Why did THORChain refuse to block Bitget hacker addresses moving $6M to Bitcoin?

THORChain rejected Bitget's request to blacklist wallets involved in a $387.5 million exploit because the protocol's decentralized architecture lacks a central authority to freeze funds. This refusal allowed the attacker to successfully swap 2,390 ETH into 75.2 BTC through 27 permissionless transactions.
Why did THORChain refuse to block Bitget hacker addresses moving $6M to Bitcoin?

THORChain refused to block the Bitget hacker's addresses because the protocol is designed as a decentralized, permissionless cross-chain liquidity network that does not possess a centralized "kill switch" or blacklisting mechanism. Unlike centralized exchanges that can freeze accounts at the request of law enforcement or other platforms, THORChain’s core infrastructure processes swaps programmatically based on liquidity pool rules, regardless of the sender's identity or the history of the assets. This architectural choice prioritizes censorship resistance, even when faced with high-profile thefts like the $387.5 million Bitget exploit.

Following the breach in early 2026, Bitget urgently requested that major protocols halt transactions tied to the stolen funds. However, blockchain monitoring confirmed that the attacker bypassed these warnings by utilizing THORChain to move approximately $6 million. Specifically, the hacker executed 27 successful swaps, converting 2,390 ETH into 75.2 BTC. By moving these assets from Ethereum to the Bitcoin network, the perpetrator effectively broke the immediate link to Ethereum-based monitoring tools, complicating recovery efforts for Bitget and its users.

This incident highlights the escalating tension between DeFi protocols and centralized entities in the 2026 regulatory environment. While US-based exchanges are under strict mandates to implement robust Anti-Money Laundering (AML) controls, decentralized bridges like THORChain operate in a legal grey area where code is law. For the broader market, this event underscores the utility and the controversy of cross-chain liquidity, as it provides both essential interoperability for legitimate users and an exit ramp for illicit actors.

Investors and US-based users should monitor whether this event prompts renewed calls from global regulators for "gatekeeper" requirements on DeFi node operators. The ability of hackers to move millions of dollars across chains without oversight remains a primary target for upcoming crypto market structure legislation. In the short term, Bitcoin and Ethereum liquidity remains stable, but the incident serves as a stark reminder of the security risks inherent in centralized exchange custody and the immutable nature of decentralized finance transactions.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.