Skip to content Skip to sidebar Skip to footer

The latest dispute between Bitget and THORChain has sharpened one of the most uncomfortable questions in crypto: when a large-scale theft happens, who gets to act, and how quickly?

In the aftermath of the reported $387.5 million theft tied to Bitget, the exchange reportedly urged THORChain to stop serving addresses linked to the hacker. THORChain, however, rejected that request. The refusal became even more notable after on-chain tracking showed that the stolen assets were not sitting idle. In fact, about $6 million worth of value moved toward Bitcoin through a series of swaps on the THORChain network.

What the on-chain activity showed

According to the available reporting, CoinDesk identified 27 successful swaps that moved roughly 2,390 ETH into 75.2 BTC. That conversion is significant for a few reasons. First, it shows that the hacker was actively working through the stolen funds rather than simply holding them in one place. Second, it highlights how quickly value can shift across chains and asset types in a decentralized finance environment.

For observers, the picture was clear: even as Bitget pushed for intervention, the funds were already in motion. The swaps did not stop the broader incident, but they did expose a practical tension between an exchange trying to contain damage and a decentralized protocol operating under rules that do not easily lend themselves to emergency freezes.

Why THORChain’s response matters

THORChain is not a traditional exchange. It is a decentralized cross-chain protocol designed to enable swaps between different blockchain ecosystems without relying on a central authority to move funds around. That design is one of its strengths, but it also creates a difficult dynamic when criminal activity is involved.

Decentralization versus rapid response

When a centralized exchange is hit by an exploit, it can often freeze accounts, pause withdrawals, or flag suspicious addresses within minutes. A decentralized protocol, by contrast, is built around open access and permissionless interaction. If an address is simply sending or receiving value according to the rules of the network, there is no obvious “off switch” that a protocol can flip without undermining the very principles that make it decentralized in the first place.

That is why THORChain’s refusal to block the requested addresses was so telling. It did not necessarily mean the protocol was indifferent to the theft. It meant that the protocol was operating within a framework where unilateral blocking is far more complicated than it is on a centralized platform.

The exchange’s dilemma

Bitget, on the other hand, was in a much more direct position. As the exchange where the theft was reported, it had every reason to try to slow down the movement of stolen assets. From the exchange’s perspective, the request to THORChain was likely a defensive measure: if the funds were being routed through a known chain of addresses, cutting off access could have limited the hacker’s options.

But the fact that the swaps still went through underscores a broader problem. In crypto, the speed of movement can outpace institutional response. A protocol may not be willing or able to stop traffic on demand, and an exchange may not have the same level of control over external networks as it does over its own internal rails.

What the swaps reveal about hacker behavior

The conversion of ETH into BTC is especially interesting because it suggests a deliberate strategy rather than random movement. Moving value into Bitcoin could serve several purposes:

  • Exit liquidity: Bitcoin remains one of the most liquid and widely accepted assets in the crypto ecosystem, making it a practical destination for someone looking to move funds.
  • Obfuscation: Shifting from one asset to another can complicate tracking, especially when combined with mixing services, privacy tools, or further cross-chain movement.
  • Portability: Bitcoin’s deep market access can make it easier to convert value into fiat or move it across exchanges and payment rails.

In other words, the swaps were not just a technical detail. They were a signal that the hacker was working to normalize the stolen assets and prepare them for the next stage.

What this means for the broader crypto market

This episode is another reminder that security in crypto is not only a question of smart contract code, wallet management, or exchange internal controls. It is also a question of network-level response. Even if one institution wants to stop bad actors, the rest of the ecosystem may not be structured to comply immediately.

That creates a gap. Exchanges want speed. Protocols want consistency. Investigators want traceability. And attackers want frictionless movement. When those incentives collide, the result can be exactly what we saw here: a high-profile theft, a failed request for intervention, and millions of dollars in value quietly changing shape on-chain.

The bigger lesson is that the industry will keep running into this same friction point. As cross-chain infrastructure grows, so will the number of actors that need to coordinate when something goes wrong. Without clearer standards, shared trust frameworks, or better emergency protocols, incidents like this are likely to remain messy, public, and expensive for everyone involved.

For now, the Bitget-THORChain dispute is more than a headline. It is a case study in what happens when the speed of decentralized finance meets the urgency of a major security breach. And in this case, the chain did not wait for permission to move.

Related read: Lido DAO Vote #214 Passes: What Dual Governance Means for stETH Holders