Bitget Hack Rekindles THORChain Compliance Debate

Bitget Hack Rekindles THORChain Compliance Debate

The $387.5 million Bitget hack has reopened a difficult question for decentralized finance: when stolen assets reach a permissionless liquidity protocol, who can realistically be required to stop them? The full Bitget loss did not pass through THORChain, but attacker-linked wallets have used the cross-chain protocol to convert portions of the stolen assets into Bitcoin. Bitget’s official tracing update says approximately $387.5 million was transferred to attacker-controlled addresses across multiple networks after the September 24 breach.

Bitget CEO Gracy Chen subsequently asked THORChain to refuse service to publicly identified attacker addresses. THORChain declined, arguing that its current architecture does not provide transaction-specific blacklisting. Public transaction analysis identified 27 successful THORChain swaps converting roughly 2,390 ETH into 75.2 BTC, worth about $6.3 million at the time. The dispute is therefore about whether a protocol should build selective intervention controls, not whether THORChain currently possesses a simple wallet-freezing switch.

Network Control Does Not Equal Address-Level Censorship

THORChain does have emergency controls. Its documentation says node operators can pause the entire network, halt trading or stop operations involving a particular blockchain when funds are at risk. Those controls operate at network or chain level and are materially different from refusing one identified wallet while continuing to process everyone else’s swaps. The distinction matters because previous THORChain interventions cannot automatically be used as evidence that nodes could have selectively frozen the Bitget attacker.

The network’s January 2025 THORFi crisis illustrates the difference. An admin key was temporarily used to pause Lending and Savers, but THORChain later removed that administrative mechanism, while subsequent pauses were coordinated through node voting. Its current emergency documentation describes node-operated halts and requires decentralized consensus for longer interventions. Past willingness to stop protocol functions demonstrates governance capability, but not necessarily technical capacity for address-by-address sanctions screening.

Other systems have deliberately chosen another architecture. NEAR Intents recently said its SHIELD controls rejected more than $50 million in attempted Bitget-linked routes, while only about $503,000 was actually restricted during execution. That contrast shows that intervention depends heavily on where compliance controls are placed in the stack. THORChain has also appeared in previous laundering routes, including Bitcoin linked to the Coldcard exploit moving through THORChain and CoinJoin.

Legal Exposure Depends on Who Actually Controls the Service

The Financial Action Task Force’s 2026 DeFi report does not say that every decentralized protocol is automatically a regulated virtual asset service provider. Instead, FATF tells jurisdictions to examine whether identifiable people or entities exercise control or sufficient influence, profit from the service, set parameters or maintain an ongoing business relationship with users. Calling software “decentralized” is not determinative, but neither is the existence of governance controls enough by itself to establish legal liability.

U.S. criminal precedent also requires care. Tornado Cash co-founder Roman Storm was convicted in 2025 of conspiring to operate an unlicensed money transmitting business, while Samourai Wallet’s founders pleaded guilty to operating a money transmitter that knowingly processed criminal proceeds. Those cases involved evidence about identifiable operators, infrastructure, fees and knowledge; they do not establish that an autonomous cross-chain protocol is liable whenever criminals use it.

Civil liability is similarly fact-dependent. DeFi disputes are increasingly reaching conventional courts, including litigation over the $292 million KelpDAO exploit and court proceedings involving $71 million frozen after that incident. Those cases demonstrate that decentralization does not keep disputes outside the legal system, but they do not create a general duty requiring protocols to blacklist stolen assets.

The immediate question for THORChain is therefore narrower than whether “DeFi can be prosecuted.” The next meaningful milestone is whether regulators or law enforcement formally examine THORChain’s governance, operators and transaction-processing structure after the Bitget flows. Until that happens, criminal liability, money-transmitter exposure and negligence claims remain legal theories rather than enforcement outcomes established by the September hack.

Follow Us

Ads

Main Title

Sub Title

It is a long established fact that a reader will be distracted by the readable

Ads
banner 900px x 170px