Newsroom

Bitget CEO Urges Thorchain to Halt Stolen Fund Transfers After $387.5 Million Hack

27 September, 2026   /   News   /  AI   /   Tags:  thorchain, bitget, stolen, addresses, gracy

Bitget CEO Urges Thorchain to Halt Stolen Fund Transfers After $387.5 Million Hack

Exchange revises loss estimate upward and publicly calls on the cross-chain protocol to refuse service to attacker addresses as funds move through decentralized rails

Bitget has raised its estimate of losses from a September 24 security incident to approximately $387.5 million and formally requested that Thorchain block transactions linked to the attackers. The revised figure accounts for assets held on Zcash and TRON networks rather than any additional unauthorized movements beyond the original event.

Unauthorized transfers began at 2:31 p.m. Eastern Time from certain hot wallets. The exchange initially reported about $351.6 million affected. Assets involved include XRP, ether, Tether, Zcash, USD Coin, USDT0, Tether Gold, BNB, Avalanche and TRON tokens. Bitget has published lists of attacker-controlled addresses spanning EVM networks, the XRP Ledger, Zcash and TRON.

Funds Routed Through Multiple Protocols Including Thorchain

Attackers have been shifting the stolen assets across several platforms. Reports indicate tens of millions of dollars in XRP were deposited into Thorchain vaults, with a substantial portion already swapped into bitcoin. The bitcoin has subsequently been distributed across numerous addresses. Other venues used include Chainflip, Uniswap, 1inch Fusion, Stargate, Across and Relay.

Bitget stated that its User Protection Fund held more than $464 million at the time the incident was disclosed.

CEO Gracy Chen’s Public Appeal

Two days after the breach, Bitget CEO Gracy Chen posted on X asking Thorchain to stop serving the identified attacker addresses. She noted that the addresses are publicly listed and actively tracked.

Decentralization is a design principle, not a shield for facilitating known stolen funds. The industry is watching.
Gracy Chen, Bitget CEO

The request has drawn mixed responses in the community, with some users pointing to the permissionless nature of the protocol and questioning why similar demands were not directed at bitcoin miners or other base-layer networks.

Thorchain’s Response and Design Stance

Thorchain’s official account replied that the protocol is decentralized and permissionless in the same manner as Bitcoin, Ethereum and BNB Chain. It expressed sympathy for those affected by the exploit while asking what responsibility those networks should bear when processing funds identified as stolen.

The protocol operates through smart contracts, liquidity pools and independent node operators. Its terms of use state that network behavior is governed by code, contracts and consensus rather than any central authority capable of unilaterally approving or rejecting transactions.

Prior Incidents Shape the Debate

Thorchain previously faced pressure after the Bybit breach, during which between $1.2 billion and $1.5 billion in stolen funds passed through the network. At that time, the FBI requested blocking of certain addresses linked to North Korean actors. Three validators briefly voted to halt ether trading before four others reversed the decision within roughly 30 minutes, allowing operations to continue. One developer later departed the project over the episode.

In a separate May 2026 incident involving the GG20 exploit, which drained approximately $10.7 million to $11 million from a vault, network operators paused the system. Service remained suspended for an extended period, reported by some as 39 days, while patches were applied. Certain Thorchain front ends have long screened sanctioned or flagged addresses, though such measures can be circumvented.

Some community members have cited the earlier multi-week suspension as inconsistent with the protocol’s current defense of fully permissionless operation in the Bitget case.

As of the latest statements, Thorchain has not indicated any plan to implement address-level blocking for the Bitget-linked funds. The exchange continues to track the movement of the stolen assets while its withdrawals were scheduled to reopen in the days following the initial disclosure.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.