$84,162+1.65%
BTC7D TREND
$2,715+2.50%
ETH7D TREND
$119.73+1.27%
SOL7D TREND
$763.97+0.39%
BNB7D TREND
DeFi Data →
Risk
Risk

THORChain Won’t Block Bitget Hack Funds Moving $387.5M to Bitcoin

Reports circulating on September 28, 2026 claim that THORChain, the permissionless cross-chain liquidity protocol, declined to block wallets allegedly connected to a Bitget exchange exploit, allowing approximately $387. 5 million to be routed toward Bitcoin.

·3 min readMakeDefilibanpreferred onGoogle

Reports circulating on September 28, 2026 claim that THORChain, the permissionless cross-chain liquidity protocol, declined to block wallets allegedly connected to a Bitget exchange exploit, allowing approximately $387.5 million to be routed toward Bitcoin. The $387.5 million figure, the hacker attribution, and THORChain’s reported refusal remain unverified: available research contains no primary incident statement from Bitget, no transaction hash, and no on-chain proof of the claimed movement.

What the Alleged Transfer Claims, and What Remains Unconfirmed

The reported narrative describes a Bitget hack followed by a cross-chain conversion of stolen funds into Bitcoin, with THORChain acting as the routing layer. THORChain operates as a decentralised cross-chain AMM; it does not custody assets but facilitates swaps between native layer-1 tokens including BTC, ETH, and others through bonded node operators and liquidity pools. For related coverage, see Solana ETFs Outpace Bitcoin Funds During Fed Week.

No on-chain evidence for this specific movement has been independently surfaced at time of publication. Verification would require, at minimum, origin wallet addresses on the source chain, intermediary swap transaction hashes traceable through THORChain’s router contracts, and a destination Bitcoin address confirmed by a block explorer such as Mempool.space. None of those have been provided in available reporting. For related coverage, see Bitcoin Erases $86B ETF Paper Loss as BTC Nears $86K.

Bitget has not issued a security disclosure or incident report confirming an exploit. Until a primary statement is published and the $387.5 million calculation methodology is explained, this figure should be treated as an unconfirmed claim from a single source. For related coverage, see Bitcoin Hits $86K as Dogecoin Leads, Liquidations Near $1B.

Why THORChain’s Censorship Architecture Makes Blocking Technically and Politically Contested

THORChain’s protocol design is permissionless at the swap layer: node operators validate and sign outbound transactions based on threshold signature schemes, not individual address whitelists. Blocking a specific wallet address would require either a coordinated node majority refusing to process transactions from that address, or an emergency halt triggered through the protocol’s mimir governance parameters. For related coverage, see Ninepoint Launches US Energy ETF as AI and Bitcoin Miners Compete for Power.

Both mechanisms carry significant trade-offs. A node-majority block sets a precedent that validators can selectively censor flows, undermining the censorship-resistance guarantee that underpins THORChain’s value proposition to liquidity providers. An emergency halt, used previously during the 2021 exploit incidents, freezes all swaps and creates impermanent loss exposure for LPs across every pool while the protocol is paused, as Bitcoin prices continue moving while pool positions are locked.

Liquidity providers and arbitrageurs interacting with THORChain’s RUNE-denominated pools carry a secondary risk if tainted assets enter and are subsequently flagged by compliance tooling downstream: pool contamination can trigger counterparty refusals on centralised exchanges that source liquidity from cross-chain protocols. This risk is not hypothetical; similar contamination dynamics emerged after the Ronin bridge exploit in 2022 when Tornado Cash-linked ETH reached Uniswap pools.

Minimum Evidence Required Before Treating This as Confirmed

Three verification steps are needed before this story can be reported as fact rather than an unverified claim. First, a primary Bitget security disclosure or on-chain proof of the exploit’s originating transaction. Second, the specific THORChain swap transaction hashes showing the cross-chain route from the source asset to Bitcoin, along with the USD-equivalent value at time of each swap leg. Third, a statement from THORChain’s node operators, core team, or governance forum addressing whether a block was formally requested, whether it was technically feasible given the protocol state at the time, and what the outcome of any internal deliberation was.

Readers tracking this story should monitor THORChain’s Thornode governance parameters for any mimir changes and Bitget’s official channels for an incident report. On-chain investigators should cross-reference suspected wallet addresses against THORChain’s inbound transaction logs on the relevant chain before amplifying the $387.5 million figure.

Protocol-level censorship decisions in DeFi carry governance weight beyond the immediate incident. How THORChain’s node set responds, or does not respond, to requests from hacked centralised exchanges will inform LP risk models and potentially attract regulatory scrutiny of permissionless routing infrastructure, a pressure point that is already shaping cross-chain bridge governance across the broader DeFi compliance landscape heading into Q4 2026.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Defiliban · Oliver Benjamin

Oliver Benjamin

Oliver Benjamin

@oliver-benjamin