×

Bitget Breach: THORChain Rejects Fund-Blocking Request as $6M Moves to BTC

Bitget Breach: THORChain Rejects Fund-Blocking Request as $6M Moves to BTC

The Bitget hacker moved roughly $6.3 million in ether into bitcoin through THORChain on Monday, despite Bitget’s request that the cross-chain network block wallets connected to the $387.5 million theft.

CoinDesk’s examination of THORChain’s public transaction records found 27 completed swaps involving about 2,390 ETH and 75.2 BTC. The BTC generated through those transactions was sent to a single wallet. Four more swaps totaling 400 ETH were still pending in the records reviewed.

The transactions took place between roughly 03:55 and 06:23 UTC from an Ethereum wallet that Lookonchain had identified as part of the attacker’s activity. Most orders were submitted in batches of approximately 100 ETH, worth about $265,000 each.

Stolen ETH Converted Through THORChain

THORChain enables cryptocurrency swaps between different blockchains without requiring users to use a centralized exchange.

This allows someone holding stolen ETH to exchange it for BTC and direct the proceeds to another wallet without first interacting with a centralized platform that could potentially freeze the assets. The transactions remain visible on public blockchains, meaning investigators can still trace the movement of funds.

Bitget was breached on September 24, when an attacker stole approximately $388 million after bypassing protections around the exchange’s wallets.

The exchange has said it located and fixed the underlying vulnerability, although it has not publicly explained how the attacker managed to gain access.

Bitget Requests a Block on Attacker Wallets

Bitget released addresses linked to the hacker and offered a 5% bounty for qualifying efforts to freeze or recover the stolen cryptocurrency.

As the attacker began using other services to move the assets, Bitget CEO Gracy Chen asked THORChain to stop processing transactions from those addresses.

Chen said the wallets were publicly identified and under active monitoring. She urged THORChain to refuse transactions involving the addresses, arguing that decentralization should not prevent action against known stolen funds.

THORChain responded Monday by distinguishing its emergency shutdown mechanisms from selective wallet restrictions.

The protocol said a network halt is designed to protect THORChain during a security incident and is not intended to freeze individual assets or stop a particular user’s swap.

Emergency Measures Would Affect Legitimate Transactions

THORChain’s documentation describes controls that can suspend swaps across the network or restrict activity involving an individual blockchain.

For example, operators can halt transactions involving Ethereum. Such a move would also disrupt legitimate users relying on the same cross-chain route.

The network activated similar controls in May after an attacker stole approximately $10.7 million from a THORChain vault used to hold assets supporting swaps.

Trading remained suspended while developers investigated and fixed the vulnerability, with activity restarting on June 22 after around five weeks.

THORChain said the wallets linked to that incident were never blacklisted. The shutdown was instead intended to contain a direct threat to the protocol, while Bitget’s request concerns funds stolen from an outside exchange.

Hacker Hits Execution Limits

Not every swap attempted by the attacker was completed successfully.

Two separate orders for 100 ETH were only partially filled because some portions failed to meet their minimum price conditions. Approximately 114 ETH was returned to the wallet that initiated the transactions.

The episode shows how public blockchain tracking can coexist with limited intervention capabilities. Investigators can follow funds as they move through decentralized protocols, but those protocols may not offer the address-specific freezing tools available to centralized exchanges.

Share this content:

Copyright © 2025 CoinsNewz