Ly Gravity

THORChain Refused to Freeze the Bitget Hacker Wallets. The Code Says It Could Have.

CryptoAlpha • • Blockchain
On September 24, 2025, an attacker signed a transaction that should not have existed. According to Bitget's own post-mortem, the breach did not require a novel cryptographic exploit, nor a reentrancy bug, nor a manipulated oracle. It required a set of approval credentials inside a backend wallet system, and a transfer approval flow willing to authorize them. The result moved approximately USD 387.5 million in user assets. Three days later, on a Saturday, the CEO of Bitget published a request to THORChain: freeze the wallets, stop the flow, help us recover the funds. THORChain declined. On Monday, they declined again. I want to be precise about what was declined, because the imprecision in this debate is the entire debate. The request was not for THORChain's validators to burn someone's keys. It was not a demand for a protocol upgrade. It was a request to do something the network has demonstrably done before, for itself, in May of this year. What was refused was not a capability. It was an exercise. Trust is a variable; proof is a constant, and here the proof of capability is a matter of public record. The gap between what THORChain says it is and what its bytecode permits is now the most consequential question in cross-chain infrastructure. This is not a dispute about philosophy. It is a dispute about whether a threshold signature scheme can be asked, by its own operators, to sign or to not sign. It can. Everything downstream of that fact is rhetoric. Let me establish the context before I dissect the mechanism, because readers deserve the full ledger, not the headline. THORChain is a decentralized cross-chain liquidity protocol. Its selling proposition is unusual and, on paper, elegant: users swap native assets across chains without wrapping them. BTC for ETH. ETH for XRP. No bridged derivatives, no custodial IOU representing the underlying, no synthetic claim token that has to be trusted to redeem. The architecture that makes this possible is a network of vaults secured by Threshold Signature Scheme (TSS). A TSS splits a private key into shares distributed across validator nodes. No single node holds the whole key. To sign a cross-chain transaction — to move BTC out of a vault, for instance — a threshold number of nodes must collaborate in a distributed signing ceremony. The key never assembles in one place, and the signature emerges from the collective. This is a mature design. It is not experimental. THORChain's mainnet has processed real, large capital flows for years. On the axis of technical maturity, it clears the bar that most cross-chain systems fail. On the axis of security assumptions, it is where the trouble lives. A TSS vault is not a trust-minimized bridge. It is an M-of-N intermediary. Whether M-of-N is better or worse than a single intermediary depends entirely on who controls the N, and on the rules that govern what the collective will agree to sign. That is the model. Now the mechanism. In May 2025, THORChain suffered its own exploit. During that incident, the protocol did something unambiguous: it paused the network. Chain-level. Node-coordinated. The signing activity stopped. Whether one frames this as a responsible circuit breaker or a governance overreach depends on one's priors, but the technical fact is not contested: the validator set coordinated to stop signatures. It was not a reorg. It was not a client patch deployed by a foundation. It was a set of node operators deciding, collectively, that the correct state of the world was a state in which no new signatures were produced. GoPlus, the security firm, stated the same capability in plain terms during the current dispute: node voting can pause signing on a single chain. This is the sentence that ends the argument THORChain is trying to have. If node voting can pause signing on a single chain, then node voting can decline to sign for a single vault. There is no architectural chasm between "we paused everything" and "we declined, selectively, for one address set." There is only a difference in scope and a difference in will. THORChain's public position, per reporting, is that it is "permissionless and doesn't censor by design," and that it should not be asked to filter transactions any more than Bitcoin, Ethereum, or BNB Chain should be. I have read that comparison several times, and each time it fails on the same structural point. On Bitcoin, a miner who refuses to include your transaction does not prevent your transaction from existing. Another miner includes it in the next block. Inclusion is competitive and permissionless at the margin. On Ethereum, the same holds. On BNB Chain, the validator set is more concentrated than either, and yet the validators cannot selectively freeze a specific address's ability to have its balance moved by a third party — they can only order transactions, and ordering is not the same as authorization. The TSS model is different in kind, not in degree. A cross-chain vault signature is not an ordering decision. It is an authorization decision. When a threshold of THORChain nodes declines to co-sign, no amount of alternative sequencing, no competing block builder, and no re-org fixes it. The funds are, functionally, frozen — not by a blacklist contract, but by collective inaction. This is a soft freeze with different paperwork. The paper is the withdrawal of assent, and the effect is identical to a blacklist minus the formal record. Star Xu, the founder of OKX, made the sharpest technical formulation of the entire episode. TSS distributes control among multiple parties, but distributing an intermediary does not eliminate the intermediary. He is correct, and it is worth stating why with the precision the point deserves, because this is not a slogan. It is a theorem about custody. A single custodian is a point. A TSS vault is a set of points that must reach consensus to act. Consensus sets have properties that points do not. They can tolerate the failure of some members. They can rotate membership. They can, under pressure, behave better or worse than a single custodian, depending on the incentive structure and the governance rules. But there is one property they inherit from the point they replaced: the ability to not act. A single custodian can refuse to move your money. An M-of-N custodian can also refuse. The refusal is distributed; the refusal is still a refusal. The crypto industry has spent a decade conflating "no single point of control" with "no control." These are not the same statement. Distributed control is still control. A protocol whose vaults are secured by an M-of-N signature set is a protocol whose vaults are secured by an M-of-N signature set, and that set can be asked to sign or not sign. Everything else — the immutability of the contracts, the transparency of the code, the absence of an admin key — is orthogonal to this fact. Now, the part that requires the coldest reading. In May, when THORChain's own treasury or vault obligations were at risk, the network paused. In late September, when a third party — Bitget, and by extension its users — lost USD 387.5 million through a THORChain-routed flow, the network declined to pause. I am not going to moralize about this, because moralizing is noise. I am going to describe it as a governance outcome, because that is what it is. The same validator set, exercising the same mechanism, reached two different decisions under two different sets of facts. In the first case, the loss was internal. In the second, the loss was external. If the mechanism can be invoked to protect the collective's own assets but not to protect a counterparty's assets, then the operative governance principle is not "no censorship by design." The operative principle is "censorship, selectively, in defense of self." That is a coherent policy. It is not, however, the policy THORChain has stated. And once a protocol's actions diverge from its stated policy, the stated policy is no longer a constraint. It is a marketing artifact. I have seen this pattern before, in a different form. In 2022 I was contracted to review the yield distribution contracts underpinning the Anchor Protocol on Terra. The public narrative was an algorithmic money market with a sustainable 19.5 percent anchor yield. The contracts described something else entirely. Tracing the inflows and outflows over 72 hours, the yield was not revenue. It was subsidy funded by the protocol's own reserves and by new deposits — a debt instrument dressed as a rate. The mechanism did not care that the narrative said "sustainable." The mechanism enforced a specific cash flow, and that cash flow had a terminal date. When the narrative finally collided with the balance sheet, the collapse was not a surprise. It was arithmetic. I wrote a 40-page failure-mode report. Regulators cited it months later. The lesson I extracted then and apply now: do not read the whitepaper. Read the function that moves the money. So let me read the function that moves the money here. THORChain's cross-chain movement is enforced by the TSS signing ceremony. The relevant question is not whether the ceremony is decentralized. The relevant question is what inputs it accepts. A signing ceremony accepts a request — a set of inputs describing a destination, an amount, and an asset — and either produces a signature or does not. The set of requests it will sign is a policy, and that policy is a computational object. It can include, at minimum, the following condition: do not sign requests whose destination addresses belong to a specified set. That condition is not novel cryptography. It is a membership test. Membership tests are, in the taxonomy of software, trivial. Adding one shrinks the set of signable requests. It does not break the TSS math. It does not require a fork of the signature scheme. It requires the nodes to agree on the contents of the set. Which returns us to the only question that matters: what do the nodes agree to, and under what pressure do they agree to it? This is where I want to bring in the economic layer, because the nodes are not abstract. Node operators run infrastructure, and infrastructure has costs. THORChain generates protocol-level revenue through swap fees, and that revenue flows to the actors who provide the liquidity and the security. The security provider is the node operator. The node operator's marginal incentive is therefore to maximize the volume of swaps the network processes, subject to the cost of failing over. Every swap — including a swap that converts stolen BTC into something else — pays a fee. The fee does not ask where the input collateral came from. It cannot. There is no provenance field on a UTXO that says "this coin was stolen on September 24." Provenance is an external, off-chain attribution, and the protocol's fee logic is indifferent to it. This is the origin of the sharpest line in the entire affair. GoPlus warned, in substance, do not put the industry at risk for the fee line. That phrase — the fee line — is the whole thing in two words. A protocol that earns revenue from movement is a protocol that benefits from movement. When the movement is legitimate, the benefit is legitimate. When the movement is the laundering of USD 387.5 million, the benefit is what people in the compliance world call toxic revenue. Toxic revenue is real revenue. It pays validators. It is booked. It is, in the short run, indistinguishable from clean revenue on a P&L statement. In the long run, it is a liability with a delayed realization. I do not believe the THORChain node operators woke up and collectively decided to launder money. I believe the incentive structure made a refusal cheap and a compliance cheap expensive, and the structure did the work. Bureaucracies — and a node set is a bureaucracy — optimize for stability and continuity. Filtering introduces a decision that can be wrong, and being wrong about a filter is a reputational and legal risk of its own. Not filtering introduces no new decision; it preserves the status quo, which is the default behavior of any governance system under uncertainty. The refusal was not necessarily malice. It was the path of least resistance, which is how most governance failures actually happen. Now the historical ledger, because the pattern is the argument. Per reporting, THORChain has functioned as a transfer channel in a recurring series of major exploits. Lazarus Group flows. Kelp DAO, at roughly USD 292 million. Bybit, in 2025. And now Bitget, at USD 387.5 million. Set aside the individual attributions; the sampling itself is the signal. A general-purpose cross-chain protocol that routes native assets without wrapping is, by construction, an excellent laundering primitive. It converts one chain's traceable asset into another chain's differently-traceable asset, and it does so without requiring the attacker to accept a held derivative that a compliant issuer could freeze. That is precisely the property a legitimate user wants and precisely the property a launderer needs. Legitimate demand and illicit demand are for the same product. This is not a defect. It is the product's defining feature, viewed from the demand side. The consequence is that THORChain has not stumbled into the role of a laundering conduit. It has been selected for it, repeatedly, by actors who understand the architecture better than most of the people defending it on social media. When a system is chosen by sophisticated adversaries on the basis of its design, the design is the vulnerability. This is what I mean when I say immutability is not immunity. The property that protects users from a foundation also protects attackers from a foundation. Let me now quantify the urgency of the current flow, because one detail in this episode has been under-weighted. GoPlus estimated that approximately USD 8.5 million — about 101.5 BTC — had already exited, and that roughly USD 43 million in XRP, about 27.63 million units, was in the process of being converted at the time of assessment. Read that again as an auditor. The funds are not sitting still waiting for resolution. They are in motion. Every hour the dispute continues is an hour the attacker uses to convert traceable value into harder-to-trace value, to fragment holdings across addresses, and to cross additional boundaries. The request to freeze was not primarily about recovering the funds THORChain was asked to touch. It was about slowing the conversion before the asset base became unidentifiable. Refusal does not make recovery impossible. It makes recovery a footrace the good guys are losing by default. This is the point that the "tools are neutral" defense tends to elide. Michael Perklin, and others aligned with the tool-neutrality thesis, argue that THORChain is a tool, and that tools are neither good nor evil, only used. On a purely abstract level, I agree that a hammer is not a murderer. But a hammer is not operated by a governance committee that has already demonstrated it can pause the hammer's swing. The neutrality of a self-contained instrument is one thing. The neutrality of an instrument with a live operator is another. THORChain's operators are not absent. They are present and selectively active. Calling that neutrality is a category error. The defensible version of the tool-neutrality argument, and I want to steelman it because the bulls deserve their strongest case, runs like this. If THORChain begins filtering, it must develop an adjudication process for deciding when to filter. Adjudication processes demand evidence standards, appeals, and accountability. None of these exist in a permissionless system, and therefore any filter is arbitrary and captured. Better to be uniformly permissive than selectively arbitrary. There is real force here. A protocol that filters badly is worse than a protocol that does not filter at all, because the bad filter is both ineffective and a source of legitimacy for the idea that filtering is fine. This is the argument that a refusal can be principled rather than merely convenient, and I concede its internal logic. What collapses the steelman is the May pause. One cannot hold the position "we never filter" while maintaining a documented instance of network-level pausing for self-defense. The bull's strongest argument requires uniformity. THORChain does not have uniformity. It has a precedent for filtering its own risk and a policy of not filtering external risk. That is not neutrality. That is selective neutrality, and selective neutrality has a name in regulatory language, and the name is not favorable. Which brings me to the regulatory layer, where this story's real weight sits. Bitget's own account attributes the attack methodology to actors consistent with North Korean (Lazarus) operations. I am going to proceed carefully here, because attribution between a public claim and a court-level finding is a large distance. But the analytic point does not depend on the attribution being proven. It depends on the attribution being made, publicly, by a regulated counterparty, in connection with funds that moved through an identifiable protocol. Once that sentence is on the record, the legal exposure exists in the space between the claim and its resolution, and regulators move in that space. If the funds are ultimately found to belong to a designated sanctions entity, the question for THORChain is not whether it intended to process sanctioned value. Intent is not the test. The test, in the OFAC framework and in its analogues, is generally whether a U.S.-nexus actor provided a service to a sanctioned party. A protocol that knowingly declined an opportunity to prevent a designated entity's funds from moving, after having the capability and a prior demonstration of that capability, occupies a materially worse legal position than one that merely lacked the capability. The distinction is between "could not" and "would not." Regulators are far more comfortable with the first. Tornado Cash is the instructive precedent, and the parallels are uncomfortable. In 2022, OFAC designated the Tornado Cash contracts. The designation was not based on a finding that every transaction was illicit. It was based on the gravity and volume of sanctioned-value flows and on the protocol's role as a systematic conduit. The developers faced criminal exposure. The contracts — immutable, deployed, unauditable by the team that no longer controlled them — were nevertheless sanctioned, and the practical effect was that compliant counterparties disconnected. Being immutable did not save Tornado Cash, because sanctions do not act on the code. They act on the people and entities that would interact with it. The code survives. The access dies. The reason this analogy matters for THORChain is the capability asymmetry. Tornado Cash, at the moment of designation, could credibly argue there was no team, no operator, and no one who could turn anything off. That argument failed at the entity level, but it was a real argument. THORChain cannot make it. THORChain has a node set that has demonstrated the ability to pause. When a protocol has a demonstrated ability to stop something and declines, the narrative shifts from "unavoidably permissive infrastructure" to "willfully permissive infrastructure." The first is a design choice. The second is a decision. Decisions are the thing regulators name. I want to close the loop on the securities dimension, because readers will ask, and I do not want to overstate it. RUNE, the protocol's native asset used for staking and security bonding, is not the center of this story. But the Howey framework asks whether there is an investment of money in a common enterprise with an expectation of profit from the efforts of others. THORChain's decentralization weakens the "efforts of others" prong — a genuinely distributed node set is a relatively strong defense. But the same governance evidence that damages the censorship-resistance narrative also weakens the decentralization defense, for a symmetric reason. If the nodes can coordinate to pause and can coordinate to selectively refuse, they are more coordinated, and more centrally effective, than the securities defense would prefer. The same fact cuts both ways. This is the internal coherence of the forensic view: the property that makes a protocol credibly decentralized is the property that makes it credibly permissive, and THORChain has partially surrendered the first without surrendering the second, which is the worst cell in the matrix. Let me lay out the four-cell matrix explicitly, because it is the cleanest way to see the trap. A protocol can be (1) decentralized and permissive, (2) decentralized and filtering, (3) centralized and permissive, or (4) centralized and filtering. Cell one is the ideal and is largely mythical at the cross-chain layer for reasons I have described. Cell two is coherent and honest. Cell four is coherent and unpopular. THORChain has positioned itself in cell three — centralized and permissive — while describing itself as cell one. Cell three is the only cell in which the operator carries all of the agency and none of the responsibility. That is the cell regulators exist to eliminate. Now let me turn the blade the other way, because a cold dissection that only cuts one direction is not a dissection. It is advocacy wearing a lab coat. Here is what the bulls got right, and it is more than the bears will admit. The request from Bitget asked THORChain to do something with no clean stopping rule. Freeze these addresses. Which addresses? The ones Bitget identifies. Based on what evidence? Based on an attribution made days after the event, by a party with a direct financial interest in recovery, without a court order, without an independent adjudicator. Consider the incentive terrain one step further out. If a protocol establishes that a sufficiently large exchange's public request is sufficient to trigger a state-level freeze, then the protocol has handed a policy lever to any exchange CEO with a social media account. The next request will be more aggressive. The one after that will target a controversial but legally unproven address. Within a year, the "freeze on request" mechanism is used to censor a legitimate counterparty, and no one can point to the moment it broke, because every individual freeze was locally defensible. The bulls are also correct that filtering creates a second-order problem they rarely get credit for naming: once you accept a filter, you accept an obligation to maintain it. A protocol that filters once becomes a protocol that is expected to respond to every future request, on every chain, for every asset. That is a permanent operating cost, a permanent legal exposure, and a permanent political burden. There is a real argument that a cross-chain protocol run by volunteers and node operators — not by a compliance department — is structurally incapable of running that function well, and that the honest thing is to refuse the function rather than run it badly. I have audited systems that took on compliance functions they could not staff. Those systems produced false positives that hurt innocent users and false negatives that hurt everyone. Bad filtering is not a lesser evil. It is a different evil with a legitimacy halo. Finally, the bulls are right that "code is law" is not a slogan to be mocked. It is a load-bearing design philosophy. If we accept that a protocol should be commandeered on request, we have to specify who may command it and under what standard, and the crypto industry has spent fifteen years failing to specify that standard. The absence of a standard is a real reason to pause before inventing one under emergency conditions. I concede all of that. And none of it survives contact with the two facts I keep returning to: THORChain did pause before, and the funds are moving now. The bull case is a case for uniform permissiveness. THORChain is not uniformly permissive. The bull case is a case against ad hoc filtering. The current situation is the ad hoc outcome, since the protocol has already made two different choices about two different incidents. The bull case, in short, defends a position the protocol does not occupy. That is the finding. Not that THORChain should have frozen the wallets, though on balance I believe the marginal freeze was justified given the magnitude and the timing. The finding is narrower and harder: THORChain's public account of what it is cannot be reconciled with its own operational history. The company of proofs does not match the story of intentions. For the reader in a sideways market, here is what to do with this. Choppy conditions reward positioning, not prediction, and positioning requires signal. Three signals are worth watching, in priority order. First, watch for regulatory action. The Tornado Cash sequence ran, in broad strokes, from escalating public attention to designation to enforcement, over a window measured in months rather than days. If the U.S. Treasury's OFAC or FinCEN moves against any address or entity connected to this flow, the effect on RUNE and on every integration that touches THORChain will not be gradual. Liquidity is a confidence function, and confidence in a disputed bridge is the first thing to leave. The tell to watch is not a headline; it is a Wells notice, a sanctions listing, or a sudden change in exchange asset policy toward RUNE pairs. Second, watch whether the exchange reflex becomes a policy. If major exchanges begin formally restricting THORChain-related deposits or delisting RUNE pairs under the heading of risk control, that tells you the compliance layer has begun routing around the protocol, and routing around is how infrastructure gets orphaned. This can happen without any regulatory action at all. A CEX does not need a regulator's permission to refuse your asset. It needs only a risk committee's anxiety. In the FTX forensics work I contributed to in late 2022, the most revealing movements were never the headline transfers. They were the quiet policy changes at the edges — the pairs that stopped trading, the deposits that started flagging — that preceded the collapse by weeks. Watch the edges. Third, watch THORChain's own stance. If the protocol softens — introduces an optional review module, a cooperative flagging process, any mechanism that distinguishes between self-protection and counterparty protection — that is a partial repair of the narrative and a partial de-risking of the legal position. If it hardens and doubles down on "we never filter," the internal inconsistency becomes a public liability, and the next incident will arrive with this one as precedent. Let me state the contrarian read plainly, because the crowd is not positioning for it. The bullish narrative around THORChain and every similar "censorship-resistant" cross-chain primitive is that permissiveness is a moat. The evidence here suggests it is the opposite. The protocol's permissiveness is why it attracts the exact flow — sanctioned, laundered, high-profile — that is most likely to end its access to the regulated liquidity on which it ultimately depends. The moat is also the drain. A protocol that lives on the boundary between legitimate and illicit demand does not capture both markets permanently. It captures both markets until the boundary is redrawn by an authority it did not consult, and then it captures only the market it cannot legally serve. This is the structural position of every system that has ever tried to monetize the gray zone: a temporary arbitrage that pays for a permanent discount. The deepest point is not about THORChain at all. It is about what "decentralized" has been allowed to mean. For a decade, the word has been used as a shield — if a system is decentralized, it is not accountable, and if it is not accountable, it is not responsible. THORChain is the case that breaks the shield. It is decentralized enough to claim the exemption and centralized enough to exercise discretion. It wants the sovereignty of a protocol with no operator and the self-preservation of a protocol with one. You cannot hold both. The mechanism that lets you pause for yourself is the mechanism that lets a regulator tell you to pause for someone else, and the only thing standing between those two exercises is a governance decision that just went on the record as "it depends on whose money it is." Trust is a variable; proof is a constant. The proof, in this case, is a May pause and a September refusal from the same validator set. That is the record. It will be read by people who do not care about the philosophy and care a great deal about the precedent. The question the industry should be asking is not whether THORChain should have frozen the wallets. It is who, exactly, decides when a "permissionless" system is allowed to act like an operator — and whether we want that decision made by the operators themselves, in the dark, for reasons they do not have to disclose. That is not a question about code. It is a question about power, and no whitepaper has ever answered it.

THORChain Refused to Freeze the Bitget Hacker Wallets. The Code Says It Could Have.

THORChain Refused to Freeze the Bitget Hacker Wallets. The Code Says It Could Have.

THORChain Refused to Freeze the Bitget Hacker Wallets. The Code Says It Could Have.

Market Prices

BTC Bitcoin
$84,878.7 +1.02%
ETH Ethereum
$2,703.4 +0.86%
SOL Solana
$118.48 -0.56%
BNB BNB Chain
$772.9 +0.61%
XRP XRP Ledger
$1.5 -0.08%
DOGE Dogecoin
$0.0950 +0.59%
ADA Cardano
$0.2502 +1.62%
AVAX Avalanche
$10.96 -0.34%
DOT Polkadot
$1.18 -4.75%
LINK Chainlink
$14.33 -0.08%

Fear & Greed

74

Greed

Market Sentiment

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$84,878.7
1
Ethereum ETH
$2,703.4
1
Solana SOL
$118.48
1
BNB Chain BNB
$772.9
1
XRP Ledger XRP
$1.5
1
Dogecoin DOGE
$0.0950
1
Cardano ADA
$0.2502
1
Avalanche AVAX
$10.96
1
Polkadot DOT
$1.18
1
Chainlink LINK
$14.33

🐋 Whale Tracker

🔴
0x8b45...6a3c
3h ago
Out
2,319 ETH
🔵
0x9648...8a7f
3h ago
Stake
38,883 BNB
🔵
0x8264...8719
12h ago
Stake
422.28 BTC

💡 Smart Money

0x3f99...8c8c
Early Investor
+$2.6M
67%
0x7ad0...5208
Experienced On-chain Trader
+$3.3M
81%
0xc2d2...81b6
Top DeFi Miner
+$4.9M
81%

Tools

All →