Newsroom
27 September, 2026 / News / AI / Tags: thorchain, bitget, stolen, addresses, gracy

Exchange revises loss estimate upward and publicly calls on the cross-chain protocol to refuse service to attacker addresses as funds move through decentralized rails
Bitget has raised its estimate of losses from a September 24 security incident to approximately $387.5 million and formally requested that Thorchain block transactions linked to the attackers. The revised figure accounts for assets held on Zcash and TRON networks rather than any additional unauthorized movements beyond the original event.
Unauthorized transfers began at 2:31 p.m. Eastern Time from certain hot wallets. The exchange initially reported about $351.6 million affected. Assets involved include XRP, ether, Tether, Zcash, USD Coin, USDT0, Tether Gold, BNB, Avalanche and TRON tokens. Bitget has published lists of attacker-controlled addresses spanning EVM networks, the XRP Ledger, Zcash and TRON.
Attackers have been shifting the stolen assets across several platforms. Reports indicate tens of millions of dollars in XRP were deposited into Thorchain vaults, with a substantial portion already swapped into bitcoin. The bitcoin has subsequently been distributed across numerous addresses. Other venues used include Chainflip, Uniswap, 1inch Fusion, Stargate, Across and Relay.
Bitget stated that its User Protection Fund held more than $464 million at the time the incident was disclosed.
Two days after the breach, Bitget CEO Gracy Chen posted on X asking Thorchain to stop serving the identified attacker addresses. She noted that the addresses are publicly listed and actively tracked.
The request has drawn mixed responses in the community, with some users pointing to the permissionless nature of the protocol and questioning why similar demands were not directed at bitcoin miners or other base-layer networks.
Thorchain’s official account replied that the protocol is decentralized and permissionless in the same manner as Bitcoin, Ethereum and BNB Chain. It expressed sympathy for those affected by the exploit while asking what responsibility those networks should bear when processing funds identified as stolen.
The protocol operates through smart contracts, liquidity pools and independent node operators. Its terms of use state that network behavior is governed by code, contracts and consensus rather than any central authority capable of unilaterally approving or rejecting transactions.
Thorchain previously faced pressure after the Bybit breach, during which between $1.2 billion and $1.5 billion in stolen funds passed through the network. At that time, the FBI requested blocking of certain addresses linked to North Korean actors. Three validators briefly voted to halt ether trading before four others reversed the decision within roughly 30 minutes, allowing operations to continue. One developer later departed the project over the episode.
In a separate May 2026 incident involving the GG20 exploit, which drained approximately $10.7 million to $11 million from a vault, network operators paused the system. Service remained suspended for an extended period, reported by some as 39 days, while patches were applied. Certain Thorchain front ends have long screened sanctioned or flagged addresses, though such measures can be circumvented.
Some community members have cited the earlier multi-week suspension as inconsistent with the protocol’s current defense of fully permissionless operation in the Bitget case.
As of the latest statements, Thorchain has not indicated any plan to implement address-level blocking for the Bitget-linked funds. The exchange continues to track the movement of the stolen assets while its withdrawals were scheduled to reopen in the days following the initial disclosure.









