Bitget CEO Gracy Chen Presses THORChain To Cut Off Stolen Funds After $387M Hack
Bitget’s chief executive has publicly pressed THORChain to stop processing funds tied to last week’s exchange breach, arguing that a protocol’s architecture should not be treated as cover for moving assets already identified as stolen.On September 24, Bitget detected unauthorized outflows from hot and warm wallets.
The company later put the loss at about $387.5 million across several chains, with a large XRP position among the biggest pieces.
Cold storage was not hit, and private keys were not taken.
According to CEO Gracy Chen, attackers compromised a backend system in the wallet stack, forged transaction data, and tricked Bitget’s own approval flow into signing transfers that looked ordinary.
Chen has said IP patterns and on-chain behavior resemble prior operations linked to North Korean groups, though formal attribution remains with investigators.
Bitget froze withdrawals, said a protection fund of more than $464 million covers customer balances, and began working with law enforcement and forensic firms.
Within a day, portions of the loot were already being swapped through THORChain into Bitcoin.
Chen then posted that the attacker addresses were public and tracked, and that Bitget had formally asked the cross-chain protocol to refuse those addresses.
“Decentralization is a design principle, not a shield for facilitating known stolen funds,” she wrote.
“The industry is watching.”
She also noted that after the February 2025 Bybit theft of roughly $1.46 billion, about $1.2 billion of those proceeds had likewise moved across chains via THORChain.
THORChain later expressed regret but stressed that it is permissionless in the same sense as Bitcoin, Ethereum, or BNB Chain.
The contrast with earlier crises is sharp.
Bybit’s heist remains the largest crypto theft on record.
Users were made whole by the exchange; almost none of the stolen principal was clawed back.
Most of the ether was converted to bitcoin through THORChain while analytics firms watched in public.
Ronin’s 2022 bridge drain of more than $500 million, also tied to North Korea, forced a recapitalization rather than a clean recovery.
Poly Network’s $611 million exploit ended with the attacker returning most of the money.
Wormhole’s $325 million loss was absorbed by a backer.
KuCoin recovered a large share of a $281 million 2020 breach through industry cooperation. Mt. Gox’s 2014 collapse left customers waiting years.
Centralized venues can pause withdrawals, tap insurance or reserves, and lobby issuers to freeze tokens.
Decentralized venues usually cannot reverse a signed swap without breaking their own rules.
That is why Chen’s request lands on a deeper fault line.
Many products marketed as decentralized still concentrate real power. Foundations, core developers, governance token blocs, and node sets can halt markets, push upgrades, or coordinate pauses.
THORChain itself froze signing and trading after its own May 2026 vault exploit when operators stacked emergency votes.
Countless DeFi apps retain admin keys or small multisigs.
A rotating validator set is not the same as the absence of human control.
Permissionless settlement can coexist with identifiable operators who choose, or refuse, to run software that filters known thief addresses. Treating “decentralization” as an all-purpose defense blurs that distinction and leaves victims with fewer practical remedies after the next large CEX or bridge failure.