THORChain says it can halt the network but won’t freeze the Bitget hacker

- THORChain says its emergency network halt protects the protocol and is not a mechanism for freezing individual wallets.
- The DEX has rejected Bitget’s request to block the addresses behind a roughly $387.5 million exchange hack.
- Security firms say THORChain’s validator-controlled vaults give it more power to intervene than it admits, while supporters call that a false comparison to Bitcoin and Ethereum.
THORChain has come out to defend itself with a clarification that the emergency halt it initiated after its May 2026 $10.6 million exploit is not the same thing as the Bitget intervention request to prevent attackers from moving part of the $387.5 million stolen from the exchange through its platform.Â
The response is the latest episode in a standoff triggered by the year’s largest crypto hack after Bitget CEO Gracy Chen went public on September 26 with a formal request that THORChain refuse service to the publicly tracked attacker wallets, as Cryptopolitan reported.Â
Attackers used the same THORChain route after the Bybit hack, which was, ironically, also the largest security breach of 2025.Â
THORChain: A halt is not a freeze
THORChain defended its decision not to go through with Bitget’s request by directing attention to important context it claims is being missed.Â
A network halt is “an emergency security mechanism designed to protect the protocol,” according to THORChain, and “is not a selective freeze of specific funds or an individual swap.”Â
The DEX clarified that during the May 2026 incident, in which it lost $10.7 million to hackers, it initiated a protocol-wide shutdown to contain the incident. Even then, it did not consider blacklisting the attacker’s addresses, and it would not do it now.
Security firms poke holes at THORChain’s defenseÂ
GoPlus Security pushed back against THORChain’s defense comparing itself with base layers like Bitcoin and Ethereum, posting on September 27 that the protocol “has never been strictly decentralized” and telling it not to “enable criminals — or put the industry at risk — just to take swap fees on stolen funds.”Â
The blockchain security firm highlighted distinctions between THORChain’s threshold signature vaults and those of Bitcoin and Ethereum.Â
Longtime crypto security executive and THORChain supporter, Michael Perklin, backed up THORChain, calling out “AI slop” suspicion in the GoPlus comparison he considered “cherry picking at best, a false equivalency at worst.”Â
Perklin argued that threshold signing is an automated process, not a series of human approvals on individual transfers.
“In all 3, there is no active choice to sign, only an active choice to turn off the machine,” he wrote, comparing a THORChain node operator’s options to a Bitcoin miner or Ethereum validator powering down.Â
Shutting the infrastructure to stop criminal transactions, he argued, would stop legitimate ones at the same time. THORChain itself made a similar case, questioning what responsibility Bitcoin, Ethereum, and BNB Chain should bear when they process transactions touching known stolen assets.
Bitget is already moving on with a compensation plan
The dispute plays out against an active recovery effort. Bitget suffered its breach on September 24, with the loss later revised up from $351.6 million to $388 million after transfers on Zcash and TRON were counted.Â
Fortune reported that Chen suspects North Korean attackers exploited a backend system to make fraudulent withdrawals look legitimate, without stealing private keys. The exchange’s investigation found that the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials.
As of this report, Chen stated that Bitget had processed 9,585 BTC withdrawals across the Bitcoin and BSC networks, totaling approximately 4,098 BTC after BTC withdrawals resumed on September 28.
ETH withdrawals are scheduled to resume on September 29, USDT withdrawals on September 30, and other supported tokens, fiat and P2P services on October 2.
Bitget says cybersecurity firms Mandiant and SlowMist are assisting, and it has launched a recovery-bounty program paying up to 5% for funds frozen or recovered, plus a live dashboard to track attacker wallets.Â
The exchange also points to its Protection Fund of 5,500 BTC, worth roughly $464 million, though the hack would consume a large share of it.
If you're reading this, you’re already ahead. Stay there with our newsletter.
FAQs
How much did Bitget lose in the September 2026 hack?
Bitget confirmed that roughly $387.5 million in assets moved to attacker-controlled addresses, up from an initial estimate of $351.6 million after transfers on Zcash and TRON were counted, making it the largest crypto hack of the year to date, according to Fortune.
What did Bitget ask THORChain to do?
Bitget CEO Gracy Chen formally asked THORChain to refuse service to the publicly tracked attacker addresses, arguing that decentralization should not be used as a shield for moving known stolen funds.
Why does THORChain say it won't freeze the addresses?
THORChain says a network halt is an emergency security mechanism meant to protect the protocol itself, not a selective freeze of specific funds, and it points to its refusal to blacklist addresses after its own $10.7 million exploit in May 2026.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
















