Bitget CEO Asks THORChain (RUNE) to Block Addresses Tied to $387.5M Hack
Bitget CEO Gracy Chen asked THORChain (RUNE) to block hackers behind its $387.5M breach; the permissionless network has refused similar freezes before.
AI SummaryAI
- Gracy Chen formally requested THORChain refuse service to listed attacker addresses.
- Attackers moved tens of millions in XRP through THORChain vaults into Bitcoin.
- Circle and Tether froze about $318,000 in stablecoins tied to the hack on Friday.
- Bitget offers a bounty paying 5% of frozen and 5% of recovered funds.
Bitget’s $387.5M Demand to THORChain
Bitget chief executive Gracy Chen has publicly demanded that THORChain (RUNE) refuse service to the attackers who drained roughly $387.5 million from the exchange this week, staging a direct confrontation between a centralized trading venue and a permissionless cross-chain bridges network. Two days after the breach first surfaced, Bitget revised its loss estimate upward: the exchange’s official support notice now states that approximately $387.5 million was transferred into attacker-controlled addresses, up from an initial estimate of about $351 million published when the incident emerged. On-chain tracing shows the thieves are moving the haul through THORChain, the omnichain liquidity layer behind RUNE: multiple weekend reports indicated that tens of millions of dollars in XRP were deposited into THORChain vaults, with tens of millions more already swapped into Bitcoin. That Bitcoin was then split and dispersed across a vast web of BTC addresses, complicating recovery. Outflows have also been tracked through Chainflip, Uniswap, 1inch Fusion, Stargate, Across and Relay. Chen’s appeal, posted on X Saturday, was unambiguous: “Our attacker addresses are publicly listed and under active tracking. We formally request that THORChain refuse service to these addresses.” She added that “decentralization is a design principle, not a shield for known stolen funds in circulation,” warning that “the entire industry is watching.” Bitget has also published a live trace dashboard and API covering the attacker addresses for real-time monitoring. The demand lands on a structural tension: THORChain lets users swap assets across blockchains — BTC for ETH, for instance — without identity checks, the very property that draws thieves. Replies to Chen’s post pushed back hard, with one user asking why she did not demand Bitcoin miners block the funds, and another asking whether she resents the highway a bank robber fled down.
Permissionless by Design, Tested Before
THORChain’s official account answered the request at 2:17 pm Eastern on Saturday, tagging Chen directly. The response expressed sympathy for the exploit and everyone affected, but drew a hard line: THORChain, like Bitcoin, Ethereum and BNB Chain, is decentralized and permissionless, and the team asked what responsibility those chains should bear when handling known stolen funds. Bitget — a top-tier venue often ranked among the best crypto exchanges — is confronting a protocol that has faced this exact standoff before. After the roughly $1.2–1.5 billion Bybit hack in February 2025, on-chain tracking firm MistTrack noted that close to $1.2 billion of the loot moved through THORChain. Under FBI pressure to freeze North Korea-linked addresses, three of the protocol’s validators voted to pause ETH trading; four reversed that decision within half an hour, and one developer resigned over the chaos. Analytics firm TRM Labs had earlier described the network as the preferred route for North Korea’s largest thefts, citing Bybit as well as the roughly $300 million KelpDAO exploit. Architecture explains why blocking is hard to deliver: the protocol’s own documentation describes 95 nodes operating worldwide with no admin key and no multisig control — a defining trait of Web3 infrastructure. Yet the network has shown it can halt itself. After the GG20 attack in May drained roughly $10.7 million from one of its own vaults, operators suspended the network and kept it offline for weeks while patching the flaw — a capability that exists, but one historically reserved for internal incidents rather than external theft. Bitget is pursuing recovery on parallel tracks: a bounty program paying 5% of any frozen and 5% of any recovered funds, functioning like crowdsourced DeFi insurance and partially routed through Bybit’s LazarusBounty channel; a $318,000 stablecoin freeze executed by Circle and Tether on Friday, September 25; and an investigation assisted by cybersecurity firms Mandiant and SlowMist that Bitget says it has contained, ruling out further unauthorized transfers. Withdrawals are restarting in phases, though Chen cautioned the process runs slower than usual because the incident spans multiple blockchains and tokens.
RUNE’s Permissionless Standoff
Our read: the outcome will be decided less by rhetoric than by code and governance. Bitget’s published attacker addresses, live trace dashboard and the $318,000 stablecoin freeze show centralized chokepoints work wherever they exist; THORChain is deliberately the gap. The protocol’s own post-mortems — the GG20 vault drain it answered with a weeks-long suspension — prove a pause mechanism exists, so the open question is governance will, not technical capability. For RUNE holders the episode cuts both ways: thief-driven swap volume today, mounting regulatory and reputational exposure tomorrow. RUNE itself has moved sharply, gaining roughly 20% over the past 24 hours as attention refocuses on the network.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


