The latest standoff between THORChain and Bitget has turned a high-profile crypto theft into a broader debate about who has the authority, or the ability, to stop stolen funds from moving across chains.
According to reporting by CoinDesk, the hacker behind a reported $387.5 million theft from Bitget continued moving assets through THORChain even after the exchange asked the protocol to stop serving addresses linked to the incident. In that window, about 27 successful swaps moved roughly 2,390 ETH into 75.2 BTC, a transfer worth approximately $6 million at the time.
That sequence of events matters because it sits at the intersection of three uncomfortable realities: large-scale exchange hacks are still common, cross-chain infrastructure can be used to reshuffle stolen value quickly, and decentralized protocols are often expected to act responsibly without being given the same centralized levers as banks or exchanges.
What happened in the THORChain-Bitget dispute?
Bitget asked THORChain to block or restrict addresses tied to the stolen funds. THORChain did not comply. Instead, swaps involving those addresses continued to settle, allowing part of the stolen amount to be converted from Ethereum into Bitcoin.
On the surface, that may look like a failure to cooperate. In practice, it reflects a deeper structural issue. THORChain is a cross-chain protocol designed to facilitate permissionless swaps between different blockchain networks. It does not operate like a traditional exchange with a compliance team that can freeze a user account, lock a withdrawal, or pause an address on request.
For a protocol built around automated liquidity pools, smart contracts, and open access, the idea of blocking a specific address is not a simple operational decision. It raises questions about governance, precedent, chain-level policy, and the line between being a public infrastructure layer and becoming a custodial gatekeeper.
Why the move from ETH to Bitcoin is significant
The fact that the hacker moved value into Bitcoin does not automatically mean the funds are hidden. On-chain data still shows the swaps, the amounts, and the destination addresses. But it does make the funds harder to handle from an exchange perspective and potentially complicates recovery efforts.
Bitcoin is often the default destination for stolen crypto because it is widely supported, deeply liquid, and can be moved across many wallets, services, and platforms. For a thief, converting stolen ETH into BTC may be a way to reposition the funds before attempting to cash out, consolidate them, or move them further along the chain.
The reported 27 swaps and the movement of about 2,390 ETH into 75.2 BTC suggests a deliberate pattern rather than random activity. That kind of behavior is typical in post-hack laundering attempts, where the goal is to break the direct link between the compromised exchange wallet and the final exit points.
The censorship question at the heart of the dispute
The most difficult issue here is not technical. It is philosophical. If a known criminal address is using a decentralized protocol, should the protocol block it?
Proponents of strict permissionlessness would say no. They argue that once a protocol is live
Related read: Riot Platforms Clears $200M Credit Facility and Frees Up Collateral
