Bitgetโs recent $387.5 million security breach has sparked a debate over how decentralized crypto networks and cross-chain services should handle assets linked to known hacks.
The exchange has asked THORChain to block addresses associated with the attack after investigators traced portions of the stolen assets across multiple blockchain networks. THORChain, however, has pointed to its permissionless structure and questioned whether it should selectively restrict transactions involving specific addresses.
Bitget initially estimated the value of assets affected by the September 24 breach at around $351.6 million before increasing the figure to approximately $387.5 million as its investigation identified additional transactions. The exchange said the incident involved unauthorized transfers across several blockchain networks.
According to Bitget, the attacker exploited a vulnerability in a third-party security product and used compromised internal credentials to initiate fraudulent withdrawal commands. The exchange has said its private keys and cold wallets were not affected.
Following the breach, the stolen assets moved through multiple networks and cross-chain services, including Ethereum, BNB Chain, TRON and THORChain, before some of the funds were converted into Bitcoin. Investigators have continued tracking the attacker-controlled addresses through publicly available blockchain data.
Bitget CEO Gracy Chen called on THORChain to refuse service to addresses linked to the attacker. THORChain responded that its emergency controls are designed to protect the protocol during security incidents and are not equivalent to selectively freezing individual wallets.
The distinction is important because THORChain operates differently from a centralized exchange. Its cross-chain infrastructure relies on independent node operators and threshold-signature-secured vaults to authorize transactions. A permanent blacklist would therefore require changes to how transactions are processed and enforced across the network.
THORChain does have mechanisms that can halt trading or signing during emergencies. However, applying those controls whenever suspected stolen funds enter the network could also interrupt legitimate transactions involving unrelated users.
The Bitget incident has also involved several other blockchain networks and cross-chain services. Investigators have identified roughly a dozen services through which the stolen assets moved, including Uniswap, Across, Stargate, deBridge, Relay, PancakeSwap and Circleโs Cross-Chain Transfer Protocol.
This means blocking a single route may slow the movement of stolen funds without necessarily preventing attackers from using alternative services. At the same time, public blockchain records have allowed investigators to map attacker-controlled addresses and follow the movement of assets across networks.
Bitget continues to work with security firms and other industry participants to trace and recover the stolen funds. The exchange has also published attacker addresses and offered rewards for efforts that successfully freeze or recover eligible assets.
The incident has placed renewed attention on the balance between permissionless crypto infrastructure and intervention when stolen assets move through decentralized networks.
