Bitget CEO asks Thorchain to refuse service to tracked attacker addresses

By Crypto Wire
September 26, 2026

Bitget CEO Gracy Chen formally asked Thorchain on Saturday to refuse service to publicly listed attacker addresses tied to the exchange’s security incident, Bitcoin.com, Lookonchain, Blockzeit, and related desk wraps reported September 26. Bitget now pegs the theft near $387.5 million—up from earlier ~$351 million prints—and says attacker-controlled wallets remain actively tracked. Chen’s X post framed the ask as an industry test: “Decentralization is a design principle, not a shield for facilitating known stolen funds. The industry is watching.” Attribute the formal request, the loss figure, and the quote to Bitget / Chen via those Saturday wraps—do not invent that Thorchain has already frozen any specific vault balances.

Why Thorchain sits in the laundering tape. Bitcoin.com’s Saturday feature says Bitget’s attacker has been moving stolen funds across several rails and that Thorchain is among the venues used to shuffle proceeds—including reports of tens of millions in XRP deposited into Thorchain vaults and another stash already swapped toward BTC, with bitcoin then peeled across many addresses. The same wrap lists other reported rails such as Chainflip, Uniswap, 1inch Fusion, Stargate, Across, and Relay. MistTrack-linked reporting in aggregate desks likewise flags Thorchain swaps and cross-chain transfers after the Bitget incident. Treat those routing notes as attributed investigator/desk claims, not as a complete public ledger of every hop.

Thorchain’s reply landed the same afternoon. Bitcoin.com timestamps the protocol’s official X response at about 2:17 p.m. Eastern Saturday, tagging Chen: Thorchain said it was “devastated” about the exploit, then restated that it is “decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain,” asking what responsibility those base layers should bear when handling known stolen funds. Blockzeit’s industry-support wrap likewise says Thorchain rejected the refuse-service ask on permissionless grounds. That reply does not, by itself, confirm any temporary trading pause or validator freeze on Bitget-linked addresses.

Bybit precedent keeps the governance fight familiar. Bitcoin.com notes Thorchain was previously leveraged to move roughly $1.2–$1.5 billion in stolen funds after the Bybit breach, and that an FBI-era push to block DPRK-linked addresses briefly saw three validators vote to halt ETH trading before four validators reversed that decision about half an hour later. Chen’s Saturday ask also cites that Bybit-era routing as context. Treat the prior standoff as backdrop, not proof Saturday’s Bitget flows match the same dollar path.

What this post is not. LN 9786 already covered the Lookonchain/Bitquery Binance-funded 457.9 ETH refill into the attacker hub. LN 9776 covered the ~$83 million unfreezable XRP move. LN 9755 filed the phased withdrawal reopen clock (September 28 BTC through October 2). LN 9780 covered Sygnum Protect institutional off-exchange custody while retail withdrawals stay paused. Today’s unused angle is Chen’s formal Thorchain refuse-service ask plus the protocol’s same-day permissionless reply—Rug Room governance tape about cross-chain swap rails after a major exchange drain.



How collectors and traders should read the ask without inventing a freeze. Thorchain can halt the whole system or pause trading in some incident modes—Bitcoin.com cites the May 2026 GG20 vault exploit pause that kept the network down for weeks—but that capability is not the same as an admin key that silently blacklists one exchange’s attacker set the way a centralized venue can. Some Thorchain front ends have screened sanctioned or flagged addresses for years, Bitcoin.com notes, yet those screens can be bypassed. Chen’s public ask therefore pressures validators, front ends, and industry norms more than it promises an automatic on-chain blacklist.

Community pushback arrived immediately under Chen’s thread. Bitcoin.com quotes respondents asking why Bitget is not demanding bitcoin miners stop the funds, and comparing the request to blaming a highway after a bank robbery. That debate is part of the Saturday story: permissionless cross-chain infrastructure remains a laundering path after large exchange incidents, and CEOs who need recovery tools will keep colliding with protocols that define themselves like base-layer settlement. Attribute the pushback as reported replies, not as a poll of Thorchain node operators.

Bitget operational backdrop stays thin here. The exchange still says the flaw is fixed, trading and deposits continued, and balances are covered by its User Protection Fund while withdrawals reopen on the staged calendar already on the wire. Industry support desks note peers such as Bybit, Tether, and Circle joining tracing and recovery work. None of that replaces Thorchain’s refusal to treat publicly flagged attacker addresses as refuse-service targets on Saturday’s reply.

Rejected near-echos for this tick. Binance 457.9 ETH hub refill is LN 9786. Stolen XRP freeze limits are LN 9776. Withdrawal reopen calendar is LN 9755. Sygnum Protect is LN 9780. Quit reclaim / ERC721C validator blocks are LN 9788. Phygital desk 59 remains unused today—no fresh vaulted-collectible story cleared the last-6-hours bar.

Why Rug Room 52 plus Latest News 16 (no Editor’s Pick—Sep 26 OC EP already 5/5). A same-day CEO demand that Thorchain refuse publicly tracked Bitget attacker addresses—and Thorchain’s permissionless reply—is unused exploit-aftermath governance tape distinct from the XRP-move and Binance-refuel desks. Author is Crypto Wire for desk 52. Publicize stays off.

What not to invent: that Thorchain validators voted to freeze Bitget addresses Saturday, a precise dollar total of Bitget loot already swapped to BTC on Thorchain beyond attributed desk claims, that every front end now screens those addresses, or that Bitget’s $387.5 million figure has been independently audited in this article. Stick to Bitget / Chen / Thorchain / Bitcoin.com / Lookonchain / Blockzeit attributions for the ask, the reply, the loss print, and the Bybit-era backdrop.

Bottom line: Bitget CEO Gracy Chen asked Thorchain to refuse service to tracked attacker addresses after the ~$387.5 million incident, and Thorchain answered that it is permissionless like Bitcoin and Ethereum—unused Rug Room news for Sep 26 OC.

Disclaimer: This article is provided for informational and educational purposes only. It does not constitute financial, investment, legal, or trading advice. The NFT market is highly volatile, and past performance is not indicative of future results. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets. The cover image for this article may have been created using artificial intelligence (AI).

8bitcrypto NewsDesk

Crypto Wire — she runs the default news desk from Los Angeles. Market tape, NFT drops, and policy wires filed fast with zero shill. Your straight signal from 8bitcrypto.

Leave a Reply

Discover more from 8bitcrypto

Subscribe now to keep reading and get access to the full archive.

Continue reading