THORChain (RUNE) Rejects Bitget's Plea to Block Hacker After $6.3M in ETH Swaps
THORChain (RUNE) refused Bitget's freeze request as 2,390 ETH worth $6.3M converted into 75.2 BTC. Post-hack volume hit $678M in two days.
AI SummaryAI
- Bitget hacker swapped 2,390 ETH for 75.2 BTC via THORChain in 27 swaps on Monday.
- Bitget lost $387.5 million in a Sept. 24 breach of its backend wallet system.
- Bitget CEO Gracy Chen formally asked THORChain to refuse service to attacker addresses.
- THORChain halted its network for five weeks after a May exploit that drained $10.7 million.
2,390 ETH Converted Into Bitcoin
The wallet tied to the Bitget attacker kept converting stolen ether into bitcoin on Monday, moving roughly $6.3 million through the THORChain (RUNE) swap network in a single morning session. On-chain records we reviewed show 27 successful swaps submitted between about 03:55 and 06:23 UTC, exchanging approximately 2,390 ETH for 75.2 BTC, with every bitcoin payout directed to a single consolidation address. The orders went in batches of roughly 100 ETH — about $265,000 each — from an Ethereum wallet that blockchain tracker Lookonchain identified as part of the attacker's activity. Four additional swaps covering another 400 ETH were still marked pending in the records. Not every order cleared cleanly: two 100 ETH swaps were only partly filled after portions failed to meet their specified minimum price, returning about 114 ETH to the sending wallet — visible proof of slippage cutting into the sweeper's execution. THORChain's design explains why the trail is open even though the funds are unstoppable: the protocol settles cross-chain trades without accounts, so unlike assets sitting on the best crypto exchanges, whose compliance teams can freeze withdrawals, nothing stands between the sender and settlement — yet every hop remains publicly traceable in the underlying blockchain records.
Bitget's Freeze Request and Bounty
Bitget's request grew out of the Sept. 24 breach that drained about $388 million — the company's own figure is $387.5 million — from its exchange wallets, after an attacker broke into a backend wallet system and had the exchange's own approval process sign the transfers, using techniques Bitget says are highly consistent with North Korean hacker organizations. On Saturday, CEO Gracy Chen asked THORChain to refuse service to the publicly listed attacker addresses, arguing that decentralization “is a design principle, not a shield for facilitating known stolen funds.” Bitget paired the request with a 5% bounty for freezing or recovering stolen funds, while tracing partner SlowMist urged that decentralization should not become a blanket excuse. THORChain's first reply said the protocol is as permissionless as the Bitcoin network, Ethereum and BNB Chain — Layer 1 chains — asking what responsibility those networks would bear if stolen funds crossed them. Critics rejected the framing: OKX founder and CEO Star Xu argued THORChain's validators jointly control vault assets, and security firm GoPlus estimated about 101.5 BTC, roughly $8.5 million, had already left through the protocol, with another 27.63 million XRP — about $43 million — being swapped into bitcoin.
The May Halt Precedent
THORChain pushed back on X on Monday: “A halt is not a selective freeze of specific funds or an individual swap,” the team stated, adding that the protocol “doesn’t censor by design.” The distinction is deliberate, because the network has exercised its emergency controls before — never against a named address. In May, after an attacker drained about $10.7 million from THORChain's own swap vaults, node operators coordinated a network-wide shutdown while developers repaired the vulnerability; trading resumed on June 22 after roughly five weeks, and the May attacker's addresses were never blacklisted. The protocol is also a repeat corridor for exploited funds: attackers behind April's $292 million Kelp DAO exploit routed proceeds across THORChain, as did North Korea's Lazarus Group after the $1.5 billion Bybit hack. The Bitget inflows have been a revenue windfall as well — THORChain processed $678 million in the two days after the hack, against $20 million to $60 million in daily volume the week before, collecting nearly $1.2 million in gross system income. We covered the original request in our earlier report.
For our desk, the story is less about perceived hypocrisy than about verifiability. The on-chain evidence is complete: the attacker's Ethereum wallet, the 27 settled swaps and the single bitcoin consolidation address are all public and independently checkable — which is precisely why Bitget's public address list and 5% bounty can function at all. The root cause, per Bitget's own account, sits with the exchange: a backend wallet system whose signing approval process was subverted. Its remediation pairs the patched vulnerability with a User Protection Fund covering the full loss. Permissionless routing will keep absorbing hacked funds; tracing, not blocking, remains the lever the industry actually controls.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


