CandyPulse

THORChain vs. Bitget: The $388M Exploit Re-igniting Crypto’s Neutrality Debate

By CANDY Team · 2026-09-29 · News

Table of Contents


The aftermath of Bitget's enormous security breach has brought back one of decentralized finance's most divisive ideological conflicts: the friction between absolute protocol neutrality and compliance with law enforcement.

While the hacker is actively moving millions of dollars in stolen Ethereum through the cross-chain liquidity protocol THORChain to swap it into native Bitcoin, Bitget's direct requests for blacklisting have been rejected outright.

The decision has divided the Web3 industry. One side sees THORChain's refusal as an uncompromising defense of base-layer censorship resistance, while critics contend that it offers cybercriminals a frictionless escape route at victims’ expense.

Anatomy of the $388M Breach

The incident started with unauthorized transfers that emptied hot and warm reserves from the centralized exchange Bitget. Early estimates put the damage at $351.6 million, but ongoing forensic accounting by Mandiant and SlowMist soon raised the total to $387.5 million.

According to Bitget CEO Gracy Chen, the intrusion did not result from compromised private keys or cold storage. Rather, the attacker exploited a flaw in an external third-party security management tool, gaining elevated internal API credentials to circumvent automated withdrawal risk checks and fabricate abnormal transfer commands.

Once inside, the attacker moved fast, splitting the proceeds across multiple intermediary wallets and using coin-mixing protocols such as Wasabi before bridging into cross-chain settlement networks.

The Cross-Chain Laundering Conduit

To break the chain of custody, the attacker turned to THORChain, which enables native cross-chain swaps (such as ETH to BTC) without wrapped tokens or custodial middlemen. On-chain data shows the attacker carried out dozens of automated transactions, sending thousands of ETH through THORChain's pools to come out as untraceable, native Bitcoin.

With the recovery window closing rapidly, Bitget contacted the THORChain development community and node operators, asking for an emergency freeze on known attacker addresses.

THORChain said no.

The Case for THORChain: Credible Neutrality

THORChain's node architecture and community defenders maintain that the refusal is a fundamental engineering boundary and not an administrative choice.

The Case Against: Emergency Powers and Incentive Conflicts

Critics and blockchain security analytics firms, including GoPlus Security, argue that THORChain’s "unbiased infrastructure" defense rings hollow against its operational history:

The Road Ahead for Decentralized Rails

Bitget has since contained the vulnerability and begun gradually restoring network withdrawals in phased tiers. Even so, the breach leaves the wider Web3 ecosystem facing an unresolved paradox.

If decentralized finance protocols build in backdoors, blacklists, and selective enforcement, they become impossible to tell apart from the traditional correspondent banking rails they aim to replace. But if they stay resolutely neutral, they inevitably become automated clearinghouses for high-profile cybercrime.

THORChain has chosen its side: code must remain neutral, no matter how high the cost.


More on CandyPulse

Quant's Banking Deal: What The Clearing House Pick Means, and What It Doesn't, for QNT

RedotPay Completes Financial Audit as It Pushes Ahead With U.S. IPO Plans

Memecoin Warning on Robinhood Chain as GoPlus Flags Suspected Coordinated Token Operation

Compound Governance Clash: Reserve Conversion Sparks Voting-Power Dispute