THORChain has pushed back against a formal request from Bitget CEO Gracy Chen to block wallet addresses linked to a hack that drained approximately $387.5 million from the exchange, reigniting a debate over whether decentralized cross-chain protocols should deny service to known bad actors.
Bitget’s on-chain tracing update revised its initial loss estimate upward from $351.6 million after investigators identified attacker-controlled receiving addresses across Ethereum and other EVM-compatible networks, the XRP Ledger, Zcash, and TRON. The exchange says the incident is now contained and that no further unauthorized transfers are possible. For related coverage, see Binance Supports THORChain RUNE Network Upgrade June 2025.
Chen publicly asked THORChain to refuse service to the listed attacker addresses, according to Bitcoin.com News reporting. THORChain responded by describing the protocol as decentralized and permissionless in the same manner as Bitcoin, Ethereum, and BNB Chain, and asked what responsibility those base-layer networks bear for handling known stolen funds. For related coverage, see Bybit to Support THORChain (RUNE) v3.19.0 Network Upgrade.
Why the “permissionless” argument divides the industry
The protocol’s stance drew immediate disagreement from prominent figures. Bitcoin.com News reports that OKX founder Star Xu and Dashpay’s Joel Valenzuela took opposing positions on whether THORChain should act against the flagged addresses. The split reflects a recurring tension in the industry between the technical neutrality of open protocols and their practical role in facilitating the movement of stolen funds.
The dispute echoes a controversy earlier in 2025, when THORChain faced criticism after reportedly facilitating an estimated $1.2 billion in fund flows tied to the Bybit hack. That incident, combined with the current Bitget case, puts sustained pressure on THORChain’s governance community to define a public policy on sanctioned addresses. For Southeast Asian exchanges such as Indodax, Tokocrypto, and Coins.ph, which route cross-chain liquidity through protocols like THORChain, the outcome of that debate has direct compliance implications.
What blocking would and would not achieve
Attacker-controlled addresses in the Bitget incident span multiple blockchains, meaning any action by THORChain would address only the cross-chain routing layer, not the underlying chains where the funds currently sit. Bitget’s own update confirms the stolen assets are spread across EVM networks, XRP Ledger, Zcash, and TRON, each with independent infrastructure. A THORChain block would limit the attacker’s ability to swap assets permissionlessly across those chains but would not freeze the funds outright.
THORChain’s native token RUNE was trading at $0.752888 at the time of data capture, down 0.91% over 24 hours, against a broader crypto market reading a Fear & Greed score of 70 (Greed). The muted price reaction suggests markets are treating this as a governance and reputational issue rather than an immediate protocol-level risk. Previous coverage of THORChain RUNE upgrade execution and market reactions shows the token has historically been sensitive to governance news.
The case is the latest in a growing list of incidents involving cross-chain infrastructure. A previous crypto bridge hack involving $11 million demonstrated how fragmented blockchain environments complicate coordinated responses. THORChain’s expanded DeFi capabilities through Rujira have also broadened its attack surface and increased the stakes of governance decisions around address filtering.
What comes next for THORChain and regional exchanges
The unresolved question is whether THORChain node operators will act unilaterally, whether the broader community will pass a governance proposal, or whether the protocol will maintain its current position. Bitget has published the primary attacker-controlled addresses for each affected network, so any future block would be technically straightforward to implement if the community chose to do so.
For regulators across the ASEAN region, where several jurisdictions are finalizing virtual asset service provider frameworks, the THORChain response sets an informal precedent: decentralized protocol operators may resist external pressure to restrict access even when stolen funds are publicly identified. That stance will likely feature in ongoing regulatory consultations in Singapore, Thailand, and the Philippines, where licensing regimes increasingly require exchanges to demonstrate they are not facilitating the movement of illicit assets.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
