THORChain co-founder Chad Barraford acknowledged that the protocol could have taken action to disrupt funds linked to the Bitget hack, which drained $387.5 million from the exchange. However, he argued that implementing an effective response would have been difficult due to the challenges of coordinating validators while attackers quickly move funds to new addresses.
Barraford made the comments during an interview alongside onchain analyst Taylor Monahan. The discussion centered on whether THORChain responded adequately after Bitget requested the protocol stop serving addresses connected to the stolen funds.
Coordination and Speed Constraints
According to Barraford, THORChain currently lacks a mechanism to immediately censor individual transactions or wallets. Achieving the two-thirds validator consensus required for certain actions takes approximately three days on average and can sometimes extend to two weeks, making it difficult to respond before attackers relocate funds.
A faster response would require redesigning THORChain to grant a smaller group greater control, Barraford said. Halting trades already in progress would require vault migration—a process itself requiring two-thirds consensus that could take one to two weeks.
Available But Limited Options
Interviewer Laura Shin pointed out that THORChain possesses existing functions capable of halting Ethereum or Bitcoin trading. She noted that the Ethereum halt function could theoretically return certain swaps associated with stolen funds to their sender. Shin also highlighted THORChain's MakePause function, which allows a single node to temporarily halt chains for roughly an hour.
Barraford responded that using these mechanisms against an active attacker creates practical problems: broad halts affect legitimate users while validators coordinate a more permanent response. He noted that validators reach quick consensus when exploits threaten THORChain itself, as protecting the protocol is part of their responsibility.
Precedent and Disagreement
Monahan referenced the ThorFi incident, when an admin key temporarily paused lending before validator consensus approved further action. She argued this demonstrated THORChain's willingness to intervene. Shin compared the situation to the historical DAO hack response, noting that ShapeShift repeatedly reacted as the attacker attempted to convert stolen funds, though she acknowledged ShapeShift's centralized structure allowed faster response than a validator-driven protocol.
Monahan argued that THORChain's inability to perfectly stop stolen funds should not prevent validators from attempting to make laundering more difficult. She questioned using decentralization as justification for taking no action when a significant portion of protocol activity consisted of stolen funds.
Following the Bybit hack, some THORChain validators attempted to pause Ethereum trading when stolen funds moved through the protocol, but the effort failed because most validators opposed the action. Barraford said roughly 20 validators may have left over the disagreement, though he stressed he did not recall the exact number.
Path to Stronger Controls
When asked directly what would happen if validators supported censoring illicit transactions, Barraford acknowledged the possibility. "If you get a two third majority agreeing that we should censor transactions, then sure, that would be the way of the community," he said.
Shin raised NEAR Intents as an example of a protocol taking a more active approach, noting its Shield risk layer can refuse quotes or halt swaps and had blocked an attempted $50 million in laundering. When asked whether THORChain could implement something similar, Barraford said it was technically possible if validators supported it, though he suggested validators likely would not pursue such measures.


