THORChain Faces Scrutiny Over Bitget Hack Laundering

By bonuz NewsroomPublished September 29, 2026
THORChain Faces Scrutiny Over Bitget Hack Laundering

On 24 September 2026, attackers drained $387.5 million (USD) from Bitget's wallets, then routed stolen BNB, TRX, and XRP through THORChain to convert them into bitcoin. The case reopens a global debate over whether decentralized protocols must block known stolen funds.

What actually happened

Bitget lost approximately $387.5 million (USD) from its hot and warm wallets on 24 September 2026, according to Wu Blockchain. Bitget said attackers manipulated its backend wallet infrastructure rather than stealing private keys, and suggested involvement of a North Korea-linked group. Detection occurred at 18:31 UTC, but outflows continued until roughly 21:23 UTC. By 26 September, AMLBot found about 88% of stolen funds still dormant, while Bitquery estimated THORChain swaps had produced approximately 126.71 BTC, worth about $10.6 million (USD). BNB swaps alone generated roughly 51.26 BTC. Bitget CEO Gracy Chen publicly asked THORChain to deny service to the attackers' addresses, saying, "Decentralization is a design principle, not a shield for facilitating the movement of known stolen funds. The entire industry is watching."

How we got here

THORChain launched its mainnet in 2022, after Australian developer John-Paul Thorbjornsen and American Chad Barraford prototyped cross-chain swaps in 2019. The protocol uses threshold signature schemes, letting rotating validator sets jointly control vault funds without a single custodian. It has faced scrutiny before. After the 2025 Bybit hack, MistTrack tracked nearly $1.2 billion (USD) in stolen funds moving through THORChain during cross-chain transfers. In May 2026, roughly $10.7 million (USD) was stolen from THORChain's own vaults, prompting nodes to halt the network for about 39 days. Critics now cite that halt as proof the protocol can act when it chooses to.

Why this matters for you

For THORChain users and RUNE holders, the dispute raises reputational and regulatory risk. Exchanges may restrict withdrawals to THORChain-linked addresses, or regulators could push for interface-level screening. For builders of cross-chain protocols, the case highlights a growing tension between permissionless design and demands for compliance. Wallet and exchange operators, including those building AR and hardware wallets, may need clearer standards for flagging known stolen-fund addresses before transactions reach settlement. For everyday crypto users, the incident is a reminder that convertibility across chains can also help attackers, so due diligence on counterparties and bridges matters more than ever.

The bigger question

If a protocol can technically halt itself to protect its own funds, as THORChain did for 39 days in May 2026, should it be expected to do the same for other victims' stolen assets? Or does true permissionlessness mean treating every transaction the same, regardless of its origin? The answer could shape how regulators and exchanges treat decentralized infrastructure for years to come.

What to watch

Security firms including AMLBot, Bitquery, and MistTrack continue tracing the stolen funds as they move across chains. THORChain's community has not announced formal policy changes since Gracy Chen's 26 September 2026 request. Watch for possible governance proposals on address screening at the interface level, and for regulatory statements referencing the Bitget case. Bonuz will track how exchanges and wallet builders respond to renewed pressure on cross-chain protocols.

Keep reading