Bitget's estimated losses from this week's hack have climbed to $387.5 million, according to the exchange. Two days after the breach, CEO Gracy Chen publicly requested that Thorchain, a decentralized network for swapping crypto assets across different blockchains, block the hackers from using its protocol.
"Our attacker addresses are publicly listed and actively tracked. We are formally asking Thorchain to refuse service to these addresses," Chen wrote on social media. She added that "decentralization is a design principle, not a shield for facilitating known stolen funds."
The stolen funds have been routed through multiple platforms. Tens of millions in XRP have been deposited into Thorchain vaults, with additional amounts already swapped for bitcoin. The attackers are also reportedly using Chainflip, Uniswap, 1inch Fusion, Stargate, Across, and Relay to move the funds.
Thorchain responded by emphasizing its permissionless structure, comparing itself to Bitcoin, Ethereum, and BNB Chain. "What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?" the protocol's official account stated.
Precedent from Bybit Hack
Chen's request faces a significant hurdle. After the Bybit hack, which moved $1.2 to $1.5 billion in stolen funds through Thorchain, the FBI asked the industry to block addresses linked to the Democratic People's Republic of Korea. Three of Thorchain's validators initially voted to halt ETH trading, but four validators reversed the decision half an hour later. The network continued operating, and a developer subsequently quit over the incident.
Although Thorchain has the technical capability to halt its entire system or pause trading on individual assets—as it did for weeks following a May 2026 exploit that drained approximately $10.7 to $11 million from one of its vaults—validators chose not to block the Bybit funds. Some Thorchain front ends have screened sanctioned addresses for years, but this screening can be bypassed.


