THORChain pushed back again Monday on Bitget‘s request to block wallets connected to its $387.5 million hack, saying its emergency halts exist to protect the protocol and are not a way to freeze particular funds.

“A halt is not a selective freeze of specific funds or an individual swap,” THORChain wrote on X. “THORChain is permissionless and doesn’t censor by design.”

Bitget CEO Gracy Chen made the request on Saturday, saying the attacker’s addresses are public and being tracked. “We are formally asking @THORChain to refuse service to these addresses,” she posted, adding that decentralization “is a design principle, not a shield for facilitating known stolen funds.”

Bitget has said attackers broke into a backend wallet system on Sept. 24 and got its own approval process to sign the transfers, using techniques consistent with North Korea-linked hackers.


Get Unchained’s crypto news in your inbox with the free Unchained Daily newsletter.


The Bitcoin Comparison

THORChain’s first reply said the protocol is “decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain.”

Critics rejected the comparison. OKX founder and CEO Star Xu argued that THORChain’s validators jointly control the assets in its vaults. “TSS distributes control among multiple parties, but distributing an intermediary does not eliminate the intermediary,” he wrote. In a later post, Xu noted that node operators paused the network in May, when THORChain’s own vaults were drained.

GoPlus Security said on Sunday that node votes can pause signing on a single chain, and estimated that about 101.5 BTC, worth roughly $8.5 million, had already left through THORChain, with another 27.63 million XRP, about $43 million, being swapped into bitcoin. “Do not put the industry at risk for the fee line,” the security firm wrote.

THORChain’s Defense

In Monday’s post, THORChain said that during its May exploit, in which $10.7 million was taken from its liquidity pools, the attackers’ addresses “were never blacklisted and therefore never prevented from swapping on THORChain.”

It also pointed to a post by Michael Perklin, who called GoPlus’s argument “cherry picking at best, a false equivalency at worst” and wrote that “All tools in existence are inherently neutral by nature.”

The protocol has faced these questions before. Attackers behind April’s $292 million Kelp DAO exploit routed stolen funds through THORChain, as did North Korea’s Lazarus Group with most of the ether it converted to bitcoin after the 2025 Bybit hack.

Bitget has said its User Protection Fund covers the full loss.

Related Listen: The Chopping Block: ColdCard’s $100M RNG Hack, AI-Powered Security & Ethereum’s Staking Yield Taper