THORChain (RUNE) Refuses Bitget's Request to Block $387.5M Hack Addresses
THORChain (RUNE) rejected Bitget's plea to block wallets tied to a $387.5M hack, saying its halt is an emergency mechanism, not a selective address freeze.
AI SummaryAI
- THORChain refused Bitget's request to block wallets tied to a $387.5 million September breach.
- Bitget revised its hack loss estimate from $351.6 million to about $387.5 million.
- THORChain halted its full protocol after losing roughly $10.7 million in a May 2026 exploit.
- Circle and Tether froze 99,990 USDC and 218,023 USDT linked to the attack.
THORChain Declines Address Freeze
THORChain (RUNE), the cross-chain liquidity protocol that lets users swap native assets directly between blockchain networks, has publicly refused Bitget's demand to deny service to wallets tied to the exchange's $387.5 million September hack. In its official statement posted on Sept. 28 (the protocol's public response), the team drew a sharp line between two very different powers: an emergency network halt, which it has used before, and a selective address freeze, which it says it does not operate and has no intention of building. The refusal is the latest chapter in a standoff that began when Bitget CEO Gracy Chen formally asked the protocol on Sept. 26 to refuse service to attacker wallets, as covered in our earlier report on the freeze request.
the protocol's public responsehttps://x.com/THORChain/status/2104460133132562449
Bitget disclosed the breach on Sept. 24, initially estimating losses at $351.6 million before raising the figure to roughly $387.5 million after adding Zcash and TRON transfers identified in a fuller accounting. The exchange's investigation found the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials rather than stealing private keys, and the attackers used the same THORChain route after the Bybit breach, which was 2025's largest security incident. THORChain's defense rests on precedent: during its own May 2026 exploit, in which it lost about $10.7 million, the protocol shut itself down entirely to contain the incident — and even then it never blacklisted the attacker's addresses, and will not do so now. The THORChain team argues its halt is “an emergency security mechanism designed to protect the protocol,” not “a selective freeze of specific funds or an individual swap,” and asks what responsibility Bitcoin, Ethereum and BNB Chain should bear when processing known stolen assets.
Security Firms Split on Vault Control
The neutrality argument has not gone unchallenged. GoPlus Security published a rebuttal on Sept. 27, asserting that THORChain “was never strictly decentralized” and urging it not to “enable criminals — or endanger the industry — just to earn swap fees on stolen funds.” The firm highlighted the differences between THORChain's node-managed threshold vaults and the base design of a Layer 1 chain like Bitcoin or Ethereum. Veteran security executive Michael Perklin defended the protocol, arguing that threshold signing is an automated process, not a series of human approvals: “in all three cases there is no effective option to sign, only an effective option to shut the machine off,” he wrote (his public argument), comparing a THORChain operator's choices to a Bitcoin miner or Ethereum validator powering down — a stance consistent with the protocol's earlier rejection of similar pleas. Recovery data shows how limited external leverage is: Circle froze 99,990 USDC and Tether froze 218,023 USDT linked to the incident, roughly $318,013 at the dollar peg, or about 0.082% of the revised loss. A single traced route, reported Sept. 27, moved roughly 4 BTC from TRON through USDT0 to Ethereum, then via a THORChain swap into Bitcoin and a Wasabi CoinJoin round. Bitget offers a 5% bounty for eligible freezes and another 5% for recovery, with Mandiant and SlowMist assisting, and points to its 5,500 BTC protection fund, valued near $464 million. Withdrawals restarted in stages: 9,585 Bitcoin withdrawals totaling about 4,098 BTC on Sept. 28, ETH on Sept. 29, USDT on Sept. 30, and remaining services by Oct. 2. Readers tracking the market in real time can follow live spot and futures prices on Bitget.
his public argumenthttps://x.com/mperklin/status/2104201990104399886
What the May Post-Mortem Proves
The May 2026 incident is the decisive primary evidence in this dispute. On-chain records and the protocol's own post-mortem show that a solvency check identified a vault imbalance of roughly $10.7 million, triggering a full network halt, an 11-step restart with vault and key-share verification, and a resumption of trading only in June. That history confirms the halt power is real — and blunt. Our reading: the question is not whether THORChain (RUNE) can stop processing, but whether its governance should add address screening, who would maintain the list, and how a false match is reversed. Until a screening rule exists in code, halting everyone remains the only switch the network has.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


