Blockchain & Crypto

Bitget CEO Urges THORChain to Block Funds Linked to $387M Hack

Bitget CEO Gracy Chen has called on THORChain to stop processing transactions involving wallets linked to the exchange’s $387.5 million security breach, arguing that decentralization should not prevent protocols from taking action against publicly identified stolen funds.

Bitget CEO Urges THORChain to Block Funds Linked to $387M Hack

Bitget detected unauthorized transfers from parts of its hot and warm wallet infrastructure on September 24. The exchange initially estimated the loss at $351.6 million before raising the figure to approximately $387.5 million after including transactions involving Zcash and TRON.

According to Bitget, the attackers did not obtain private keys. Instead, a backend system within the exchange’s wallet infrastructure was compromised, allowing the attackers to manipulate transaction data and trigger Bitget’s own authorization process. The stolen assets were distributed across multiple networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base.

Around $102.9 million worth of XRP accounted for the largest portion of the stolen assets. Bitget said its cold wallets were not affected and that customer balances are covered by a protection fund exceeding $464 million.

The exchange has been working with Mandiant, SlowMist and law enforcement agencies to investigate the incident. Bitget has also launched a 5% recovery bounty and established a public tracker for recovered funds.

Meanwhile, part of the stolen cryptocurrency has already moved through THORChain and been converted into Bitcoin. Chen said Bitget had formally asked the cross-chain protocol to block the identified attacker addresses.

“Decentralization is a design principle, not a shield for facilitating known stolen funds,” Chen wrote.

THORChain responded that its infrastructure is permissionless, drawing a distinction between its model and centralized exchanges that can freeze withdrawals or block specific users.

The dispute highlights a recurring challenge in the crypto industry: how decentralized protocols should respond when blockchain transactions involve assets that have been publicly identified as stolen.

Bitget has preliminarily linked the attack to patterns associated with North Korean hacking groups, although no government has officially attributed the incident. TRM Labs and Elliptic have also identified connections between the stolen funds and wallets previously associated with North Korean laundering activity.

The exchange has begun restoring withdrawals in stages, with Bitcoin withdrawals reopening on September 28 and other assets scheduled to follow through October 2.

Pay Space

Pay Space

2398 Posts

https://payspacemagazine.com/author/payspacemagazineauthor/

Our editorial team delivers daily news and insights on the global payment industry, covering fintech innovations, worldwide payment methods, and modern payment options.