THORChain has rejected calls to block addresses linked to Bitget’s September 24 exploit, defending its permissionless architecture as criticism mounts over whether its validator-controlled vaults make the protocol comparable to Bitcoin or Ethereum.
Bitget has now confirmed approximately $387.5 million was transferred to attacker-controlled addresses during the wallet breach, up from its initial $351.6 million estimate after additional Zcash and TRON transactions were classified.
Bitget CEO Gracy Chen publicly asked THORChain to refuse service to the identified addresses, writing that “decentralization is a design principle, not a shield for facilitating known stolen funds.”
THORChain described itself as “decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain” and asked what responsibility those networks should bear when known stolen funds pass through them.
Star Xu Challenges THORChain’s Bitcoin Comparison
OKX founder and CEO Star Xu disputed the comparison, focusing on THORChain’s Threshold Signature Scheme and validator-controlled vault architecture.
Xu argued that THORChain’s selected validator set collectively controls assets held inside its TSS vaults and can move those assets once the required signing threshold is reached. He described the protocol as an intermediary between users and the native chains, adding: “Distributing an intermediary does not eliminate the intermediary.”
He followed with a second response pointing to THORChain’s own intervention during its May vault exploit, arguing that its ability to stop network activity separates it from Bitcoin’s base-layer architecture.
THORChain’s incident report confirms that automatic solvency controls first halted signing and trading across several chains after approximately $10.7 million was drained. Node operators then stacked manual pauses and cast Mimir governance votes, bringing trading, signing, chain observation and churning to a full controlled halt within roughly two hours.
The protocol’s Q2 report records a substantially longer disruption than the 13-hour period cited in Xu’s post: THORChain remained offline for roughly five weeks before restarting on June 22 with patched TSS code and the ADR-028 recovery framework.
THORChain Documentation Confirms Broad Halt Powers
THORChain’s emergency procedures explicitly describe make pause as the “big red button that stops everything.” A node operator can initiate a 720-block network pause, while additional operators can extend it. Nodes can also vote through Mimir to halt signing for individual connected chains.
Those controls establish that THORChain operators can interrupt protocol activity. The published documentation does not describe an equivalent protocol-level mechanism for selectively blacklisting one external wallet while allowing all other swaps to continue.
MistTrack, SlowMist’s onchain tracking platform, also entered the dispute after tracing Bitget-related funds into THORChain for swaps and cross-chain transfers. It argued that “decentralization should not become a blanket excuse”when publicly flagged stolen funds are involved.
Security researcher Taylor Monahan separately challenged THORChain’s non-intervention argument, pointing to the network’s established ability to pause operations and coordinate protocol changes.
Bitget says some affected assets have already been frozen through cooperation with exchanges, blockchain projects and security firms. Its recovery program now offers a 5% bounty for eligible actions that directly result in stolen assets being frozen or recovered.



Be the first to comment