After suspected North Korean hackers exploited crypto exchange Bitget for $387.5 million, investigators traced the recipient addresses. Bitget CEO Gracy Chen then requested that decentralized cross-chain swaps platform THORChain block service to these addresses.
THORChain responded by asserting its permissionless nature, comparing itself to Bitcoin, Ethereum, and BNB Chain. The protocol also noted it has retired its admin key and lacks the technical ability to censor addresses.
The incident highlights a legal paradox facing decentralized finance platforms. According to Yuriy Brisov, legal counsel at D&A Partners, a protocol's strongest defense against liability claims is demonstrating true decentralization and inability to interfere with transactions. However, exercising control—even to block stolen funds—can expose a protocol to broader legal obligations regarding fraud prevention and user protection.
Contrasting Approaches
NEAR Protocol's Intents platform took a different approach, using its automated SHIELD program to block addresses linked to the Bitget hack from swapping $50 million. The platform declined a 5% bounty offered by Bitget for the action.
According to Brisov, automated systems that block illicit addresses without human intervention may retain stronger legal protections than manual enforcement, as they demonstrate good-faith protective measures without centralized control.
Historical Precedent
This controversy mirrors a previous incident in which THORChain processed approximately $1.2 billion in stolen funds from a $1.46 billion Bybit hack. THORChain had retired its admin key just 11 days before that incident.
Brisov noted that the Bybit case has already opened THORChain to potential legal claims, and similar actions could follow the Bitget incident.
Legal Framework Considerations
Brisov explained that demonstrating control over assets—through blocking capabilities or protocol upgrades—exposes decentralized platforms to expanded liability claims regarding pump-and-dump schemes, volatility, token vetting, and investor protections.
The legal distinction between property and code remains significant. Smart contracts, unlike traditional financial instruments, are not treated as property under U.S. law, which affects how money laundering and sanctions liability apply to permissionless protocols.


