Exchange Hack Ignites Debate Over Network Freezes
A $387.5 million security breach at a major cryptocurrency exchange has ignited a debate regarding the responsibilities of decentralized cross-chain protocols in handling stolen assets. Following a September 24 hack, investigators tracked unauthorized transfers across multiple networks, prompting the affected trading platform, Bitget, to request a service denial for the attacker's public addresses.
THORChain, the cross-chain protocol facilitating some of the movement, refused the request and defended its permissionless architecture. The network argued that while it has emergency halt mechanisms to protect its own system, these features are not intended to function as selective blacklists for individual users. The protocol likened its infrastructure to networks like Bitcoin, Ethereum, and BNB Chain, questioning the liability of decentralized systems when processing illicit transactions.
Bitget CEO Gracy Chen publicly confirmed on September 26 that the attacker's addresses were being actively monitored, and she pushed back against the protocol's refusal to intervene.
“Decentralization is a design principle, not a shield for facilitating known stolen funds,” Chen said. “The industry is watching.”
Structural Disagreements
Security firm GoPlus Security challenged THORChain's comparison to base-layer networks on September 27. The firm noted that the cross-chain system utilizes a threshold signature vault mechanism where active validators collectively control assets and sign outbound transfers. GoPlus argued this setup, which includes documented pause functions and coordinated voting for per chain halts, differs significantly from Bitcoin and Ethereum, where users hold private keys individually.

To support its point, GoPlus highlighted a May 15 incident where THORChain lost approximately $10.7 million to an exploit involving a weakness in its GG20 Threshold Signature Scheme. During that event, automated solvency checks triggered a halt on trading and signing across several chains. Node operators coordinated a shutdown, and the network remained offline until June 23 after executing an 11 step restart plan that brought the system to version 3.19.0.
Michael Perklin, a crypto security executive supporting THORChain, rejected the comparison made by GoPlus. Perklin argued that threshold signing is an automated process, not an active decision by validators to individually approve specific transactions. He maintained that node operators can only choose to turn their machines offline.
“In all 3, there is no active choice to sign, only an active choice to turn off the machine,” Perklin said, adding that halting infrastructure to block criminal activity would concurrently stop legitimate user transactions.
Tracking the Fallout
Bitget initially estimated its losses at $351.6 million before identifying further TRON and Zcash transfers, bringing the total breach value to approximately $387.5 million. The exploit impacted assets including ETH, XRP, ZEC, USDC, BNB, AVAX, TRX, and USDT across the XRP Ledger, Ethereum, and several EVM networks. Blockchain tracking firm AMLBot has traced roughly 4 BTC tied to the hack moving from TRON through USDT0, Ethereum, and THORChain before entering a Wasabi CoinJoin round.
This dispute mirrors a previous controversy involving THORChain during the 2025 Bybit hack, where attackers generated $2.91 billion in trading volume and approximately $3 million in fee revenue for the network. Currently, Bitget is offering a 5% recovery bounty for freezing stolen assets and an additional 5% for recovery actions, while Tether and Circle have successfully frozen approximately $318,000 in USDC linked to the breach.


