for roughly 85%. Three validators voted to pause ETH transactions, and four votes overturned it within minutes. Core developer Pluto subsequently resigned. The FBI issued a notice the same day requiring virtual asset service providers to block the relevant addresses. The protocol ultimately maintained its permissionless stance.


The difference between the two instances mainly comes from governance willingness, not technical capability. As of now, nodes have not initiated a new chain-halt vote for the Bitget case.


节点只在自盗时选择停机


Nodes only choose to halt the chain when they themselves are hacked


Scale far smaller than Bybit, chain-halt vote still not initiated


The stolen amount from Bitget has been revised upward from $351.6 million to approximately $387.5 million. Although it is not on the same scale as Bybit, the amount is not the point. So far, about $157 million has been confirmed as cashed out via THORChain.


What determines the direction of the controversy is whether nodes will initiate another chain-halt vote for Bitget, and how much of the stolen funds will ultimately complete this route. The former is governance willingness, the latter is the pricing basis. For RUNE holders, short-term trading impulses and long-term compliance narrative pressure need to be calculated together on the same ledger.


Welcome to join the official BlockBeats community:

Telegram Subscription Group: https://t.me/theblockbeats

Telegram Discussion Group: https://t.me/BlockBeats_App

Official Twitter Account: https://twitter.com/BlockBeatsAsia

举报 Correction/Report
Choose Library
Add Library
Cancel
Finish
Add Library
Visible to myself only
Public
Save
Correction/Report
Submit