Home | FCA & regulatory news | British English edition
Trade Hub UK

Independent coverage of UK markets, FCA policy and institutional trading

AD Investing.com Markets AD LSEG Data AD CME Group Education AD Bank of England Statistics
Digital Assets

THORChain rejects Bitget request to block hacker as $6 million moves to bitcoin

CoinDesk found 27 successful swaps moving about 2,390 ETH into 75.2 BTC, even as Bitget urged THORChain to stop serving addresses tied to the $387.5 million theft.

  • A wallet linked to the Bitget hacker swapped about 2,390 ether, worth $6.3 million, for 75.2 bitcoin through THORChain on Monday.
  • Bitget, which lost about $388 million in a Sept. 24 breach, asked THORChain to block publicly identified attacker addresses and has offered a 5 percent bounty for freezing or recovering stolen funds.
  • THORChain rejected selective blacklisting, saying its emergency controls can halt broader network activity but cannot freeze an individual address or transaction.

A wallet linked to the Bitget hacker converted about $6.3 million in ether

CoinDesk’s analysis of THORChain’s public transaction records identified 27 swaps marked successful, exchanging about 2,390 ETH for 75.2 BTC. All the bitcoin payouts went to one address. Four additional swaps involving 400 ETH were marked pending in the response reviewed.

The records cover orders submitted between about 03:55 and 06:23 UTC on Monday from an Ethereum wallet identified by blockchain tracker Lookonchain as part of the attacker’s activity. Most were submitted in roughly 100 ETH batches, worth about $265,000 each.

THORChain lets users exchange assets on different blockchains without opening an account at a centralized exchange. An attacker can send in stolen ether and receive bitcoin in another wallet without passing through an exchange that could block the transfer. The swaps remain publicly visible, however, allowing investigators to follow the funds across networks.

Crypto exchange Bitget lost about $388 million in a Sept. 24 breach after an attacker bypassed security controls protecting its exchange wallets. The company has since said it has identified and fixed the vulnerability, though it has not publicly detailed how the attacker gained access.

The exchange had published attacker addresses and offered a 5% bounty for eligible efforts that freeze or recover stolen funds. As the attacker moved those assets through other services, Bitget CEO Gracy Chen publicly asked THORChain over the weekend to refuse the transactions.

“Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses,” she wrote on X. “Decentralization is a design principle, not a shield for facilitating known stolen funds.”

THORChain’s public response on Monday defended its policy of allowing anyone to use the network and distinguished its emergency shutdown controls from an address blocklist.

“A THORChain network halt is an emergency security mechanism designed to protect the protocol,” the project wrote. “A halt is not a selective freeze of specific funds or an individual swap.”

Its operators do have controls that can interrupt trading, the team said. THORChain’s documentation describes settings that stop swaps across every connected blockchain or restrict activity involving a particular chain, such as Ethereum. Using those controls would also interrupt other users’ transactions on the affected routes.

As such, the network used emergency controls in May after an attacker stole about $10.7 million from one of its own vaults, or the accounts holding assets used for swaps. Operators coordinated a shutdown while developers investigated and repaired the vulnerability. Trading resumed June 22 after roughly five weeks.

THORChain said the May attacker’s addresses were never blacklisted. That intervention protected a compromised protocol, while Bitget is asking it to reject funds stolen from an outside exchange.

Read More: Thorchain halts trading after $10 million cross-chain exploit, RUNE token drops 12%

Monday’s swap records also show the attacker encountering trading limits. Two 100 ETH orders were only partly filled after portions failed to meet their specified minimum price, returning about 114 ETH to the sending wallet.

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.