An address connected to the Bitget exploiter traded roughly 2,390 ether, valued at $6.3 million, for 75.2 bitcoin via THORChain on Monday.
Bitget, which suffered a loss of approximately $388 million during a September 24 exploit, requested that THORChain blacklist explicitly named malicious wallets and has put forward a 5% reward for freezing or retrieving the pilfered assets.
THORChain declined to implement selective blacklisting, noting that its emergency protocols are capable of pausing entire network operations but cannot freeze a specific account or transaction.
On Monday, an Ethereum wallet flagged by analytics provider Lookonchain as tied to the perpetrator converted roughly $6.3 million worth of ether ETH into bitcoin BTC through THORChain, while the centralized platform urged the cross-chain protocol to restrict addresses holding the stolen funds.
An evaluation of THORChain’s public ledger by CoinDesk uncovered 27 completed exchanges, trading about 2,390 ETH for 75.2 BTC. All resulting bitcoin distributions were sent to a single destination. An additional four transactions involving 400 ETH appeared as pending within the data reviewed.
The logs span orders placed between roughly 03:55 and 06:23 UTC on Monday from the aforementioned Ethereum address. Most transactions were submitted in increments of approximately 100 ETH, valued near $265,000 each.
THORChain enables individuals to swap assets across disparate blockchains without creating an account on a custodial platform. An assailant can deposit compromised ether and receive bitcoin in an alternative wallet without utilizing an intermediary that might halt the transfer. Nonetheless, these swaps remain publicly viewable, enabling analysts to trace the capital across networks.
Digital asset exchange Bitget encountered a roughly $388 million shortfall on September 24 after a bad actor bypassed safeguards securing its platform wallets. The enterprise subsequently stated it discovered and patched the vulnerability, though it has not publicly outlined how entry was achieved.
The exchange had shared the perpetrator’s addresses alongside a 5% bounty for authorized actions that freeze or recover the looted capital. As the attacker funneled those resources through external protocols, Bitget CEO Gracy Chen publicly urged THORChain over the weekend to reject the transactions.
“Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses,” she posted on X. “Decentralization is a design principle, not a shield for facilitating known stolen funds.”
THORChain issued a public reply on Monday defending its stance of permitting open network access and separated its emergency shutdown mechanisms from address blacklisting.
“A THORChain network halt is an emergency security mechanism designed to protect the protocol,” the project stated. “A halt is not a selective freeze of specific funds or an individual swap.”
The protocol’s maintainers do possess mechanisms capable of suspending activity, the team noted. THORChain’s documentation outlines configurations that can halt swaps across every linked blockchain or restrict functionality tied to a specific network, such as Ethereum. Deploying those tools would also disrupt unrelated user transactions along those pathways.
Accordingly, the network invoked emergency protocols in May after an intruder made off with roughly $10.7 million from one of its native vaults, which are the pools holding liquidity for trades. Maintainers coordinated a pause while engineers investigated and fixed the security flaw. Operations resumed on June 22 following a duration of about five weeks.
THORChain noted that the addresses belonging to the May exploiter were never blacklisted. That intervention safeguarded an impaired protocol, whereas Bitget is requesting the rejection of funds stolen from a third-party platform.
Read More: Thorchain halts trading after $10 million cross-chain exploit, RUNE token drops 12%
Monday’s trading data additionally indicates the attacker ran into execution constraints. Two orders of 100 ETH were only partially executed because portions missed their defined price minimums, sending roughly 114 ETH back to the originating wallet.
Originally published at https://www.coindesk.com/tech/2026/09/28/thorchain-rejects-bitget-request-to-block-hacker-as-usd6-million-moves-to-bitcoin.